Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Enforcement July 26, 2026 4 min

Wind Tre, EUR 1.7 million: the breach started with a phone call

Fake support technicians convinced staff at two retail outlets to grant system access. Data of over 365,000 customers exfiltrated, with IBANs and cards for 41,359

TL;DR for the DPO

The weak link was not a firewall: it was two people behind a shop counter, talked into it over the phone by someone claiming to be technical support. The authority charged Arts. 5(1)(f) and 32(1)(b), finding shortcomings in the protection of credentials and digital certificates. Fine: EUR 1,715,600.

The three points that matter

  • Article 32 security is not only technology: it includes organisational measures, and staff training is one of them. A successful social engineering attack is also a failure of the instructions given to those who process data under Art. 29.
  • System access is not limited to the IT department: it includes retail staff, often employed by third parties. They must be trained, authorised in writing, and given a clear procedure for verifying the identity of anyone requesting remote access.
  • Credential and digital certificate management is the technical point charged. Multi-factor authentication, personal rather than shared credentials, prompt revocation: these are the measures that, if documented, can be defended; if absent, they are paid for.

What to do now, in practice

1) Ask clients who can access the systems holding their customers' data, including branches, shops, agents and suppliers: the list is almost always longer than they think; 2) check there is a written procedure for remote access and for verifying the identity of whoever requests it; 3) schedule dedicated training on social engineering, with real examples, and keep the attendance record: it is the evidence that Art. 32 was taken seriously; 4) review multi-factor authentication and credential management; 5) if the client has outlets run by third parties, review the Art. 28 agreements and the instructions given.

Why it matters for your clients

This decision is the best argument for persuading a client to take training seriously. It is not about theory: a well-crafted phone call opened the door to the data of 365,000 people. In smaller companies the typical reaction is 'it won't happen to us, we're small': the answer is that social engineering works best precisely where nobody expects to be a target.

Official source:Italian Data Protection Authority - decision no. 348 of 14 May 2026 (doc. no. 10263796), made public with newsletter no. 549 of 16 July 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free