Autistici/Inventati sits in an uncomfortable part of the internet: the place where privacy is not a setting buried in a menu, but the whole point of the system. For more than two decades, a small Italian collective has quietly run servers for people who do not want their politics or their private lives to be monetized, profiled, or handed over with a polite fax to whoever asks nicely enough.

cover

That model has survived police server seizures, secret backdoors, Vatican curiosity, and a long list of attempts to turn “we don’t keep logs” into a prosecutable offense. Now it is colliding with a global climate in which encryption, anonymity and self-hosted infrastructure can get you labeled as “extremist” faster than any actual bomb ever could.

In brief

  • Autistici/Inventati (A/I) is a hacktivist collective founded in 2001 that treats privacy and anonymity as baseline infrastructure, not optional add-ons.
  • Its servers host thousands of email accounts, websites, blogs and mailing lists for activists, NGOs and politically engaged users who explicitly reject fascism, racism, sexism and militarism.
  • In 2004, Italian police secretly seized and copied the entire contents of A/I’s servers with the cooperation of hosting provider Aruba, without informing the collective, which only discovered it a year later.
  • In August 2026 the US Department of State and Treasury designated Autistici/Inventati a “Specially Designated Global Terrorist” under Executive Order 13224, arguing that its tools support far-left militant networks worldwide, a framing the collective firmly denies.
  • The case exposes a deep fault line: when you build infrastructure that refuses logging and profiling, you defend digital freedom while simultaneously painting a target on your back.
  • For users, defenders and investigators, Autistici/Inventati is a real-world test of everything we say about privacy, proportionality and the role of intermediaries in a surveillance-heavy networked society.

A different kind of ISP

Autistici/Inventati was born in March 2001, in the middle of the Italian and European no-global mobilizations, when technologists, activists and privacy advocates decided it was time to build their own infrastructure rather than rent it from whoever had the biggest data center, as A/I’s own history of the collective recounts. Their founding goal was simple and radical: an autonomous server that would provide free communication services while respecting anonymity and refusing to treat users as a marketing dataset.

From the beginning, A/I positioned itself as a political project, not a neutral hosting provider. According to an interview with Vice Italia, the group explicitly addresses people, whether or not they are involved in political projects, “who recognize themselves in the values of anti-fascism, anti-sexism, anti-militarism, anti-racism” and who support communication that is as free and independent as possible. The statement rejects the idea of treating terms of service as wallpaper, an explicit refusal of the myth that infrastructure can stay apolitical while mediating political struggle.

The services themselves look deceptively ordinary: email, mailing lists, web hosting, blogs, chat, video conferencing, streaming, and anonymity tools including an anonymous remailer and personal VPN access. Under the hood, the design is stubbornly privacy-centric: minimal data retention, no connection logs, heavy use of cryptography, and a refusal to ask for personal details even when that would make life easier for administrators. As the A/I service request page puts it, “every request will be read by a real person, not by a robot,” and trust is meant to run both ways, without asking for personal data.

Over the years the numbers have grown while remaining modest by commercial standards. A/I’s own history page cites nearly 12,000 mailboxes, over 1,000 websites, more than 3,000 blogs and around 3,000 mailing lists at the time of writing, while the US government’s 2026 designation put the figures higher, at roughly 16,000 mailboxes, 1,500 websites, 5,500 mailing lists and 10,000 blogs. For a hyperscale cloud provider these are rounding errors. For a self-managed, donation-funded hacklab infrastructure, they are more than enough to attract serious, sustained attention.

Seizures, backdoors and the long memory of the state

Attention first crystallized dramatically in 2004, when Italian police seized and copied the contents of every disk in A/I’s server, working with hosting provider Aruba, without telling the collective anything about it. A/I only found out by chance a year later while reviewing case documents related to an unrelated request to shut down a single mailbox, a sequence its own history page describes in detail.

The following year, the story escalated further. According to a contemporaneous EDRi bulletin republished by Autistici/Inventati, on 21 June 2005 the collective discovered a backdoor that Italian postal police had installed on the server back in June 2004, following a seizure ordered by the Bologna public prosecutor in an investigation into the anarchist collective Crocenera. Investigators had gained access to the server’s private SSL certificate and installed tools to monitor, intercept and decrypt all traffic passing through it, not just the traffic relevant to their case. Statewatch’s coverage of the episode noted that the server hosted around 500 websites, 600 discussion groups with 30,000 participants, and 5,000 email accounts used by activists, journalists, lawyers and student groups, meaning that potentially all of that traffic had been under surveillance for 371 days before discovery.

A/I’s response was to file a formal complaint with the Italian Data Protection Authority, publicly warn users to treat the compromised server as insecure, and develop what they call the “R* Plan,” a strategy to harden their defense of user privacy and travel around Italy and Europe explaining what had happened, as detailed in its own history page. The collective’s own account is blunt about what followed: “after 2005 we have been constantly pestered by prosecutors and security forces (and even by the Vatican!) asking us to hand over users’ data and identities and we are proud to say we were always able to answer: we are sorry, but we do not have them.” In 2010, according to the same source, a Norwegian-linked investigation went so far as to seize three entire servers in three different countries just to verify that A/I really held no usable logs, an operation that reportedly cost significant public money to recover nothing but encrypted files.

This history matters for two reasons. First, it shows that when privacy infrastructure becomes politically inconvenient, the response is often not a proportionate legal request but invasive technical measures aimed at bypassing the very design choices that protect users. Second, it demonstrates how little weight “targeted interception” retains in practice when the technical effect is wholesale access to unrelated third-party communications, a problem very familiar to anyone following the European debate around client-side scanning and proposals like Chat Control.

On my own blog I recently wrote about how the P.E.T. Guide, a privacy manual written for activists, unintentionally maps the same operational security landscape that digital forensics practitioners now have to navigate during investigations. Autistici/Inventati lives squarely in that landscape: a place where threat models assume backdoors, multi-jurisdiction hosting and adversaries with more patience than restraint.

From hacktivists to “global terrorists”

Fast forward to August 2026 and the tone has become dramatically harsher. On 26 August, the US Department of State, in coordination with the Treasury, announced the designation of Autistici/Inventati as a Specially Designated Global Terrorist (SDGT) under Executive Order 13224, triggering asset freezes on any US-linked property and prohibiting US persons from transacting with the collective, as outlined in the State Department’s designation notice.

The State Department’s press release is unusually detailed for this kind of action. It describes A/I as an “Italy-based extremist group” whose “cadre of radical hackers and tech developers” provides encrypted chat and email, web hosting, video conferencing, streaming and “anonymity shields” to “Marxist, anarchist, and other left-wing extremist groups,” and claims the collective “manually vets all potential users for ideological affinity” before granting access. It links A/I’s infrastructure to specific incidents, including rail sabotage across France, Italy, Germany and the Netherlands, an attack on the Transalpine Pipeline, arson campaigns against German energy infrastructure, the Oregon-based Rose City Antifa group, an Atlanta anarchist cell opposing a police training facility, and the “Jane’s Revenge” firebombing campaign against crisis pregnancy centers, arguing these networks relied on A/I’s platforms to publish communiqués, share tactical manuals and coordinate anonymously.

Italian press coverage of the announcement captured the collective’s reaction. As reported by La Stampa, Autistici/Inventati answered in Italian: “Respingiamo al mittente tutte le accuse presentate in tali dichiarazioni e allo stesso tempo riaffermiamo con forza il nostro impegno nel fornire una piattaforma di strumenti di auto-difesa digitale per permettere ad attivist*, singole persone, gruppi e associazioni di comunicare liberamente,” a line that sends the accusations back while reaffirming its commitment to digital self-defense tools. The Washington Examiner added that the collective openly advertises services such as encrypted email, private messaging and the Noblogs blogging platform, allowing users to anonymize their data, and noted that scrutiny of A/I intensified after an October 2025 Daily Caller report and Senate testimony highlighting how activists used its services to publish claims about attacks and to post immigration officers’ personal information.

The crucial detail is that the designation does not claim A/I planned or executed any specific attack itself. It targets an infrastructure that allegedly hosted or carried communications for people involved in violence, treating the existence of hardened privacy features, no logs, encryption, anonymity, as evidence of complicity rather than as a defensible design choice serving a much broader and mostly lawful user base, a reading laid out in the State Department’s designation notice.

Autistici/Inventati has never hidden its political orientation. The Wikipedia entry on Autistici/Inventati summarizes it plainly: users “must share the collective’s stance against fascism, racism, sexism and militarism,” and the group describes itself as promoting encrypted, minimally logged communications for left-wing activists since 2001, including support for Indymedia Italy’s coverage of the 2001 G8 summit in Genoa. In other words, A/I refuses the comforting corporate narrative in which a platform claims to “just run infrastructure” and pretends that moderation choices are apolitical. The price of that honesty is now visible: when your infrastructure is explicitly aligned with certain movements, the threshold for being framed as part of “terrorist support” drops dramatically, especially in a geopolitical climate where protest and extremism are deliberately blurred together.

Privacy infrastructure as a political act

The A/I case is not an isolated anomaly; it sits inside a broader pattern. Across the last two decades, there have been systematic attempts to classify privacy-enhancing technologies as suspicious by default, from “going dark” narratives about end-to-end encryption to the recurring proposal that client-side scanning and mass content inspection can somehow be made “proportionate” with enough technical caveats, an argument I examined in detail when writing about how Chat Control keeps reopening the same privacy fault line. When privacy becomes infrastructure rather than a checkbox, the political stakes reveal themselves quickly.

Autistici/Inventati’s model is built around a few stubborn choices, documented consistently across its own materials and independent accounts:

  • No logs: the collective states plainly that it does not keep connection logs or identity information, and has repeatedly told prosecutors and security services it simply has no data to hand over, as its own history page recounts.
  • Encryption everywhere: SSL/TLS for web and mail, an anonymous remailer, personal VPN access and how-to guides for keeping communications confidential, as its own service page details.
  • Minimal personal data: service requests are handled by a human being who deliberately avoids collecting sensitive information, on the premise that trust must be mutual rather than enforced through identity checks, a policy stated on the service request page.
  • Explicit political alignment: users must share the collective’s opposition to fascism, racism, sexism and militarism, a condition stated openly rather than hidden behind neutral-sounding terms of service, as the Wikipedia entry notes.

Each of these choices functions simultaneously as protection and provocation. For activists, journalists and citizens living under heavy surveillance, infrastructure that does not retain logs and does not fold at the first knock on the door is a form of digital sanctuary. For law enforcement agencies used to treating metadata and server logs as an automatic extension of their evidence toolkit, that same sanctuary looks like obstruction, and in the current climate, like grounds for a terrorism designation.

What Autistici/Inventati does is essentially the inverse of automated suspicion: instead of scanning everyone’s communications by default, as proposals like Chat Control would require, it automates forgetfulness. If you do not log, you cannot hand over data you never had, even under pressure. This is not a comfortable position for anyone involved. It forces a direct confrontation between privacy as a fundamental right and the legitimate need to investigate crime, and there is no tidy resolution, only trade-offs that different legal systems weigh differently.

Lessons for users, defenders and investigators

From a user’s perspective, Autistici/Inventati is a test of how seriously people take their own threat models. Plenty of people say they care about privacy, then hand their entire digital lives to commercial platforms that treat data protection as a public relations exercise rather than a design constraint. A/I flips that script: its services are donation-funded, run by volunteers, and deliberately inconvenient in places because security and anonymity come first, not user growth metrics.

For defenders and digital forensics practitioners, the collective’s history is a reminder that “the logs don’t exist” is not always incompetence or obstruction; sometimes it is a conscious, documented policy rooted in a political commitment to protect users from profiling, and investigations have to adapt their expectations accordingly. In an earlier piece on this blog about the P.E.T. Guide, I argued that privacy manuals written for activists are among the most useful reading materials for understanding the operational security patterns investigators now routinely encounter in the field. Autistici/Inventati is precisely the kind of infrastructure those manuals assume exists.

At the same time, A/I’s history with the 2004 server seizure, the 2005 backdoor discovery, and the 2026 terrorist designation is a warning about how far states are willing to go when confronted with infrastructure they cannot easily bend to their will, a history documented by A/I’s own account and the State Department’s designation notice. Secret interception of all traffic on a server used by tens of thousands of unrelated people is not “targeted” in any meaningful sense. Branding a privacy collective as a terrorist-support entity because some of its users committed crimes carries a clear political signal about where the line between tool and complicity is now being drawn, a line already much closer to the tool than most civil liberties frameworks would tolerate.

There is a narrow path between naive idealism, believing that offering secure tools automatically makes the world better, and cynical resignation, assuming that any sufficiently strong privacy tool will inevitably be treated as criminal infrastructure. Walking that path requires honesty about trade-offs, engagement with legal frameworks rather than dismissal of them, and a refusal to let fear of misuse become a blanket justification for dismantling privacy protections that the overwhelming majority of users rely on for entirely legitimate reasons.

If you care about digital freedom, cases like Autistici/Inventati cannot be waved away as somebody else’s political fight. They show, in painful and well-documented detail, what happens when privacy stops being a slogan and becomes a running service with real users, real adversaries, and now, real geopolitical consequences.

FAQ

What is Autistici/Inventati and what services does it provide?

Autistici/Inventati is an Italian hacktivist collective that runs privacy-focused infrastructure such as email, web hosting, mailing lists, chat and anonymity services for activists and like-minded users.

Why was Autistici/Inventati targeted by police and later designated as a terrorist entity?

Italian police secretly seized and later backdoored its servers during past investigations, and in August 2026 the US designated it a Specially Designated Global Terrorist, arguing its tools enable far-left violent networks, a claim the collective strongly rejects.

What does the Autistici/Inventati case tell us about privacy and digital freedom?

It shows how infrastructure built to protect anonymity and resist logging can be both a shield for legitimate activism and a political target, raising hard questions about the line between offering secure tools and being blamed for how they are used.