Italian authorities are investigating claims by the LockBit ransomware gang that they breached the network of the Italian Internal Revenue Service (L'Agenzia delle Entrate).

See also: Phishing campaign targets LinkedIn employees who manage Facebook Ad Accounts
LockBit claims to have stolen 100GB of data (including corporate documents, scans, financial reports , and contracts) that will be leaked online if the Italian tax agency does not pay a ransom demand by August 1.
The Italian revenue agency released an official statement on its website regarding “alleged theft of data from the tax information system,” saying it had requested more information from Sogei (Società Generale d'Informatica) SpA, a public company of the Ministry of Economy and Finance that manages the technological infrastructure of the financial administration.
"From the technical investigations carried out, Sogei rules out that a cyberattack may have occurred on the Agency's website," the agency said.
See also: Source code of info-stealer malware is available on hacking forum

Sogei SpA also manages the IT infrastructure used by other Italian services, including the Ministries of Justice, Interior and Education, the Attorney General and the Ministry of Finance.
"Regarding the alleged cyberattack on the tax information system, Sogei spa informs that from the initial analyses carried out, no cyberattacks nor has data been stolen from platforms and technological infrastructures of the Financial Administration," the public company said.
"From the technical investigations carried out, Sogei therefore rules out a cyberattack on the Revenue Service website.".
See also: CosmicStrand UEFI malware infects Gigabyte and ASUS motherboards
Sogey SpA added that it is currently cooperating with and supporting an ongoing joint investigation coordinated by the Italian National Cybersecurity Agency and the Postal Police.

The LockBit ransomware gang first appeared in September 2019 as ransomware-as-a-service (RaaS) and re-released as LockBit 2.0 RaaS in June 2021 after ransomware groups were banned from posting on cybercrime forums.
In February, the FBI released a flash alert with indicators of compromise related to LockBit ransomware attacks (representing 40% of all known ransomware attacks in May 2022), asking organizations targeted by affiliates of this RaaS to urgently report the incident.
Last month, LockBit released “LockBit 3.0,” introducing the first ransomware bug bounty program, new extortion tactics , and Zcash cryptocurrency payment options.
Information source: bleepingcomputer.com
