Research from NETSCOUT found that the Milano Cortina 2026 Winter Games became the latest major international event to be targeted by hacktivist groups. During the Games, distributed denial-of-service (DDoS) attack rates increased substantially, compared to historical levels, with threat actors taking aim across the entirety of the event – from before the opening ceremony through to after its conclusion.
Throughout the event, targets ranged from critical visitor infrastructure (such as hotels, transportation and ski sites) to official organisations like ministries and consulates in areas with an affiliation to the Games.
Attacks escalated from two weeks prior to the games and eased upon their close. Attacks against Italian infrastructure in Italy were up 181% compared to 2025. Efforts escalated with the highest attacks in a single day reaching a peak of 2,200.
Attacks came from a range of groups with NoName057(16), Qilin and LockBit 5.0 all claiming responsibility for a number of incidents – though those have not been independently verified.
The campaign was not limited to Cortina itself, Milan saw a huge spike in cyberthreats as the Winter Games co-host.
In the lead up to the Games (January 20 – February 5) there were 4,963 attacks, averaging 300 daily. Attacks ramped up significantly during the Games with 12,963 attacks, averaging 720 daily attacks between February 6 – 23. Post-Games the attacks tempered again but this period still accounted for the most attempted attacks in a single day. This period saw 5,315 attacks, with a peak of 2,281 on February 24 – the day after the Games concluded, representing the highest number of attacks experienced in Italy in the past three years in a day.
NETSCOUT reported that attacks varied in technique, averaging more than two vectors per attack. UDP flooding was most common accounting for 85% of attacks, followed by DNS amplification in 19% of cases, and memcached amplification for 11.8% and NTP, STUN, SSDP and SNMP in less cases.
Recommended reading
- Report: Enterprise PCs Wide Open to Hackers 76 Days a Year
- NCSC Warns UK Business to Prepare for Iranian Cyber-attacks
- One in Ten UK Firms “Wouldn’t Survive” a Cyber-Attack
This persistent campaign of cyberattacks during the Milano Cortina 2026 Winter Games demonstrates how major international events create predictable windows for cyberthreat activity. The attack activity observed against Italy between January and March 2026 demonstrates an elevated DDoS threat landscape.
Excellent cyber defences are required to combat this threat, with upcoming sporting events likely to be no different. A strategic and co-ordinated cyber defence strategy will be required for the 2026 FIFA World Cup and Glasgow’s own 2026 Commonwealth Games.





