Italy fined €1.7M over security flaws linked to two data breaches

▼ Summary
– Italy’s data protection authority fined WINDTRE €1.7 million after hackers used social engineering to breach its systems twice, stealing personal data from over 365,000 customers.
– For 41,359 customers, the stolen data included payment details like IBAN numbers, partially masked credit card numbers, and card expiry dates.
– The regulator found technical failures: digital certificates and private keys were not stored in encrypted vaults, and internal APIs lacked rate-limiting and CAPTCHA protection.
– WINDTRE argued the breaches resulted from human error, not system vulnerabilities, but the regulator rejected this defense, citing the technical shortcomings.
– The penalty amount was influenced by WINDTRE’s quick breach reporting, remedial actions, cooperation, and clean prior record, with an order to improve credential and certificate security.
Italy’s data protection watchdog, the Garante per la Protezione dei Dati Personali, has slapped telecom giant WINDTRE with a €1.7 million fine over what it described as “serious data security shortcomings.” The penalty stems from two separate cyberattacks that compromised the personal information of more than 365,000 customers.
The investigation was triggered after WINDTRE, one of Italy’s largest telecom operators, reported the breaches in February 2025. Rather than exploiting software flaws, the attackers used old-school social engineering tactics. Posing as support technicians, they tricked employees at two WINDTRE retail stores into granting them access to internal systems. Once inside, the hackers extracted customer names and contact details.
For roughly 41,359 of those affected, the breach was far more severe. The stolen data included payment information: postal payment slips, IBAN numbers, partially masked credit card numbers, and card expiration dates.
The Garante found that WINDTRE had failed to properly manage login credentials and digital certificates. Its own security audits, the regulator noted, missed vulnerabilities that a more rigorous review would have uncovered. These gaps, the authority concluded, allowed attackers to infiltrate the company’s systems and pilfer sensitive data.
WINDTRE argued that its security posture was already robust, citing measures like three-factor authentication, CAPTCHA, firewalls, night-time access blocks, and weekly monitoring of store lookups. The company blamed the incidents on human error rather than systemic weaknesses. It also claimed it could not force independently operated stores or non-employee staff to adopt a password manager.
The regulator dismissed that defense, pointing to two specific technical failures. First, certificate handling was inadequate: WINDTRE’s digital certificates and private keys were stored outside encrypted vaults or dedicated key-management systems, leaving them vulnerable if a device was compromised. Second, API protection was incomplete. The secondary, internal APIs that enabled the enumeration attack to run roughly 2 million requests were not included in the company’s vulnerability testing. Only the main APIs were tested. The Garante noted that standard safeguards like rate-limiting and CAPTCHA on those endpoints, as recommended by the OWASP API Security Top 10 framework, would likely have stopped the attack.
The regulator ruled that WINDTRE violated GDPR rules on data integrity, confidentiality, and security. As part of the penalty, the company must: strengthen protections for login credentials and digital certificates, introduce secure password management tools, and improve its cybersecurity procedures to prevent future incidents.
When calculating the fine, the Garante considered four mitigating factors: WINDTRE’s prompt reporting of the breaches, its efforts to address the issues after the attack, its cooperation during the investigation, and the fact that it had no prior privacy violations on record.
(Source: Help Net Security)




