www.trameetech.it Wind Tre Fined €1.7 Million for Major Data Breach Affecting 365,000 Customers
Article Content
- •Wind Tre fined €1.7 million for serious data security failures.
- •Over 365,000 customers affected, with sensitive payment data exposed.
- •Attackers used social engineering to gain unauthorized access to systems.
Wind Tre Spa has been fined €1,715,600 by the Garante per la protezione dei dati personali due to severe security deficiencies that led to two data breaches affecting over 365,000 customers. The breaches occurred when hackers impersonated technical support, gaining unauthorized access to the company's systems at retail locations. The first incident involved access to data of 23 customers, while the second allowed attackers to conduct approximately 2 million database queries, exposing personal and payment information of over 41,000 users. The Garante identified significant flaws in the management of access credentials and digital certificates, which facilitated the breaches. Wind Tre has since implemented corrective measures, including revoking compromised certificates and enhancing security protocols. The company is required to report back to the Garante within 30 days regarding compliance with the imposed measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track WindTre in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…