In May 2026, a cyber espionage operation compromised the systems of Sistemi Informativi S.p.A., the IBM subsidiary that manages the IT infrastructure of the Italian public administration, potentially exposing ministries, government agencies, and public entities.
The attribution to the Chinese group Salt Typhoon—a unit linked to Beijing’s Ministry of State Security—remained unconfirmed by official sources: IBM stated that the systems were stable without providing details on the scope of the breach, while Rome’s counterterrorism unit opened an investigation. In February of the same year, approximately 120 cyberattacks of Russian origin targeted Italian embassies on four continents, Olympic sites in Cortina, and Ministry of Foreign Affairs websites—a campaign claimed by the pro-Kremlin group NoName057(16).
These incidents are not exceptions: Italy ranks fourth globally and first in Europe in terms of the number of attacks suffered, with a 27.4% increase in the frequency of incidents over the last reported year. Yet, in the face of this external pressure, a series of documented facts highlights how digital intelligence resources and capabilities are systematically directed elsewhere: toward its own citizens, toward its allies, and toward its European partners.
Allies as Targets: The BND Precedent and the Paragon Case
The most significant case from a structural standpoint remains the scandal involving the Bundesnachrichtendienst (BND), Germany’s foreign intelligence service. Between 2012 and 2015, the BND provided technical assistance to the U.S. NSA to conduct surveillance operations on senior officials at the French Ministry of Foreign Affairs, the Élysée Palace, and the European Commission, with a scope that extended to the interior ministries of Poland, Austria, Denmark, and Croatia, as well as the embassies in Berlin of France, Great Britain, Sweden, Italy, Spain, Portugal, Greece, and Switzerland, including the Vatican.
In Italy, between 2023 and 2024, the AISI and AISE intelligence agencies used the Graphite spyware developed by the Israeli company Paragon Solutions to infect the devices of journalists and “immigrant rights” activists. Prosecutors in Rome and Naples determined that the devices belonging to Fanpage editor-in-chief Francesco Cancellato and Mediterranea activists Luca Casarini and Beppe Caccia showed signs of infection on the night of December 14, 2024—three consecutive attacks likely part of the same campaign. COPASIR justified the use of spyware as a means of combating irregular immigration. Paragon terminated its contract with the Italian government after the latter refused an independent technical audit: for the first time in history, a commercial spyware company has publicly abandoned a government client, citing concerns about abuse.
The Italian case is not an isolated one in the European context. The use of commercial spyware by governments of EU countries—including Hungary, Spain, and Poland—against political opponents, journalists, and, in some cases, allied heads of state has been widely documented. This constitutes a systematic use of offensive cyber tools which, regardless of the formal legality of individual operations, directly erodes intra-European trust and diverts resources away from identifying external threats.
External Pressure: Scope and Dynamics of the Threat in 2026
The European threat landscape provides the necessary framework for assessing the severity of the imbalance described. Ransomware attacks against European organizations have increased by 23% over the past year, while attacks on the digital supply chain—a preferred method for indirectly accessing public administrations—have risen by 42%. The average time to detect a breach in Europe still stands at 18 days: nearly three weeks during which an adversary can operate undisturbed within a government’s networks.
The Salt Typhoon campaign is the most emblematic example of the Chinese threat. The group has compromised telecommunications networks in over 80 countries, targeting more than 200 organizations, including nine U.S. telecommunications operators and, more recently, European providers. A targeted attack on a major European telecommunications company replicated the same techniques used against AT&T and Verizon: exploiting vulnerabilities in Citrix systems to gain persistent remote access to networks, with the aim of intercepting government and military traffic.
On the Russian front, NoName057(16) has operated continuously against NATO countries, with an escalation of attacks targeting Italy that included—in addition to the incidents surrounding the February 2026 Olympics—the websites of Mediobanca, Nexi, Benelli Armi, and Fiocchi Munizioni, as well as the portals of various ministries, the Carabinieri, and the Guardia di Finanza. Each campaign was explicitly linked to public statements by Italian authorities regarding Ukraine, outlining a model of reactive hybrid deterrence. At the same time, the war in Iran that broke out on February 28, 2026, accelerated Iranian cyber operations against European energy and port infrastructure, exploiting the West’s geopolitical distraction to expand its scope of action.
Three Proposals for a Paradigm Shift
The analysis of the described paradox—internal offensive capabilities coupled with inadequate collective defenses—points to three areas for structural intervention, the implementation of which is technically feasible within the current institutional framework.
The first concerns the completion of a fully operational European cyber defense architecture. The European Commission’s cybersecurity package of January 20, 2026, which includes the Cybersecurity Act 2 and targeted amendments to NIS2, is a step in the right direction, but its adoption is not expected before the end of 2026 or early 2027. Meanwhile, only 16 of the 27 member states had transposed NIS2 by the start of the year, forcing the Commission to launch infringement proceedings against 23 states. Regulatory convergence is a necessary but not sufficient condition: an operational center with a mandate for real-time response is needed, one that is not subject to the unanimous consent of national governments.
The second area of action concerns the protection of the fundamental right to digital privacy and the resulting European regulation of commercial spyware. The right to privacy in personal communications is enshrined at two distinct and converging regulatory levels: Article 7 of the Charter of Fundamental Rights of the European Union establishes its primary legal basis, while EU Regulation 2016/679 (GDPR) translates its principles into binding operational obligations for all entities that process the personal data of European citizens, including public authorities. Both legal frameworks converge on the same imperative: no invasive surveillance tool can be considered compatible with European law in the absence of an explicit, proportionate legal basis subject to independent oversight. Yet neither instrument has so far established a uniform and binding procedural threshold for the use of spyware: no invasive surveillance tool should be allowed to be installed on an electronic device without prior authorization from the national judiciary and under the oversight of an independent parliamentary body, also at the national level. National—rather than supranational—parliamentary oversight is the appropriate safeguard here: it is up to the legal systems of individual Member States to ensure that their authorities operate within the bounds of the law, with mechanisms for democratic oversight rooted in domestic law.
This procedural threshold yields an analytical corollary of strategic importance. Once it is established that any installation of spyware not authorized by the judiciary of a Member State constitutes a violation of the fundamental right to privacy, it follows that any spyware found on a device outside of that procedure is necessarily of external and hostile origin. The adoption of the third point—a binding non-spying agreement among European Union member states—would also make it possible to rule out other EU states as potential perpetrators: a compromised device without a judicial order, in a context where European allies have contractually renounced mutual surveillance operations, points by exclusion to a source outside the continent. Regulating spyware is therefore not merely a measure to protect individual rights, but a tool for attribution and geopolitical deterrence, transforming a legal guarantee into a defensive intelligence capability.
The third proposal concerns, precisely, a binding intra-European non-espionage agreement. The discussion launched following the 2015 BND-NSA scandal petered out without producing any results. In 2026, with the war in Ukraine requiring intelligence cohesion, the Iranian crisis putting pressure on continental energy networks, and China systematically infiltrating European telecommunications, continuing to direct intelligence resources toward allies represents an unsustainable strategic cost. A no-spy treaty with credible verification mechanisms would free up capabilities to be redirected toward real adversaries and restore operational trust among national intelligence services—a prerequisite for any form of effective collective cyber defense. Until this reform moves forward, Salt Typhoon and its successors will continue to find a continent that is technically regulated but strategically disunited: the easiest possible target.