For two weeks, the servers that manage the social-security data of millions of Italians were under the control of a hacking group tied to China. No ransomware, no ransom demand: just silent, systematic harvesting of information. The goal of Salt Typhoon — that’s the group’s name — is not money. It’s to know everything about everyone. The story broke in the very first days of May 2026 and concerns Sistemi Informativi, a company controlled by IBM that runs the digital infrastructure of INPS, INAIL, government ministries and part of the national health system.
If you’ve ever paid a contribution, filed a social-security claim, or had a workplace injury recorded — your data was in there.
What happened: two invisible weeks
Salt Typhoon is classified as an APT (Advanced Persistent Threat): it doesn’t break in, strike and leave. It gets in, hides, and stays. For weeks, sometimes months. The aim isn’t to destroy data or demand ransoms, but to exfiltrate it silently — copy it, send it somewhere, and vanish without leaving obvious traces.
In this case, the attackers are believed to have stayed active for roughly two weeks before internal technicians, backed by the Agenzia per la Cybersicurezza Nazionale (ACN) (National Cybersecurity Agency), noticed the intrusion. How did they get in? According to the first reconstructions, through a compromised API key tied to a cloud system. Not some sophisticated, Hollywood-style attack: a door left ajar in the IT architecture of a vendor that manages state data.
Sistemi Informativi works with INPS, INAIL, the national public-administration cloud, the digital PNRR projects and the health system. In practice, it is the computing heart of the Italian public administration. And for two weeks, someone was living inside it.
What you’re actually risking
The question everyone is asking is: was my data stolen? The honest answer, right now, is that nobody knows for certain. The ACN has stated that it is working to determine “the origin and possible impact of the attack.” The systems have been stabilized and services restored. But no one is able to say precisely which data was exfiltrated.
What we do know is the type of data these systems had access to:
- INPS data: contributions paid, employment status, income situation, contractual history, information on pensions and social safety nets.
- INAIL data: workplace injuries, occupational diseases, medical and insurance information.
- Ministerial and health data: depending on which nodes were actually compromised.
Salt Typhoon doesn’t operate for the data black market. It works for the Chinese state, with geopolitical objectives: profiling public officials, workers in sensitive sectors, people with institutional roles. But in a system where the data of 60 million Italians is aggregated into a single infrastructure, even “ordinary citizens” become potentially valuable as indirect vectors.
The systemic problem: your data isn’t yours
This attack raises an issue that goes far beyond Salt Typhoon: the model by which the Italian public administration manages citizens’ data is inherently vulnerable. Centralizing everything into a single infrastructure, entrusted to a private vendor (IBM, in this case), creates a huge target. A single point of failure that, once compromised, exposes millions of people at once.
You didn’t choose to entrust your social-security data to Sistemi Informativi. You signed nothing. And yet your data was there, and now it may be in unknown hands.
This is the paradox of absent digital sovereignty: the state collects your data under legal obligation, delegates it to private entities, and when those entities are breached — you’re not a party to it. You’re simply the “data subject” who will, perhaps, receive a belated notification.
What you can do (even if you can’t “protect yourself” from this)
Being honest matters: there is nothing you can do to stop INPS from holding your contribution data. It’s mandatory by law. But there are some concrete steps worth taking:
Monitor your digital identity. Use services like HaveIBeenPwned to check whether your email addresses have shown up in previous breaches. It won’t fix this particular case, but it gives you a general view of your exposure.
Turn on two-factor authentication everywhere. If your data has been stolen and someone tries to use it to access your accounts, 2FA is your last line of defense.
Be skeptical of unexpected communications. After a breach of this scale, attempts at targeted phishing (spear phishing) increase: emails or texts that use real information about you to seem credible. Don’t click links in messages you didn’t request.
Separate your digital identity where you can. Use email aliases for online services, don’t reuse the same credentials, and consider a password manager like Vaultwarden (we’ll cover it in our self-hosting series).
Conclusion
The Salt Typhoon attack on Sistemi Informativi IBM is not an isolated incident: it’s a signal of how structurally fragile the cybersecurity of the Italian public administration is, and of how citizens’ data is exposed to risks no one ever asked them to accept. You can’t opt out of the social-security system. But you can start building around yourself a digital hygiene that limits the damage when — not if — the next breach arrives.
Sources:
- Hacker cinesi Salt Typhoon attaccano IBM Italia – Il Fatto Quotidiano
- Maxi attacco hacker cinese: rubati dati di Inps e Inail – Il Giornale
- IBM Italia colpita da Salt Typhoon: il cyberspionaggio cinese entra nella PA – ICT Security Magazine
- Attacco a Sistemi Informativi: la PA italiana è fragile – Cyber Security 360
- Personal data breaches in Europe reach 443 per day – DLA Piper