Italy’s data protection authority fined telecom operator WINDTRE €1,715,600 after determining that two February 2025 breaches exposed personal data belonging to more than 365,000 customers. Attackers reportedly used social engineering at two WINDTRE retail locations, posing as support technicians and convincing store staff to grant access to internal systems, which enabled the exfiltration of customer information. The stolen data included contact and personal details, while 41,359 customers also had payment-related information exposed, including IBANs, partially masked card numbers, expiration dates, and postal payment slip data.
The regulator said the incidents were not attributable to human error alone, citing weak management of access credentials and digital certificates, along with inadequate protection and testing of internal APIs that allowed large-scale enumeration and failed to surface identifiable vulnerabilities. The authority concluded that WINDTRE violated GDPR requirements for integrity, confidentiality, and security, and ordered the company to strengthen credential protection, certificate handling, password management, and broader cybersecurity procedures.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
WINDTRE notified the two data breaches to Italy’s data protection authority in February 2025. The notifications concerned the intrusions later tied to weaknesses in credential, certificate, and API security controls.
Italy’s data protection authority fined WINDTRE €1,715,600 after concluding that the company’s security shortcomings contributed to the February 2025 breaches. The regulator found GDPR violations and ordered improvements to credential protection, certificate handling, password management, and cybersecurity procedures.
In February 2025, attackers posing as support technicians convinced operators at two WINDTRE retail locations to grant access to internal systems, enabling two unauthorized intrusions. The incidents exposed personal and contact data of more than 365,000 customers, and payment-related data for 41,359 people was exfiltrated.
Italy’s data protection authority said the sanction against WINDTRE was announced in newsletter no. 549 published on July 16, 2026. The notice described serious security deficiencies linked to the two breaches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.