Skip to content
Deep Analysis8 min read

The Equalize Case: Anatomy of the Largest Government Database Theft in Italian History — 800,000 Victims, 52,811 Unauthorized SDI Accesses, and What NIS2 Would Have Changed

10 April 2026|AEGIDA Research Team

On April 9, 2026, the Milan Prosecutor's Office led by Marcello Viola closed the second major strand of the Equalize investigation, notifying 81 new suspects and requesting trial for Enrico Pazzali, former president of Fondazione Fiera Milano and owner of the investigative agency at the center of what is now considered the most serious compromise of public databases in Italian Republic history. Among the new suspects: Leonardo Maria Del Vecchio (son of the Luxottica founder), Fulvio Pravadelli (former Publitalia manager), Stefano Speroni (head of ENI legal department), Italian Financial Police general Cosimo Di Gesù, and Giacomo Tortu. Among the 650 confirmed victims are Paolo Scaroni, Bobo Vieri, Selvaggia Lucarelli, Fabrizio Corona, Alex Britti — and according to prosecutors, also Prime Minister Giorgia Meloni.

But the real scandal isn't the names. It's the "how". For over five years — from 2019 to March 2024 — a structured criminal organization had continuous, undisturbed, complete access to the most sensitive databases of the Italian State: SDI (Ministry of Interior Investigation System), Serpico (Revenue Agency), ANPR (National Resident Population Registry), and Bank of Italy archives. They performed 52,811 unauthorized SDI accesses and 108,805 violations of judicial and administrative archives. They profiled 800,000 Italian citizens. They generated over 3.1 million euros in illicit profits. And they did it from a modest room behind Milan's Cathedral, with a mix of malware, insider complicity, and systematic exploitation of organizational vulnerabilities that the NIS2 directive — if fully in force and applied — should have made impossible.

Equalize Srl: A Business Intelligence Firm with Unlimited Access

Equalize Srl was a Milan-based business intelligence firm marketed as a provider of legal due diligence services, asset investigations, and reputational analysis for banks, multinationals, and law firms. On paper, perfectly legal. In reality, according to Milan prosecutors, a structured criminal organization with a "dossier central" capable of producing — on customer request and for payment — complete information profiles on any Italian citizen, drawing directly from the State's most confidential databases.

At the top was Carmine Gallo, former senior State Police officer — a "supercop" with decades of experience in the most delicate investigations, including counter-terrorism and anti-mafia. Gallo personally knew law enforcement information systems, access procedures, audit mechanisms, and the people running them. His role was relational, not technical: he opened doors, built trust, activated complicity. Above him, Enrico Pazzali, a leading figure of the Milan establishment, president of Fondazione Fiera Milano. Below him: Nunzio Samuele Calamucci, 44, an IT consultant with a hacking background, the man who built the data exfiltration infrastructure and installed the Remote Access Trojans in the Ministry of Interior servers.

The Equalize investigation documented 52,811 unauthorized accesses to SDI alone (Ministry of Interior Investigation System) and 108,805 additional violations of judicial and administrative archives. Estimated profit: over 3.1 million euros between 2019 and March 2024. Profiled victims: about 800,000 Italian citizens. The largest theft of public data in Italian history.

The Four Pillaged Databases: Map of the Disaster

To understand the gravity of the Equalize case, you must understand what the compromised databases contain. Not email lists — the informational core of the Italian State.

SDI (Sistema d'Indagine), established in 1981, is the central archive of all Italian police forces. It contains: criminal records, dangerousness reports, complaints, arrest warrants, confidential intelligence, passport and weapons data, surveillance subjects, ongoing investigations. Every access should be tracked, motivated, authorized. Equalize had continuous access for five years.

Serpico is the Revenue Agency database integrating tax returns, bank accounts, VAT numbers, financial transactions above threshold, income meters, tax assessments. The system that lets the Italian fisc know practically everything about every taxpayer's economic life. Equalize used it to profile financial vulnerabilities of victims and targets — some queries, according to the investigation, were performed "at Pazzali's request" through Financial Police general Cosimo Di Gesù.

ANPR is the centralized registry of all Italian residents. And Bank of Italy archives contain banking supervision data, anti-money-laundering suspicious activity reports, financial exposures of individuals and companies.

  • SDI (Interior Ministry): 52,811 documented unauthorized accesses — criminal records, investigations, surveillance
  • Serpico (Revenue Agency): tax queries — incomes, accounts, financial transactions
  • ANPR (National Registry): residential records — civil identity of citizens
  • Bank of Italy: banking supervision, anti-money-laundering reports, financial exposures
  • Judicial and administrative archives: 108,805 additional documented violations

Attack Architecture: RAT, Insiders, and Centralized Aggregation

Equalize's operational model was a sophisticated hybrid combining three distinct vectors: technical malware, insider complicity, and engineering of an aggregation platform. None of the three vectors alone would have been sufficient. Together, they formed a practically invisible data exfiltration system.

Vector 1: The Remote Access Trojan in Ministry Servers

The first vector was installation of a Remote Access Trojan (RAT) inside Ministry of Interior servers hosting SDI. A RAT provides attackers complete remote control of the infected machine — executing commands, exfiltrating files, taking screenshots, recording user sessions — staying completely under the radar by behaving as a legitimate application at the lowest OS levels.

The RAT was used to download entire blocks of records from SDI without generating the access logs normally produced by an authorized police query. While an officer consulting SDI leaves traces in central logs (who, when, why, what was searched), a RAT operating at system level can completely bypass this audit system, copying data directly from the database or filesystems. The RAT installation, according to prosecution reconstructions, was facilitated by complicity of IT technicians who had physical or remote access to Ministry servers — the classic weak link in the chain.

Vector 2: Insider Threat and the "Trust Chain"

The second vector, perhaps the most devastating, was structured insider threat. The investigation documented multiple database accesses performed directly by law enforcement personnel — both active and retired — using their legitimate credentials to extract information then passed to Equalize for compensation. In other cases, Financial Police officers, "at Pazzali's request," accessed Serpico to acquire confidential data on target companies.

This is the most insidious dynamic, because technically there is no "intrusion": credentials are valid, access is authorized, queries respect formal protocols. What's missing is "need-to-know" and legitimacy of purpose. An audit system can track who accesses, but not whether that consultation actually serves an official investigation or whether the data will be sold to a private investigation agency. Prosecutors could only reconstruct these accesses through phone and ambient wiretaps, not through database security systems. The information security controls completely failed.

Calamucci, in wiretaps, bragged: "We can disgrace all of Italy". The phrase, recorded by investigators, sums up in eight words the level of access the organization had obtained. For five years, a private group had control over State databases superior to that of many legitimate public authorities.

Vector 3: Calamucci's Aggregation Platform

The third vector was Calamucci's creation of a software aggregation platform that enabled integrated querying of data extracted from SDI, Serpico, ANPR, and Bank of Italy. Calamucci built a "private SDI" — a centralized search interface that, given a name or fiscal code, returned a complete dossier aggregating information from all compromised sources. This platform turned data theft into a scalable service: industrialization of cybercrime applied to private intelligence.

Why Five Years Undetected? The Failure of Controls

How were 52,811 unauthorized SDI accesses missed for five years? The State should have audit logs, anomaly detection, access pattern monitoring. The answer is a combination of technical, organizational, and cultural failures.

Technically, the RAT in Ministry servers bypassed application-level logging — accessing data at a lower level invisible to SDI audit mechanisms. Organizationally, existing logs weren't analyzed with User and Entity Behavior Analytics (UEBA) capable of detecting anomalies like "this officer makes 200 queries/day vs colleague average of 15," or "this access happens at 3 AM Sunday." Culturally, the idea that the threat could come from inside — from police officers, financial guards, IT technicians of the same administration — was marginalized, because the dominant mental model was the external attacker.

Furthermore, the various compromised databases belong to different administrations (Interior, Revenue, Bank of Italy) that don't share access logs and lack a centralized correlation system. No entity could observe that the same identity was being queried simultaneously in SDI, Serpico, and ANPR — a pattern that, if detected, would have triggered immediate alerts.

NIS2: What the New Directive Would Have Changed

Here is the most important point for those operating in Italian information security. NIS2 (2022/2555), implemented in Italy through Legislative Decree 138/2024, came into force just as the Equalize case publicly exploded. Key terms: notifications by January 2026, technical and organizational measures by October 2026. For the first time in Italian history, central and regional public administrations — including the Ministry of Interior, Revenue Agency, and Bank of Italy (for non-excluded components) — are subject to binding cybersecurity obligations, with significant penalties for non-compliance.

What would NIS2 have required, if fully applied before 2019? At least five things, each potentially capable of stopping Equalize. First: systematic risk management with explicit identification of insider threats. Article 21 imposes "appropriate and proportionate" technical and organizational measures, and ENISA guidelines explicitly include insider threat as priority risk for essential entities.

Second: supply chain security. Equalize is also a case of IT supplier compromise — technicians with Ministry server access weren't necessarily Ministry employees. NIS2 requires essential entities to evaluate and manage security risks in supplier relationships. Third: continuous monitoring and incident management — UEBA would have detected Equalize's anomalous access patterns. Fourth: incident notification to ACN within 24 hours (early warning) and 72 hours (complete notification). Fifth, perhaps most important: governance and accountability — NIS2 introduces direct responsibility for management bodies.

NIS2 (Legislative Decree 138/2024) requires Italian public administrations: risk management (including insider threat), IT supply chain security, continuous monitoring, incident notification to ACN within 24h, direct responsibility of management bodies. Penalties up to €10 million or 2% of revenue for essential entities. Mandatory technical measures by October 2026.

NIS2 Limits in the Equalize Case

It would be wrong to present NIS2 as the definitive solution. NIS2 has explicit exclusions for entities operating in national security, public order, defense, judiciary, parliament, and central banks — paradoxically, the most sensitive systems may be least covered. Furthermore, NIS2 doesn't solve institutional insider complicity: if a Financial Police general decides to abuse access, no technical system can completely stop him. And NIS2 has long compliance timelines, with the concrete risk of "compliance theater" producing documentation but not real risk reduction.

Operational Lessons for Italian Companies and Entities

  1. 1.Treat insider threat as a risk equal to external threat. The employee, consultant, supplier with privileged access is statistically among the most likely compromise actors.
  2. 2.Implement User and Entity Behavior Analytics (UEBA) on systems handling sensitive data. Not enough to log accesses: logs must be correlated with behavioral baselines.
  3. 3.Rigorously apply least privilege and need-to-know. No user should access databases or records not strictly necessary to their work.
  4. 4.Independent annual audits of critical databases by external auditors, including penetration testing and historical log analysis.
  5. 5.IT supply chain monitoring. Every consultant and software supplier with access to critical systems must be identified, tracked, and risk-assessed.
  6. 6.Sensitive system segregation with dedicated jump boxes, mandatory MFA, recorded sessions for administrative activities.
  7. 7.Security culture at the top. NIS2 management responsibility is the opportunity to bring security to strategic decision-making.
  8. 8.Cooperation with ACN and CSIRT Italy. Establish operational channels before an emergency requires them.

Conclusion: A Wake-Up Call We Cannot Afford to Ignore

The Equalize case is a brutal photograph of everything that doesn't work in Italian institutional cybersecurity: underestimated insider threats, uncontrolled IT suppliers, unanalyzed logs, organizational fragmentation, absent security culture at the top. Each of these vulnerabilities is solvable. None requires exotic technology. All require political will, serious investment, and radical revision of how the State thinks about its information security. NIS2 offers a framework, but it's an opportunity only if implemented substantively, not bureaucratically. For private companies in NIS2 scope, Equalize is a wake-up call: your most sensitive data is potentially exposed to the same attack vectors. Compromised insiders, uncontrolled IT suppliers, unmonitored logs, consultants with privileged access. Defense begins by recognizing that the "external phishing attacker" model is only a minor part of real risk. The rest is inside the house.

Primary sources: ANSA — Equalize case 81 closed investigations (April 9, 2026), Il Fatto Quotidiano — Equalize Pazzali trial (April 9, 2026), Sky TG24 — Equalize case trial, The Record (Recorded Future) — Italy arrests illegal dossiers, Sasakawa Peace Foundation — Lessons from Italy's Equalize case, Bank Info Security — Private Firm Accessed Italian Govt Database, Security Affairs — Crime ring compromised Italian state databases, Open Online — "We can disgrace all of Italy" (October 28, 2024), Il Sole 24 ORE — Hacker investigation, NIS2 Directive (EU 2022/2555), Legislative Decree 138/2024, ACN Guidelines, ENISA NIS2 Implementation Guidance.