Background and Timeline: Reported on February 6 and 7, 2026, La Sapienza University in Rome, Europe’s largest by student population, confirmed it had been hit by a major cyberattack. The attack prompted the university to take its computer systems down for three days to prevent further lateral movement. The university’s website remained offline as the school began a total restoration process from backups starting over the weekend.
Modus Operandi: The ransomware attack encrypted workstations and limited email access across the entire university network. The attackers utilized a payload that specifically targeted administrative and student management platforms. The attack has been attributed to the pro-Russian hacktivist group Femwar02, which utilized encryption as a lever for geopolitical disruption rather than just financial ransom.
Victims and Financial Impact: Approximately 120,000 students and staff were affected by the total system outage, which disrupted classes and administrative functions. While the specific financial impact was not disclosed, the operational damage of a three-day total shutdown for Europe’s largest university is massive. The university is currently investigating whether any student PII or research data was exfiltrated before encryption.
Investigation and Agencies Involved: University security teams and Italian national cyber defense units are working on restoring services while investigating the initial entry vector. Forensic investigators are analyzing the ransomware payload to determine if it used known vulnerabilities in remote access software. They are coordinating with European security agencies to track the group Femwar02.
Arrests and Suspects: No suspects have been identified or arrested beyond the attribution to the group Femwar02. This group is known for carrying out geopolitically motivated disruptive attacks rather than profit-driven RaaS operations. The attackers demonstrate a high degree of technical skill in bypassing traditional perimeter defenses used by large educational institutions.
Broader Implications and Trends: Academic institutions remain prime targets for geopolitically motivated ransomware attacks due to their large user bases and the high impact of service disruptions. This incident underscores the importance of segmenting research networks from general administrative systems to mitigate the impact of a total lockout. It reflects a trend where ransomware is being weaponized for political protest.