TL;DR for the DPO
Two separate fines for the same episode: EUR 250,000 for inadequate security measures and EUR 27,500 for late notification. The second figure is the one that deserves attention: late notification is a standalone infringement, payable even when the controller has already paid for the flaw that caused it.
How the attack worked
There was no intrusion into any system. The attackers already held certain customer information - the kind of data that circulates after someone else's breach, or that can be assembled from social media - and used it to pass the contact centre's telephone identity checks. Once authenticated as the customer, they gained access to accounts and amended the personal and contact details attached to them. Some customers lost money.
Where the weakness lies
Identity verification based on information the data subject knows - date of birth, address, last digits of an ID, the amount of the last transaction - is not an authentication factor: it is a knowledge factor reproducible by anyone holding the same data. If a client's contact centre can change the email address or phone number attached to an account on that basis alone, the flaw is not in the software: it is in the procedure.
The two heads of sanction
- EUR 250,000 for the failings related to account security: technical and organisational measures not appropriate to the risk (Art. 32 GDPR). Telephone account takeover has been a known risk in banking for years.
- EUR 27,500 for the delay in notifying the breaches to the authority (Art. 33 GDPR). The first breaches were reported in May 2022, but not within the required time.
- In addition, a formal reprimand under Art. 58(2)(b).
Why the second amount matters more than the first
Security measures are debatable: appropriateness, state of the art and cost of implementation are relative notions, and the controller has room to argue. The 72-hour deadline is not: either the notification arrived in time, or it did not. It is an infringement established with a calendar, not an expert report. That is why, in the practice of a firm serving several clients, controlling the deadline is the investment with the best ratio of cost to risk avoided.
The subtle point is that the 72 hours run from when the controller becomes aware of the breach, and in cases like this awareness builds up by accumulation: first one isolated customer report, then another, then the suspicion that there is a pattern. The moment that suspicion becomes 'awareness' is a judgement that has to be written down when it is made, not reconstructed months later in front of the authority.
What to do now, in practice
1) For every client with a phone channel to end customers, ask for the identity verification procedure and try to pass it using the information you would find in a data leak. 2) Check whether changing an email address or phone number requires confirmation through a second channel: that single control breaks the account takeover chain. 3) In the breach register, for every event record the date and time at which the controller became aware and who determined it: that field decides whether notification was timely. 4) If several similar reports arrive over a period of weeks, assess whether they constitute a single continuing breach: it is a decision to be justified in writing either way.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free