The Privacy Guarantor punishes WindTre for the 2025 data breaches, involving the data of over 365 thousand customers

Written by Jason Miller

The Guarantor for the protection of personal data has imposed on Wind Three a sanction from 1,715,600 euros for serious security flaws that allowed hackers to breach company systems on two separate occasions. The exfiltration involved the personal data of over 365 thousand customers.

For some of them, exactly 41,359 usersthe damage is deeper: the attackers also stole information relating to payment methods, including the postal slip, theIbanthe partially obscured credit card number and its expiration date.

The Authority’s investigation arose from the two data breaches notified by Wind Tre itself in February 2025. The investigations reconstructed the dynamics of the attack: the cyber criminals pretended to be support technicians and managed to convince the operators of two stores to grant access to the company systems. From there, it was a short step towards exfiltrating customer personal and contact data.

The flaws identified by the Guarantor that allowed the data breaches

At the center of the disputes are the methods of management of login credentials and gods digital certificatesdeemed inadequate to contain an attack based essentially on social engineering techniques. The Guarantor also noted that the security checks conducted internally by Wind Tre were not sufficient to intercept vulnerabilities that more in-depth checks would have instead identified.

Based on these elements, the Authority ascertained the violation of the principles of data integrity and confidentiality provided for by the GDPR, in addition to the general processing security obligations. Wind Three will now have to strengthen protection systems of credentials and digital certificates, introduce secure tools for password management and review internal IT security procedures, to prevent similar episodes from happening again.

In calculating the amount of the fine, the Guarantor took into account some mitigating factors: the timeliness with which Wind Tre notified the incident, the corrective measures implemented immediately after the attack and the collaboration provided by the telephone operator during the investigation. Circumstances that limited the amount of the fine, while not excluding the company’s responsibility for the structural gaps found in its systems.

The case confirms a recurring problem in the Italian telecommunications sector: the weak point is almost never the technology itself, as we have said over and over again, but the human factor. It only takes a few operators convinced to trust a fake technician to open a flaw capable of exposing the information of hundreds of thousands of people, including the most sensitive ones linked to payments.

Jason Miller

I'm Jason Miller, and I've been passionate about technology and storytelling for over a decade. As a lead writer at Herald Editorials, I strive to bring clarity and creativity to complex tech topics. When I'm not writing, you'll find me exploring the latest gadgets or hiking in the great outdoors.