Desk live·
ForensicPost
Ransomware/Aftermath/File 23-0320

Ferrari Refused a Ransom Demand and Notified Customers Directly

Ferrari received a ransom demand in March 2023, declined it as a matter of policy, said publicly that paying funds crime, and told its customers directly. What had been taken was names, addresses, emails and phone numbers.

Constructed geometry · not a chart of case data
JurisdictionItalyMaranellothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFerrari
ActorUnattributed
D. Kennedy10 min readConfidence: high3 sources reviewed

In March 2023 Ferrari disclosed that it had received a ransom demand relating to customer contact details. The company stated that as a matter of policy it does not pay, on the reasoning that paying funds criminal activity and enables further attacks, and that it had chosen to inform customers directly instead. An investigation with an external firm was begun and authorities informed.

Exposed information is reported as names, addresses, email addresses and telephone numbers. The company reported no evidence that payment details or bank account numbers were accessed.

The Right Answer, On Favourable Terms

This corpus consistently supports non-payment, and Ferrari’s stated reasoning is the reasoning the desk endorses. The company deserves the credit for stating it publicly rather than quietly.

It should also be said that the decision was cheap. What had been taken was contact information — no payment data, no identity documents, no medical records. We have recorded refusal at 22-1024, where an insurer’s answer was a file of published terminations, and at 22-0903, where a district’s answer was student psychological assessments. Those were the same principle under pressure this one never faced.

Telling Customers Was The Substitute For Paying

The company framed direct notification as the alternative to payment, which is a genuinely useful formulation: the leverage in an extortion demand is the victim’s preference that nobody find out, and disclosing removes it.

Almost nothing else in this corpus works that way round. At 26-0721b notification came 289 days after the intrusion; at 22-0120 the customers learned from the attackers. Disclosure as a deliberate counter-move, made quickly, is rare enough to record as a tactic rather than an obligation.

A Contact List Is Not Nothing

The desk grades this SEV 3 and notes what the data suits. A verified list of names, addresses and phone numbers of people who own an expensive car is a targeting list.

We have recorded the same at 22-0404, where brokerage holdings told an attacker what a plausible message looked like, and at 26-0712 on deepfake-assisted business email compromise. Low sensitivity by field, high utility by inference — which is the gap most severity schemes, including this desk’s, do not close.

How we reported this

Compiled from Ferrari’s own statement and contemporaneous reporting, listed below. No ransomware operation is named — none was authoritatively identified — and no entry route was published. No count of affected customers was released and none is asserted. The observation that the refusal was made on favourable terms is this desk’s analysis, not a criticism of the decision. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Cyber incident in FerrariFerrari
  2. Ferrari says ransomware attack exposed customers’ personal dataTechCrunch
  3. Ferrari discloses data breach after receiving ransom demandBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary