Panzer: The Ransomware That Has Already Hit Italian Companies

Panzer: The Ransomware That Has Already Hit Italian Companies

Panzer ransomware: a new name with an experienced playbook

A new ransomware operation called Panzer surfaced in August 2026, and it did not arrive quietly. Within weeks of appearing, the group had published claims against Italian companies on its leak site, including the furniture manufacturer Doimo Cucine. For any business owner in Italy or the wider EU, this is the detail that matters most: a ransomware attack on Italian companies is no longer an abstract risk discussed at conferences, it is happening to mid-sized manufacturers with recognisable names.

What makes Panzer worth paying attention to is not novelty. It is maturity. Most new ransomware brands start small, with a single Windows encryptor and a handful of affiliates learning the trade. Panzer launched with an affiliate programme that already looked professionally structured, cross-platform payloads, and a ransomware double extortion model running from day one.

That combination usually means one of two things. Either the operators are experienced criminals rebranding after a previous group was disrupted, or they bought a mature codebase and infrastructure from someone who was. Neither scenario is good news for the businesses in their path.

What we know about the payloads

Panzer ships encryptors for Windows, Linux, VMware ESXi, and FreeBSD. That list is a strategic statement rather than a technical curiosity.

Windows coverage gets the attacker into the average office: file servers, workstations, domain controllers. Linux coverage reaches the application and database servers that quietly run production. FreeBSD support is less common and suggests the group expects to encounter appliances, storage systems, and network devices built on that base.

The ESXi payload is the one that should worry SMBs the most. A single successful attack against a virtualisation host can encrypt dozens of virtual machines simultaneously, which means the entire company disappears in one action rather than machine by machine. Many Italian SMBs consolidated their infrastructure onto two or three hypervisors over the past decade, and that consolidation is precisely what makes an ESXi encryptor so damaging.

Why ransomware as a service changes the math for SMBs

Panzer operates as ransomware as a service (RaaS). The core developers build and maintain the encryption tools, the leak site, the negotiation portal, and the payment infrastructure. Affiliates handle the actual intrusions and keep the larger share of any ransom paid, typically between 70 and 85 percent in this business model.

This structure has a direct and unpleasant consequence for smaller organisations. When attacking is franchised, the barrier to entry collapses. An affiliate no longer needs to write malware or run infrastructure, only to find a way in. That shifts the economics: attackers no longer need to hunt large enterprises to make the effort worthwhile, because the effort itself has become cheap.

Small and medium businesses become attractive targets not because they hold more valuable data, but because they are faster to compromise and more likely to pay quickly. A 60-person company with no in-house security team, one IT contractor, and an unpatched VPN appliance can be encrypted in under 48 hours from first access.

The numbers back this up. ENISA’s threat landscape reporting has consistently placed ransomware among the top threats affecting the EU, and Italy has been disproportionately represented in recent years. Clusit, the Italian association for information security, has repeatedly noted that Italy absorbs a share of global recorded attacks well out of proportion to the size of its economy, with manufacturing among the hardest hit sectors.

That last point deserves emphasis. Italian manufacturing is dense with mid-sized, family-controlled, export-oriented companies. They have valuable intellectual property, tight production schedules where downtime is expensive, and security budgets sized for a much simpler era. From an affiliate’s point of view, that is an ideal profile.

Ransomware double extortion: when backups are not enough

Traditional ransomware defence rested on one idea: keep good backups, refuse to pay, restore. Ransomware double extortion was designed specifically to break that logic.

Under this model, the attacker exfiltrates data before encrypting anything. Even if you restore every system perfectly from backup, the criminals still hold copies of your contracts, drawings, payroll files, customer lists, and email archives. The second demand is not for a decryption key, it is for silence.

For an Italian SMB, the exposure here is layered. There is the commercial damage of technical drawings or pricing reaching competitors. There is the reputational damage of customers seeing your name on a leak site. And there is the regulatory damage, which is where many companies underestimate the cost.

The regulatory bill

Under the GDPR, a data breach involving personal data must be notified to the Garante per la protezione dei dati personali within 72 hours of becoming aware of it, and affected individuals must be informed when the risk to their rights is high. Exfiltration of HR files or customer databases almost always triggers both obligations.

NIS2 raises the stakes further. Italy transposed the directive through Legislative Decree 138/2024, extending cybersecurity obligations to a far broader set of organisations than the original NIS framework, including many manufacturers, food producers, waste management operators, and digital service providers that never considered themselves regulated entities. Registration duties, incident reporting timelines measured in hours, and management accountability are all now in scope.

The practical translation: a ransomware incident in 2026 is simultaneously a technical crisis, a legal event, and a governance question your board is expected to answer. Building business continuity capability before the incident is considerably cheaper than improvising it during one.

What European SMBs should do now

None of the following requires an enterprise budget. All of it materially reduces the probability that a Panzer affiliate, or the next group to appear, gets a payday from your company.

Close the entry points

Most RaaS affiliates enter through a small set of doors: internet-exposed remote access without multi-factor authentication, unpatched edge devices (VPN concentrators, firewalls, file transfer appliances), and stolen credentials bought from initial access brokers.

Enforce MFA on every remote access path, including administrative accounts and any legacy protocol that bypasses it. Patch internet-facing appliances on a defined schedule rather than when convenient. Remove RDP exposure entirely if it still exists.

Protect the hypervisor as a crown jewel

Given Panzer’s ESXi payload, treat your virtualisation layer as a separate security domain. Management interfaces should not be reachable from the general user network. Hypervisor administrator credentials should be distinct from domain credentials, protected with MFA, and never reused. Lockdown mode and disabled SSH access are basic but frequently skipped steps.

Make backups genuinely unreachable

Backups that live on a share the domain administrator can write to are not backups, they are additional targets. Immutable storage, offline copies, and a separate authentication realm are what actually survive an attack. Equally important is testing restores on a schedule, because a backup that has never been restored is a hypothesis rather than a plan. Our backup and disaster recovery approach is built specifically around recovery time, not just data retention.

Detect the quiet phase

Between first access and encryption, attackers spend days moving laterally, escalating privileges, and staging data for exfiltration. That window is your best opportunity. Endpoint detection and response with active monitoring, whether in-house or delivered as a managed service, is what turns that window into an intervention rather than a post-mortem. Technologies such as those in our Sophos partnership are designed around exactly this detection-and-response model.

Rehearse the decision you hope never to make

Decide in advance who declares an incident, who talks to the Garante, who talks to customers, and who is authorised to negotiate or refuse. Write down the phone numbers of your legal counsel, your insurer, and your security provider, and keep that document somewhere that does not depend on the systems being encrypted.

Reading the Panzer signal correctly

Panzer will not be the last group to launch with a full affiliate programme and a cross-platform toolkit. If anything, the speed with which it reached maturity confirms that the RaaS supply chain now supports rapid rebranding and rapid scaling.

The defensive lesson is therefore not “watch for Panzer”. Indicators of compromise for a specific family age quickly, and the next brand will use different ones. The durable lesson is that the intrusion methods behind these operations have stayed remarkably stable: exposed access, missing MFA, unpatched edges, flat networks, and reachable backups.

Fix those, and you stop being the affiliate’s easiest option. In a franchised criminal economy where operators pick targets by effort required, that is a meaningful form of protection. You can review our full range of cybersecurity services to see where your current posture stands against these attack paths.

💬

Need support on this topic?

Let’s assess your company’s situation together. First consultation is free.

Contact us
📩

Stay updated every week

Cybersecurity, AI and technology for SMBs. No spam, only useful content.

Subscribe to newsletter

Content on this blog is written and reviewed by the editorial team of 10punto10 s.r.l., which holds editorial responsibility for the published content.