VYPR
breachPublished Jul 20, 2026· 1 source

Italy Fines WINDTRE €1.7 Million for Data Breaches Linked to Social Engineering

Italy's data protection authority has fined WINDTRE €1.7 million for significant security lapses that enabled two data breaches, compromising over 365,000 customers.

Italy's data protection authority, the Garante per la Protezione dei Dati Personali, has imposed a €1.7 million fine on telecommunications giant WINDTRE following two data breaches that occurred in February 2025. The regulator cited "serious data security shortcomings" as the root cause, which allowed attackers to access company systems and exfiltrate personal data belonging to more than 365,000 customers.

The breaches were not the result of sophisticated software exploits, but rather old-fashioned social engineering tactics. Threat actors successfully impersonated support technicians, convincing staff at two WINDTRE retail stores to grant them access to internal systems. This unauthorized access enabled the theft of customer names and contact details.

For a significant subset of affected customers, the compromised data was more sensitive. Payment details, including postal payment slips, IBAN numbers, partially masked credit card numbers, and card expiry dates, were exposed for 41,359 individuals. This highlights the potential financial impact on customers whose information fell into the wrong hands.

The Garante's investigation uncovered deficiencies in WINDTRE's management of login credentials and digital certificates. Notably, the company's own security audits had failed to identify vulnerabilities that more rigorous checks would have revealed. These overlooked weaknesses ultimately provided the entry point for the attackers.

WINDTRE attempted to defend its security posture by highlighting measures such as three-factor authentication, firewalls, and monitoring systems, attributing the incidents to human error rather than system vulnerabilities. However, the regulator rejected this defense, pointing to specific technical failures.

The authority identified two critical technical flaws. Firstly, WINDTRE's digital certificates and private keys were not stored in encrypted vaults or dedicated key-management systems, leaving them vulnerable to compromise if a device was breached. Secondly, the internal APIs used for the enumeration attack, which processed approximately 2 million requests, were not included in the company's vulnerability testing, despite standard security practices like rate-limiting and CAPTCHA being recommended by the OWASP API Security Top 10 framework.

Consequently, the regulator ruled that WINDTRE had violated GDPR rules concerning data integrity, confidentiality, and security. As a corrective measure, the company has been ordered to enhance its protection of login credentials and digital certificates, implement secure password management tools, and improve its overall cybersecurity procedures.

In determining the fine amount, the Garante considered WINDTRE's prompt reporting of the breaches, the remedial steps taken post-attack, its cooperation during the investigation, and the absence of prior privacy violations on record. This case underscores the importance of robust security practices, particularly in safeguarding sensitive customer data against social engineering and technical vulnerabilities.

Synthesized by Vypr AI