Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

Дата публикации: 20-07-2026 13:19:05

Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers. The regulator opened its investigation after WINDTRE, one of Italy’s major telecom operators, reported two separate data breaches in February 2025. The attackers relied on old-school social engineering instead of exploiting software vulnerabilities. Posing as support technicians, … More →
The post Italy fines WINDTRE €1.7 million over security flaws behind two data breaches appeared first on Help Net Security.


Основное содержимое страницы с новостью.

Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers.

Italy WINDTRE fine

The regulator opened its investigation after WINDTRE, one of Italy’s major telecom operators, reported two separate data breaches in February 2025.

The attackers relied on old-school social engineering instead of exploiting software vulnerabilities. Posing as support technicians, they convinced staff at two WINDTRE stores to grant them access to company systems. That access let them pull customer names and contact details out of the company’s systems.

Payment data exposed for thousands

For 41,359 of the affected customers, the stolen data went beyond names and contact information. It included payment details: postal payment slips, IBAN numbers, partially masked credit card numbers, and card expiry dates.

The regulator found deficiencies in how the company managed login credentials and digital certificates. Its investigation also found that WINDTRE’s own security audits had missed vulnerabilities that more thorough checks would have caught. According to the authority, these vulnerabilities allowed hackers to access the company’s systems and steal personal data.

The technical flaws the regulator couldn’t ignore

WindTre argued it already had solid security in place: three-factor authentication, CAPTCHA, firewalls, night-time access blocks, and weekly monitoring of store lookups. The company said the incidents came down to human error, unrelated to system vulnerabilities. It also said it couldn’t force independently run stores or non-employee staff to use a password manager.

The regulator rejected that defense and pointed to two technical failures.

The first was certificate handling. WindTre’s digital certificates and private keys weren’t stored in encrypted vaults or dedicated key-management systems, leaving them exposed if a device were compromised.

The second was API protection. The secondary, internal APIs that let the enumeration attack run at scale, roughly 2 million requests, weren’t covered by the company’s own vulnerability testing; only the main APIs were. The regulator said rate-limiting and CAPTCHA on those endpoints, standard under the OWASP API Security Top 10 framework, would likely have caught it.

The regulator ruled that WINDTRE broke GDPR rules on data integrity, confidentiality, and security. As part of its decision, the authority ordered the company to:

  • Strengthen how it protects login credentials and digital certificates
  • Introduce secure tools for password management
  • Improve its cybersecurity procedures to prevent similar incidents

In setting the penalty amount, the regulator weighed four things: how quickly WINDTRE reported the breaches, the steps the company took to fix problems after the attack, its cooperation during the investigation, and the fact that WINDTRE had no prior privacy violations on record.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1A study of 1,000 Android apps finds a privacy policy logging gap09.3824-04-2026
2WindTre Voce 5G Online in promo Limited Edition a 5,99 euro al mese0525-06-2026
3RingCentral data breach exposed info of 1.6 million accounts010.3914-08-2026
4WindTre WinDay: oggi 27 Luglio 2026 nuova promo Storytel, novità di Agosto 2026011.8627-07-2026
5WSense, 10 mln per la scaleup del wireless subacqueo partner di Fincantieri06.322-10-2025
6WindTre, Porta un Amico in Call Your Country: in omaggio una ricarica internazionale04.3730-07-2026
7South Korea hits Coupang with $400M+ fine for data breach that affected millions0811-06-2026
8Verizon Retailer Hit With 2 Data Breach Suits In NC-2616-07-2026
9Novee brings continuous AI pentesting to mobile apps06.6630-07-2026
10Orbia CISO Miranda Ritchie on building security into sustainable infrastructure0708-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 13.6. Источник: www.helpnetsecurity.com.