← Ferrari

2023 Ferrari — ransom demand over client contact data; refused payment; customer notifications

2023 Unknown records affected Share on X

Data compromised

Client contact and identification-oriented fields per Ferrari public statement and summarized customer notifications

Technical writeup

On 20 March 2023, Ferrari N.V. announced that Ferrari S.p.A. had been approached by a threat actor with a ransom demand tied to certain client contact details, launched a forensic investigation with a third-party firm, and notified authorities. The company stated it would not pay ransoms, notified customers of potential exposure, and said operations were not impacted. Follow-on reporting summarized customer notices as including names, addresses, emails, and phone numbers, with no evidence in Ferrari’s public messaging that payment-card or vehicle ownership/order details were compromised.

Root cause

Criminal extortion following unauthorized access to customer-contact holdings (full intrusion chain not detailed in public corporate statement)

References