In March 2023 Ferrari disclosed that it had received a ransom demand relating to customer contact details. The company stated that as a matter of policy it does not pay, on the reasoning that paying funds criminal activity and enables further attacks, and that it had chosen to inform customers directly instead. An investigation with an external firm was begun and authorities informed.
Exposed information is reported as names, addresses, email addresses and telephone numbers. The company reported no evidence that payment details or bank account numbers were accessed.
The Right Answer, On Favourable Terms
This corpus consistently supports non-payment, and Ferrari’s stated reasoning is the reasoning the desk endorses. The company deserves the credit for stating it publicly rather than quietly.
It should also be said that the decision was cheap. What had been taken was contact information — no payment data, no identity documents, no medical records. We have recorded refusal at 22-1024, where an insurer’s answer was a file of published terminations, and at 22-0903, where a district’s answer was student psychological assessments. Those were the same principle under pressure this one never faced.
Telling Customers Was The Substitute For Paying
The company framed direct notification as the alternative to payment, which is a genuinely useful formulation: the leverage in an extortion demand is the victim’s preference that nobody find out, and disclosing removes it.
Almost nothing else in this corpus works that way round. At 26-0721b notification came 289 days after the intrusion; at 22-0120 the customers learned from the attackers. Disclosure as a deliberate counter-move, made quickly, is rare enough to record as a tactic rather than an obligation.
A Contact List Is Not Nothing
The desk grades this SEV 3 and notes what the data suits. A verified list of names, addresses and phone numbers of people who own an expensive car is a targeting list.
We have recorded the same at 22-0404, where brokerage holdings told an attacker what a plausible message looked like, and at 26-0712 on deepfake-assisted business email compromise. Low sensitivity by field, high utility by inference — which is the gap most severity schemes, including this desk’s, do not close.
Compiled from Ferrari’s own statement and contemporaneous reporting, listed below. No ransomware operation is named — none was authoritatively identified — and no entry route was published. No count of affected customers was released and none is asserted. The observation that the refusal was made on favourable terms is this desk’s analysis, not a criticism of the decision. Graded high. Corrections: corrections@forensicpost.com.