2026 Intesa Sanpaolo — insider unauthorized queries (3,573+ customers; Garante €31.8M fine; Mar)
Data compromised
Customer financial and account metadata accessed without legitimate purpose per DPA findings
Technical writeup
Italy’s Garante per la protezione dei dati personali (March 2026) imposed a ~€31.8 million fine on Intesa Sanpaolo after finding that a single employee at an agribusiness branch had performed thousands of unsanctioned database lookups affecting roughly 3,500–3,600 customers over an extended 2022–2024 window, including high-sensitivity and politically exposed profiles in some narratives. The regulator faulted poor monitoring, delayed breach notification, and internal access model weaknesses rather than a headline external ransomware event. Reuters, The Record, and privacy-law analysis cited the case as a flagship EU insider/insider-misuse enforcement action.
Root cause
Insider abuse of customer-query privileges; weak supervisory controls (per Garante decision summaries)