Two unauthorized accesses and the exfiltration – that is, the “intentional, unauthorized and covert transfer” – of personal data of over 365 thousand customers. These are the reasons why the Privacy guarantor has imposed a fine of 1,715,600 euros on WindTre SpA due to the serious shortcomings in the security of company systems which led to an uncontrolled flow of data.
For over 40 thousand customers, the exfiltration also involved information relating to the payment methods used, such as the postal slip, the IBAN, the credit card with the number partially obscured and the expiry date.
The Guarantor’s investigation began after WindTre had notified two personal data breaches occurred in February 2025. According to what was ascertained by the Authority, the hackers they managed to break into company systems using a social engineering technique: posing as assistance technicians, they convinced the operators of two stores to authorize access to internal systems, thus managing to steal customer information.
During the investigation, various critical issues emerged in security management: in particular, the Guarantor detected deficiencies in the protection of access credentials and digital certificates. Furthermore, the company’s security checks were not thorough enough and did not identify vulnerabilities that could have been detected with more thorough checks. Precisely these flaws made it possible to access the systems illegally and the consequent theft of data.
For these reasons, the Guarantor has ascertained the violation of the principles of data integrity and confidentiality, as well as the security obligations established by the GDPR. In addition to the economic sanction, Wind Tre will have to strengthen the protection of digital credentials and certificatesadopt more secure password management tools and improve password management procedures cybersecurity to reduce the risk of new attacks.
According to what is stated in the press release, finally, in defining the amount of the fine, the Authority nevertheless took into account some elements in favor of the company, including the timely reporting of violationsthe corrective measures adopted after the cyber attacks and the collaboration provided during the entire investigation.
A story that reminds us how important it is to pay attention to your personal data. Although the responsibility for their protection falls primarily on the companies that collect and store them, incidents like this highlight how a single flaw in security systems can have consequences for hundreds of thousands of people, exposing them to the risk of scams, phishing and identity theft.