Italy’s Data Protection Authority fined Intesa Sanpaolo €31.8 million after finding that the bank failed to adequately protect customer banking data from unauthorized internal access. The investigation, opened after a July 2024 breach disclosure, found that an employee improperly accessed the records of 3,573 customers and carried out more than 6,600 consultations between February 2022 and April 2024. Regulators said the bank’s technical and organizational safeguards were inadequate and that its operating model granted excessively broad access across the customer base.
Authorities said the activity went undetected because of weaknesses in the bank’s monitoring and prevention systems, and they noted that some affected customers were high-profile public figures who should have received enhanced protection. The regulator also criticized Intesa Sanpaolo for incomplete and delayed notifications to affected customers after the breach, while noting that remediation steps later taken by the bank to strengthen internal controls and data security safeguards were considered in setting the penalty.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Italy's Data Protection Authority imposed a €31.8 million fine on Intesa Sanpaolo after concluding the bank failed to adequately protect customer banking data from unauthorized internal access. The authority said the bank's technical, organizational, and monitoring controls were inadequate.
After the breach, Intesa Sanpaolo introduced corrective actions to strengthen internal controls and data security safeguards. The regulator said these later remediation steps were taken into account when setting the penalty.
In July 2024, the breach was disclosed, leading Italy's Data Protection Authority to open an investigation into the bank's handling of customer data and internal access controls. The regulator later criticized the bank's notifications to affected customers as incomplete and delayed.
The improper access continued through April 2024, ultimately involving the data of 3,573 customers and more than 6,600 consultations. Some affected individuals were high-risk public figures who should have been subject to enhanced protections.
An Intesa Sanpaolo employee improperly accessed customer banking information, beginning a pattern of unauthorized internal consultations that affected thousands of customers. Regulators later said the bank's access model and monitoring controls were insufficient to prevent or detect the abuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourceteiss.co.uk
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.