News summary. This article summarizes the report on the cyberattack against Grupo Spaggiari Parma, a supplier of platforms used by Italian schools, published by Federprivacy.
Grupo Spaggiari Parma, which is responsible for platforms used by Italian schools, reported that it was the target of a cyberattack on August 20. Specialized platforms reported the extraction of 6.1 TB of data from more than 3,000 institutions and the publication of a sales offer for $50,000 on a hacking forum.
According to information released by the attackers, the material could include identity documents and medical certifications used in personalized educational plans for students with specific learning disorders or special educational needs. The post also mentioned a deadline of August 27, 2026, for ransom payment.
Grupo Spaggiari initially stated that the ClasseViva electronic register had not been breached and that the incident affected a separate part of its platform. In a statement dated August 26, 2026, the company said that the attack was confined to the Modulistica Smart module of the Bergantini platform, and that ClasseViva and Spaggiari's other services were not involved.
The company also stated that it is the data controller for the Bergantini platform and declared that the required measures vis-à-vis the Garante and the data subjects had already been completed. According to the statement, schools do not need to take any additional measures, teaching and administrative activities can continue without interruption, and the technical, organizational, and legal measures provided for were activated, with notification to the competent authorities.
With information from Federprivacy.
This post was summarized from the original publication using artificial intelligence, with human review.