CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Manno (TI) commune cyberattack, August 2026

incident · incident:manno-ti-commune-ransomware-2026-08 single-source-victim

Cyberattack that encrypted data on part of the servers of the Ticino commune of Manno on 2026-08-04, restored from existing backups per the commune's notice of 2026-09-16; the ransomware group SafePay was recorded listing manno.ch on its leak site on 2026-09-28 (Comune di Manno; Ransomware.live).

Aliases: Manno commune attack

Coverage
1
first 2026-09-30 → last 2026-09-30
Latest activity
2026-09-30
Manno restored from backup within an afternoon; SafePay was recorded listing the commune on 28 September
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: switzerland
Sources cited
4
3 hosts

Defender insights

What each entry about Manno (TI) commune cyberattack, August 2026 tells a defender to do, newest first.

2026-09-30NOTABLEManno restored from backup within an afternoon; SafePay was recorded listing the commune on 28 September

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-09-30Swiss commune Manno (TI) confirms a cyberattack that encrypted part of its servers on 4 August 2026; SafePay is recorded listing the commune on a leak site on 28 September
    active-threatsManno restored from backup within an afternoon; SafePay was recorded listing the commune on 28 September

Hunting pivots

ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ImpactData Encrypted for Impact

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-09-30/manno-ti-commune-ransomware-safepay-claim · ATT&CK page ↗

Entries about Manno (TI) commune cyberattack, August 2026 (1)

2026-09-30 · view entry permalink →

NOTABLENATOA2

Swiss commune Manno (TI) confirms a cyberattack that encrypted part of its servers on 4 August 2026; SafePay is recorded listing the commune on a leak site on 28 September

The Ticino commune of Manno stated in a signed notice dated 2026-09-16 that on 4 August 2026 part of its servers suffered an attack that encrypted data (Comune di Manno, 2026-09-16). The commune isolated the affected server immediately and, per the notice, restored data and operations from existing backups in the course of the afternoon (Comune di Manno, 2026-09-16). It reported the case to the competent authorities, filed a criminal complaint against persons unknown, and told residents to distrust unexpected letters or e-mails that demand urgent payments or personal or financial data and to verify through official channels (Comune di Manno, 2026-09-16). The notice names no actor, no intrusion vector, and does not say whether data left the network. Inside IT's teaser of 2026-09-29 calls it a ransomware attack and says a backup allowed a quick return to normal operation (Inside IT, 2026-09-29). The tracker's leak-post screenshot shows a countdown timer of about three days eleven hours when it was captured on 2026-09-28, which points to expiry around 1 October; the post describes no dataset (Ransomware.live, 2026-09-28).

On 2026-09-28, 55 days after the encryption, Ransomware.live recorded that the ransomware group SafePay had listed manno.ch on its leak site (Ransomware.live, 2026-09-28). That is the group's claim as recorded by a tracker: the commune has not confirmed it, and the record shows neither what data the listing claims nor that it concerns the 4 August event.

on 4 August 2026 part of the commune's servers suffered an attack (translated from Italian)

which resulted in the encryption of the data (translated from Italian)

subsequently a complaint was lodged against (translated from Italian)

the population is urged to pay attention to unexpected communications (translated from Italian)

Comune di Manno (Municipio) 2026-09-16

Ransomware.live discovered on 2026-09-28 that manno.ch has been claimed by Safepay ransomware group

Ransomware.live

A ransomware gang attacked servers of the Manno municipal administration and encrypted part of the data (translated from German)

Inside IT
incident30 Sep 04:41Zsingle-source · victim disclosureOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • manno.ch2 (50%)
  • inside-it.ch1 (25%)
  • ransomware.live1 (25%)