Italy’s privacy regulator has fined telecommunications company WINDTRE more than €1.7 million after two security breaches exposed customer information.

The WINDTRE data breaches affected more than 365,000 people. Attackers stole identity and contact details, while some customers also had payment information compromised.

The regulator blamed serious weaknesses in the company’s security systems. In particular, investigators found problems involving account credentials, digital certificates, and vulnerability testing.

Italy Issues €1.7 Million Penalty

The Italian Data Protection Authority imposed a fine of €1,715,600 on WINDTRE.

The regulator launched its investigation after the telecom provider reported two breaches in February 2025. Both incidents involved unauthorized access to company systems.

Investigators concluded that WINDTRE failed to provide enough protection for customer information. As a result, the company breached data integrity, confidentiality, and security requirements under the General Data Protection Regulation.

The authority considered the large number of affected customers when calculating the penalty. However, it also took several mitigating factors into account.

WINDTRE reported the incidents promptly. In addition, the company cooperated with the investigation and introduced corrective measures after the attacks.

More Than 365,000 Customers Affected

Attackers exfiltrated personal information belonging to over 365,000 WINDTRE customers.

The stolen records included identity and contact details. Although the regulator did not list every exposed field, this type of information may help criminals conduct phishing or identity fraud.

For 41,359 customers, the compromised data also included details about their payment methods.

The exposed payment information covered:

  • Postal payment methods
  • IBAN bank account details
  • Partially masked credit card numbers
  • Credit card expiration dates

Partially hidden card numbers are less useful than complete payment details. However, criminals can combine them with other personal information to create convincing scams.

Attackers Impersonated Support Technicians

The WINDTRE data breaches began with social engineering rather than a purely technical attack.

The hackers posed as support technicians and contacted staff at two retail stores. They then persuaded the employees to provide access to internal company systems.

Once inside, the attackers extracted customer identity and contact data. They also gained access to the payment information linked to thousands of accounts.

This method shows how criminals can bypass security controls by targeting employees. Even a protected system may become vulnerable when an attacker convinces an authorized user to grant access.

Therefore, companies must combine technical safeguards with employee training and strict verification procedures.

Regulators Found Credential Security Failures

The investigation identified weaknesses in how WINDTRE managed login credentials and digital certificates.

Credentials control who can access a system. Digital certificates can also confirm the identity of devices, users, or services. Poor protection of either can create opportunities for unauthorized access.

The regulator said better controls could have reduced the impact of the attacks. In particular, stronger credential management could have made it harder for criminals to use access obtained through the retail stores.

Italy’s privacy authority has now ordered WINDTRE to improve its protection of both credentials and certificates.

The company must also introduce safer password management tools and strengthen its wider cybersecurity procedures.

Security Testing Failed to Find Vulnerabilities

Investigators also criticized WINDTRE’s vulnerability assessment and penetration testing.

The company had performed security checks. However, those tests failed to identify weaknesses that more thorough assessments should have detected.

As a result, the vulnerabilities remained available to attackers. The regulator said those gaps helped the hackers enter the company’s systems and steal customer data.

Routine security scans may not always reveal complex weaknesses. Therefore, organizations should use several testing methods and regularly review their scope.

Penetration tests should also reflect real attack techniques. These include social engineering, stolen credentials, certificate abuse, and unauthorized access through trusted business locations.

WINDTRE Must Strengthen Its Defences

The privacy authority ordered WINDTRE to improve several parts of its security program.

Required changes include stronger protection for account credentials and digital certificates. The company must also adopt secure password-management tools.

In addition, WINDTRE must improve its cybersecurity processes to prevent similar incidents. These measures should help the company detect suspicious access and respond before attackers can remove large amounts of information.

The regulator considered the corrective work WINDTRE had already completed when deciding the final fine.

Stolen Data Could Support Further Scams

Customers affected by the WINDTRE data breaches should remain alert for phishing emails, calls, and text messages.

Criminals may use stolen contact details to impersonate the telecom provider, a bank, or another trusted organization. Payment information can make these messages appear more convincing.

Customers should never share passwords or verification codes during an unexpected call. They should also avoid following links sent through unsolicited messages.

Anyone who receives a suspicious request should contact WINDTRE or their bank through a verified number. Customers should also monitor their accounts for unfamiliar activity.

The incident shows how a successful social engineering attack can expose information from hundreds of thousands of people. Strong technical controls remain essential, but companies must also verify support requests and limit employee access.


0 responses to “WINDTRE Data Breaches Trigger €1.7 Million Fine”