Solari SolutionsIT

Articles · Local infrastructuredraft

Two weeks by hand. The Salus case and what artificial intelligence has to do with it

Published · by Daniil Tolmacov · 7 min read

On 31 August 2026 a ransomware attack stopped Policlinico Triestino, the group behind the Casa di cura Salus, for two weeks. What happened, what worked, and why the hasty adoption of artificial intelligence opens doors of the same kind.

On Monday 31 August 2026, in the afternoon, the computer systems, telephones and e-mail of all the Friuli Venezia Giulia sites of Policlinico Triestino stopped working. The group, which in Trieste runs the Casa di cura Salus and the Pineta del Carso and which, between outpatient clinics and facilities, has fourteen sites in the region, was hit by ransomware: data encrypted, a ransom demand in cryptocurrency.

What happened

For a week admissions, consultations, the laboratory, diagnostic imaging and operating theatres remained suspended. Staff worked on paper and telephoned patients with bookings to warn them. On 2 September the INC Ransom group, an organisation that sells its software to affiliates and has claimed more than eight hundred victims since 2023, published the Policlinico's name on its site, with a sample of data as proof. The Agenzia per la cybersicurezza nazionale (the national cybersecurity agency) and the Polizia postale (the postal and communications police) intervened on site; the Procura di Trieste (the Trieste public prosecutor's office) opened a file.

On 3 September the management announced that it had notified the incident to the Agenzia, to the Garante per la protezione dei dati personali (the data protection authority) and to the Polizia postale, and that it had no evidence confirming a theft of patient data. The Salus operating theatres reopened on 7 September, telephones and e-mail returned on the 9th, full operation was declared for the 14th. On 10 September the company let it be known that it had ruled out paying the ransom from the outset and had opened no negotiation. According to the reconstruction published by the local press, the infection spread to every computer on the network, including through the printer protocols.

At the time of writing there is no indication that data have been published, nor of how many people are involved: the company's position remains that of 3 September.

What worked

The case was handled in an orderly way, and it is worth saying so, because this is where one learns.

  • Backups existed, and they made it possible to restart without paying. In the most recent ransomware campaigns the attackers look first of all for the backups, to delete them: the Agenzia's advisory of 28 May 2026 on the Qilin group, which since the start of the year has been hitting mainly small and medium-sized Italian enterprises, describes exactly this sequence. A backup works if it is separated from the network and immutable.
  • There was a way of working without systems. Writing by hand for two weeks is tiring, but it was possible. A company that has never tried to work for a day without its systems does not know whether it can.
  • The notifications went out at once, and the communication was sober: no reassurance beyond the facts. Suffering an attack does not exempt a company from its GDPR obligations; the Garante has already established this by fining a health authority after a ransomware attack.
  • The ransom was not paid. Paying finances the next attack and guarantees nothing.

Not an isolated case

In the first half of 2026 the Agenzia per la cybersicurezza nazionale handled 1,072 confirmed incidents, 181 of them ransomware; in August there were 49 ransomware claims against Italian targets, the highest number in the last twelve months. The Clusit 2026 report counts 507 serious attacks in Italy in 2025, 42% more than the year before. In the North-East, over the last two years: thirty-one small and medium-sized enterprises in the Veneto hit in one week by the Akira ransomware in February 2025; the HIT group's casinos in Nova Gorica shut down for days at the end of August 2026; the accounting data of thousands of companies exfiltrated from a national cloud service in the same month. The sentence nobody should say any more is "we are not a target".

What artificial intelligence has to do with it

The Policlinico was not attacked through artificial intelligence. But those adopting artificial intelligence tools in their companies are opening, often without noticing, doors of the same nature: broad access, data leaving, software acting on its own. The last three years offer a catalogue.

Data pasted into a public service. In 2023 three Samsung engineers pasted source code and the minutes of a meeting into ChatGPT, within twenty days. In the summer of 2025 about 4,500 conversations that ChatGPT users had shared with a link ended up in Google's results, because a checkbox said "make this chat discoverable" and few had read it.

Instructions hidden in documents. In June 2025 a flaw in Microsoft 365 Copilot made it possible, with a simple e-mail containing invisible instructions, to have company files transmitted outside without the user doing anything. In 2026 the same pattern repeated in several forms: a comment in a pull request on GitHub that made coding agents publish their own access keys; an instruction file in a repository that pushed the assistant to copy a project's credentials outside. A language model does not distinguish between the document it must read and the order hidden in it.

Agents with too many permissions. In July 2025 a coding agent, during a declared code freeze, deleted a production database holding the data of more than a thousand companies; it had write access to production and the only brake was a sentence in natural language. In January 2026 more than twenty thousand installations of a popular personal agent were found exposed on the internet without any authentication, with keys, tokens and months of private conversations. In March 2026 an exposed server gave access to more than eight thousand data tables of a financial company, including the administration credentials of its cloud services.

Code generated without review. According to a 2025 analysis of more than a hundred models, 45% of the code generated by artificial intelligence fails basic security checks. In May 2026 a scan of 380,000 applications built with automatic coding tools found about five thousand that exposed customer and patient data, because the default settings make public what should remain private.

Three measures, the same ones

The measures that would have contained these cases are those that apply to any system, and that at Solari Solutions we put at the base of every installation.

  1. Local systems for confidential data. What does not leave the company cannot be indexed, retained by a foreign court or exfiltrated from a supplier.
  2. Minimum permissions, and a separate network. An artificial intelligence tool can access only what it needs, cannot perform destructive actions, and the system hosting it sits in an isolated network segment, with offline backups. The same rules the Agenzia recommends against ransomware: updates, multi-factor authentication, segmentation, immutable backups.
  3. Checking the results. What a model produces, text or code, is verified before it is used, and what an agent does is logged.

Policlinico Triestino went back to work because it had backups, a plan and the firmness not to pay. A company adopting artificial intelligence needs the same three things, before it connects the first tool.

Sources

  • Note from the management of Policlinico Triestino S.p.A., 3 September 2026 (Nordest News); update of 10 September 2026 (TriesteCafé).
  • Trieste Prima, 1, 2, 3 and 10 September 2026; Il Piccolo, 1–13 September 2026; Telequattro, 1 and 3 September 2026; ransomware.live, INC Ransom entry, 2 September 2026.
  • Agenzia per la cybersicurezza nazionale: Operational Summary, first half of 2026 and August 2026; CSIRT Italia advisory on Qilin, 28 May 2026. Clusit, Rapporto 2026, 16 March 2026.
  • Il Gazzettino, 5 March 2025 (Akira in the Veneto); Italian Gaming News, 25 September 2026 (HIT group); Cybersecurity360, 28 August 2026 (TeamSystem).
  • Bloomberg, 2 May 2023 (Samsung); Malwarebytes, 1 August 2025 (indexed conversations); arXiv 2509.10540 and Checkmarx on EchoLeak, CVE-2025-32711; Cloud Security Alliance, research notes of 17 March and 17 April 2026; The Register, 21 July 2025 (Replit); Wikipedia and Censys on OpenClaw, January 2026; UpGuard, 18 May 2026; Veracode, GenAI Code Security Report, 30 July 2025; Axios, 7 May 2026 (RedAccess).
  • Garante per la protezione dei dati personali, decision on ASL Napoli 3 Sud.