observatornews.ro Orange Romania Fined 100,000 Euros for Major Data Breach
Article Content
- •Orange Romania fined 523,900 lei for GDPR violations due to data breaches.
- •Customer data, including personal and banking information, was exposed.
- •Lack of basic security measures in applications led to significant vulnerabilities.
Orange Romania was fined 523,900 lei (approximately 100,000 euros) due to two security incidents that exposed personal and banking data of customers and employees. The breaches were linked to a vulnerability in the company's mobile application, which allowed unauthorized access to invoices of other customers, and a ticketing application that lacked essential security measures. The National Authority for the Supervision of Personal Data Processing (ANSPDCP) concluded the investigation in June 2026, revealing that the company failed to implement adequate technical and organizational measures as required by GDPR. The first incident involved a synchronization error that led to the exposure of names, addresses, and identification details, while the second incident involved a massive cyberattack exploiting the unsecured ticketing application. The total fine reflects the severity of the breaches and the potential risks to customer data and company reputation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Orange Romania in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…