observatornews.ro
Orange Romania Fined 100,000 Euros for Major Data Breach
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Orange Romania was fined 523,900 lei (approximately 100,000 euros) due to two security incidents that exposed personal and banking data of customers and employees. The breaches were linked to a vulnerability in the company's mobile application, which allowed unauthorized access to invoices of other customers, and a ticketing application that lacked essential security measures. The National Authority for the Supervision of Personal Data Processing (ANSPDCP) concluded the investigation in June 2026, revealing that the company failed to implement adequate technical and organizational measures as required by GDPR. The first incident involved a synchronization error that led to the exposure of names, addresses, and identification details, while the second incident involved a massive cyberattack exploiting the unsecured ticketing application. The total fine reflects the severity of the breaches and the potential risks to customer data and company reputation.
Key Points: • Orange Romania fined 523,900 lei for GDPR violations due to data breaches. • Customer data, including personal and banking information, was exposed. • Lack of basic security measures in applications led to significant vulnerabilities.