← Intesa Sanpaolo

2026 Intesa Sanpaolo — insider unauthorized queries (3,573+ customers; Garante €31.8M fine; Mar)

2026 3.6K records affected Share on X

Data compromised

Customer financial and account metadata accessed without legitimate purpose per DPA findings

Technical writeup

Italy’s Garante per la protezione dei dati personali (March 2026) imposed a ~€31.8 million fine on Intesa Sanpaolo after finding that a single employee at an agribusiness branch had performed thousands of unsanctioned database lookups affecting roughly 3,500–3,600 customers over an extended 2022–2024 window, including high-sensitivity and politically exposed profiles in some narratives. The regulator faulted poor monitoring, delayed breach notification, and internal access model weaknesses rather than a headline external ransomware event. Reuters, The Record, and privacy-law analysis cited the case as a flagship EU insider/insider-misuse enforcement action.

Root cause

Insider abuse of customer-query privileges; weak supervisory controls (per Garante decision summaries)

References