As cited
Copy frozen at (site build).
ransomware
Panzer ransomware targets Italian manufacturer as ESXi capability raises industrial security concerns
Panzer ransomware emerged in August 2026 as a ransomware-as-a-service operation and claimed victims across 11 countries within its first month, including two Italian organizations: Doimo Cucine (a kitchen manufacturer) and NTE Italia (a telecommunications consulting firm), though neither has publicly confirmed the incidents. The operation's support for VMware ESXi hypervisor compromise is particularly significant for Italian enterprises, as it enables attackers to encrypt multiple virtual machines and services in a single operation. Panzer operates under a semi-open affiliate model with an 80/20 revenue split and advertises builds for Windows, Linux, ESXi, and FreeBSD, with dual-extortion capabilities that compound regulatory risk under GDPR and NIS2.
Why it matters: Italian and Central European manufacturing and technology firms face immediate risk from Panzer's ESXi-targeting capability and rapid attack cycle (5 to 12 days from initial access to encryption), requiring urgent hardening of remote access controls, network segmentation around hypervisor management, immutable backups, and incident response readiness for regulatory notification within 72 hours of data exposure discovery.
- Source published
- First seen by Cybersecurity Tracker