Jul 20 / Latest News

Italy Fines WINDTRE €1.7M for Security Failures After Major Data Breaches

Italy’s data protection authority has fined telecom operator WINDTRE €1.7 million after two breaches exposed personal data belonging to more than 365,000 customers.

The regulator said the incidents stemmed from “serious data security shortcomings,” noting that attackers gained access not through software flaws but by impersonating support technicians and convincing staff at two stores to grant system access. That access allowed them to pull customer names and contact details, and for more than 41,000 people, payment information including IBANs, postal slips, partially masked card numbers, and expiry dates.

The authority found weaknesses in how WINDTRE handled login credentials and digital certificates, and said internal audits failed to detect vulnerabilities that more thorough testing would have caught. WINDTRE argued it already had strong protections—three‑factor authentication, firewalls, CAPTCHA, and monitoring—and blamed human error. Regulators rejected that defense, pointing to unencrypted certificate storage and untested internal APIs that allowed attackers to run roughly two million automated requests. They said basic controls like rate‑limiting and CAPTCHA, standard under OWASP API Security Top 10, would likely have stopped the attack.

The regulator ruled that WINDTRE violated GDPR requirements for data integrity, confidentiality, and security. It ordered the company to strengthen credential and certificate protection, adopt secure password‑management tools, and improve cybersecurity procedures. When setting the fine, the authority considered WINDTRE’s quick reporting, its cooperation, the remediation steps taken, and its lack of prior violations.