Italian Telecom Giant WINDTRE Fined €1.7M Over Dual Data Breaches Affecting 365,000 Customers
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, imposed a €1.7 million fine on WINDTRE, one of the country’s largest telecom operators, for "serious data security shortcomings" that enabled two separate breaches in February 2025. The attacks compromised the personal data of over 365,000 customers, with payment details exposed for 41,359 individuals.
The breaches stemmed from social engineering tactics rather than software vulnerabilities. Attackers posed as support technicians, tricking staff at two WINDTRE stores into granting access to internal systems. Once inside, they extracted customer names, contact details, and in some cases postal payment slips, IBAN numbers, partially masked credit card numbers, and card expiry dates.
The regulator’s investigation uncovered critical flaws in WINDTRE’s security practices. Despite the company’s claims of robust defenses including three-factor authentication, firewalls, and access restrictions audits revealed lapses in credential and certificate management. Digital certificates and private keys were not stored in encrypted vaults, leaving them vulnerable if devices were compromised. Additionally, internal APIs, which facilitated a large-scale enumeration attack (roughly 2 million requests), lacked rate-limiting and CAPTCHA protections, violating OWASP’s API Security Top 10 standards.
WINDTRE argued that the incidents resulted from human error, not systemic failures, and noted challenges in enforcing password managers for independently run stores. However, the regulator dismissed these defenses, ruling that the company violated GDPR’s data integrity, confidentiality, and security requirements.
As part of the ruling, WINDTRE was ordered to strengthen credential and certificate protection, implement secure password management tools, and enhance cybersecurity procedures. The fine amount reflected the company’s prompt breach reporting, post-incident remediation efforts, cooperation during the investigation, and lack of prior privacy violations.
Source: https://www.helpnetsecurity.com/2026/07/20/italy-windtre-1-7-million-fine/
wind tre cybersecurity rating report: https://www.rankiteo.com/company/wind-tre-s.p.a.
"id": "WIN1784558266",
"linkid": "wind-tre-s.p.a.",
"type": "Breach",
"date": "2/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '365,000',
'industry': 'Telecommunications',
'location': 'Italy',
'name': 'WINDTRE',
'size': 'Large',
'type': 'Telecom Operator'}],
'attack_vector': 'Social Engineering',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '365,000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Customer names',
'Contact details',
'Postal payment slips',
'IBAN numbers',
'Partially masked credit card '
'numbers',
'Card expiry dates']},
'date_detected': '2025-02',
'description': 'Italy’s data protection authority imposed a €1.7 million fine '
"on WINDTRE for 'serious data security shortcomings' that "
'enabled two separate breaches in February 2025. The attacks '
'compromised the personal data of over 365,000 customers, with '
'payment details exposed for 41,359 individuals. The breaches '
'stemmed from social engineering tactics where attackers posed '
'as support technicians to gain access to internal systems.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': 'Personal data of 365,000 customers, payment '
'details of 41,359 individuals',
'financial_loss': '€1.7 million fine',
'identity_theft_risk': 'Yes',
'legal_liabilities': 'GDPR violations',
'payment_information_risk': 'Yes',
'systems_affected': 'Internal systems, APIs'},
'initial_access_broker': {'entry_point': 'Social engineering (posing as '
'support technicians)'},
'investigation_status': 'Completed',
'lessons_learned': 'Importance of secure credential and certificate '
'management, need for rate-limiting and CAPTCHA '
'protections for APIs, enforcement of password managers '
'across all stores',
'post_incident_analysis': {'corrective_actions': ['Strengthened credential '
'and certificate protection',
'Implemented secure '
'password management tools',
'Enhanced cybersecurity '
'procedures'],
'root_causes': ['Human error',
'Poor credential and certificate '
'management',
'Lack of rate-limiting and CAPTCHA '
'protections for APIs']},
'recommendations': 'Implement secure password management tools, enhance '
'cybersecurity procedures, store digital certificates and '
'private keys in encrypted vaults, enforce OWASP API '
'Security Top 10 standards',
'references': [{'source': 'Garante per la Protezione dei Dati Personali'}],
'regulatory_compliance': {'fines_imposed': '€1.7 million',
'regulations_violated': ['GDPR'],
'regulatory_notifications': 'Yes'},
'response': {'remediation_measures': 'Strengthened credential and certificate '
'protection, implemented secure password '
'management tools, enhanced '
'cybersecurity procedures'},
'title': 'WINDTRE Fined €1.7M Over Dual Data Breaches Affecting 365,000 '
'Customers',
'type': 'Data Breach',
'vulnerability_exploited': 'Human Error, Lack of Rate-Limiting and CAPTCHA '
'Protections for APIs, Poor Credential and '
'Certificate Management'}