Municipality of Pisa Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Municipality of Pisa has been listed by the nova ransomware group after internal files were exfiltrated in a ransomware attack, with the incident disclosed on May 10, 2025. An undisclosed number of people may have been affected; residents are advised to check official municipal channels for further information and to take appropriate precautions.
On May 10, 2025, the Municipality of Pisa, the local government body for the historic Italian city of Pisa, was listed by the ransomware group known as nova. Public reporting indicates that the group claims to have carried out a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and further technical details about the incident have not been disclosed. For residents, businesses, and anyone who has interacted with municipal services through the official portal comune.pisa.it, the listing raises questions about the security of information held by a core public institution.
Local governments routinely manage sensitive personal and administrative records. When a ransomware group claims to have taken internal files from such an organisation, the potential consequences extend beyond the municipality itself to the people whose data may have been involved. At present, only the group’s claim and the broad description of internal-file exfiltration are publicly available.
What happened
According to the available record, the Municipality of Pisa was listed by the nova ransomware group on May 10, 2025. The listing asserts that internal files were exfiltrated during a ransomware attack. No confirmed timeline of the intrusion, no statement of how the attackers gained access, and no verified volume of data have been released. The number of individuals whose information may have been involved is listed as unknown. Official confirmation or detailed technical analysis from the municipality itself has not appeared in the public summary provided. The claim therefore rests on the group’s leak-site listing rather than on independently verified forensic findings.
Ransomware incidents of this type typically involve encryption of systems combined with data theft, followed by a threat to publish the stolen material if a ransom is not paid. In this case, the public facts stop at the assertion that internal files were taken. Whether systems were encrypted, whether a ransom demand was issued, and whether any data has actually been released remain undisclosed.
Who is nova?
Nova is a ransomware operation that has been documented in public cybersecurity reporting since roughly 2022. Like many contemporary ransomware groups, it is associated with double-extortion tactics: encrypting a victim’s systems while simultaneously stealing data and threatening to publish it on a dedicated leak site if payment is not made. The group has previously listed a range of organisations across different sectors, using the public listing itself as pressure. Its operators typically communicate through dark-web channels and claim responsibility by posting victim names and, sometimes, sample files.
In the present matter, nova’s listing of the Municipality of Pisa constitutes a claim by the group. No independent verification of the volume, content, or authenticity of any allegedly stolen material has been supplied in the available facts. Established public knowledge of nova’s methods therefore provides context for how such groups operate, but does not state the specific details of this incident beyond the listing itself.
About Municipality of Pisa
The Municipality of Pisa is the local administrative authority for the city of Pisa in Tuscany, Italy. Its official website, comune.pisa.it, functions as the primary digital portal for residents, businesses, and visitors seeking information on public services, permits, civil-registry matters, taxation, urban planning, and other municipal functions. Like other Italian comuni, it holds records necessary for the delivery of everyday government services.
A breach affecting a municipal government is consequential because such organisations sit at the intersection of personal identity data, financial records, and operational information about public infrastructure. Residents rely on the municipality for birth, marriage and residence certificates, property and tax records, social-service applications, and licensing. Any compromise of internal systems can therefore affect both the continuity of public services and the privacy of citizens who have no choice but to interact with the local authority.
What data was at risk
The facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases, or categories of personal information has been disclosed. Exact contents therefore remain unconfirmed.
Organisations of this kind typically maintain a wide range of records: civil-registry data, tax and property information, employee personnel files, correspondence, contracts, and operational documents related to public works and services. Because the public record does not name specific data categories beyond “internal files,” it is not possible to state with certainty which of these, if any, were taken. Readers should treat any more detailed claims circulating online as unverified unless corroborated by official sources.
The real-world impact
For individuals, the primary risk is that personal information held by the municipality—if it was among the exfiltrated files—could be used for identity fraud, targeted phishing, or other misuse. Because the number of people affected is unknown and the precise data types are undisclosed, the scale of this risk cannot yet be quantified. Residents who have submitted documents or conducted transactions through municipal channels may wish to remain alert for unusual communications that reference local-government matters.
For the Municipality of Pisa itself, a ransomware incident can disrupt internal operations, delay public services, and require costly recovery and forensic work. Even when systems are restored, the organisation may face ongoing scrutiny over data-protection practices and the need to notify affected parties under applicable privacy rules. The reputational and administrative burden can persist long after technical recovery is complete. None of these outcomes has been confirmed in the current public facts; they represent the ordinary consequences observed in similar municipal incidents.
Were you affected?
If you live in or have conducted business with the Municipality of Pisa, practical first steps include monitoring bank and credit accounts for unexpected activity, treating unsolicited emails or messages that reference municipal services with caution, and considering a credit freeze or fraud alert if you believe sensitive identifiers may have been exposed. Because the exact data involved remains unconfirmed, these measures are precautionary rather than responses to proven compromise of any particular record.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a scan will not confirm or rule out involvement in this specific incident, but it can indicate whether your information has surfaced elsewhere and help you prioritise further protective steps. Stay attentive to any official notices issued by the Municipality of Pisa itself for the most authoritative guidance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Ministerio de Salud de la Nación argentina Listed by nova Ransomware GroupRama judicial colombia Listed by nova Ransomware Groupnovaevo+ / T.consulT Listed by nova Ransomware GroupBio-Clima Service Listed by nova Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Municipality of Pisa Listed by nova Ransomware Group →
Publicly posted by nova — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.