← Wind Tre

2025 Wind Tre — retail social-engineering breaches; 365K+ customers (Garante fine)

2025 365.0K records affected Share on X

Data compromised

Personal and contact data of more than 365,000 customers; for 41,359 also payment-method details (postal bulletin, IBAN, partially masked credit-card number, expiry)

Technical writeup

Wind Tre notified Italy's Garante of two data breaches in February 2025. The Authority's investigation found attackers posing as assistance technicians socially engineered operators at two retail stores into granting access to corporate systems, exfiltrating customer personal and contact data for more than 365,000 people; payment-method fields were also taken for 41,359 customers. On May 14, 2026 the Garante issued a €1,715,600 fine (announced in the July 16, 2026 newsletter) for GDPR integrity/confidentiality and security failures, ordering stronger credential and digital-certificate protections, secure password tooling, and improved IT security procedures. Mitigating factors cited included timely notification, post-incident remediation, and cooperation.

Root cause

Social engineering at two retail points of sale: attackers posing as support technicians convinced store operators to grant corporate-system access; Garante later cited credential/certificate management and audit deficiencies

References