Panzer ransomware hits Italian manufacturers and telecoms
Panzer ransomware is a ransomware-as-a-service (RaaS) group that has recently targeted Italian businesses, including manufacturers and telecom firms. Attackers encrypt files and demand payment, threatening to leak data if refused.
- Report priority
- High
- Involves
- VMware ESXi
- Group
- Panzer
What to do
If you're an Italian manufacturer, telecom firm, or any business using VMware ESXi, Windows, Linux, or FreeBSD systems, check if your company has been listed as a victim by Panzer ransomware on their public leak sites or news reports. If your files are encrypted or access is blocked, you may be under attack. Doimo Cucine and NTE Italia were allegedly targeted, but neither has confirmed the incident.
If your company is listed as a victim, do not pay the ransom without verifying the attack. Contact your IT team or cybersecurity provider immediately. Report the incident to Italian authorities, such as the Cybercrime Unit of the Italian Police or AGID (Italian Agency for Digital Italy). For technical support, consult VMware's ESXi security resources or your system administrator. If your files are encrypted, avoid using the attacker's recovery tools, restore from backups if possible.
Reported details
Panzer ransomware allegedly hit Doimo Cucine, a kitchen manufacturer in Treviso, and NTE Italia, a telecom engineering firm in Catanzaro. Both companies were listed as victims by the group, though neither has publicly confirmed the attack. The ransomware group also claims to have targeted businesses in 11 other countries.
A ransomware-as-a-service (RaaS) group called Panzer has targeted Italian manufacturers and telecom firms since August 5, 2026, with a focus on VMware ESXi virtualization hosts. The attack chain exploits compromised virtualization infrastructure, allowing attackers to encrypt multiple virtual machines at once, disrupting entire business operations rather than just individual workstations. Affected systems include Windows, Linux, FreeBSD, and ESXi, with no confirmed initial access method or payload analysis by researchers.
The group claims victims in 11 countries, including Italian firms Doimo Cucine (Treviso) and NTE Italia (Catanzaro), though neither has publicly confirmed the attacks. Panzer's RaaS model offers affiliates an 80/20 revenue split, with strict recruitment screening to prevent law enforcement or researcher infiltration. The ESXi capability is particularly dangerous, as compromising a hypervisor can halt dependent services across an entire virtualized environment.
Additionally, Panzer threatens data exfiltration, allegedly stealing 30 GB from Doimo Cucine and 16 GB from NTE Italia, adding pressure beyond encryption alone. No CVE or CVSS score is associated with this threat.