Wind Tre Fined €1.7M After Data Breach Exposes Customer Info
July 21, 2026Read also: TeamViewer hit with a €240K penalty, AliExpress fined €550 million for breaching the Digital Services Act, and more.

Wind Tre fined €1.7M after a data breach exposed customer information
Italy's Data Protection Authority has fined one of country's largest telecommunication companies Wind Tre Spa €1,715,600 after finding serious security failures that led to two cyber-attacks affecting more than 365,000 customers.
The investigation began after the company reported two data breaches in February 2025. Authorities found that hackers pretended to be support technicians and convinced employees at two stores to give them access to company systems. This allowed the attackers to steal customers' personal and contact information. In some cases, the stolen data also included payment-related information, such as postal payment slips, IBANs, and credit cards with partially hidden card numbers and expiration dates.
The authority said Wind Tre used poor practices in managing login credentials and digital certificates. It also found that the company's security audits failed to detect vulnerabilities that could have been found through more thorough checks.
The authority ruled that Wind Tre violated GDPR rules on data security and confidentiality. It ordered the company to improve the protection of digital credentials and certificates, introduce secure password management tools, and strengthen its cybersecurity procedures to help prevent future attacks.
TeamViewer fined €240K for failing to disclose a cyber-attack in a timely manner
German financial regulator BaFin has fined software company TeamViewer €240,000 for failing to quickly inform investors about a cyber-attack in 2024. The regulator said the company broke the EU's Market Abuse Regulation (MAR) by not issuing an ad hoc announcement as soon as it became aware of the incident.
TeamViewer believed the attack was carried out by the Russian hacker group tracked as APT29/Midnight Blizzard. The company said the hackers only accessed its internal IT system, stealing employee names, contact details and confidential passwords. It added that customer data, product systems and communication platforms were not affected.
Instead of notifying investors immediately, TeamViewer first posted a notice on its website for customers. Following news of the attack, the company's share price fell by around 10%.
Under EU rules, companies listed on German financial markets must promptly publish information that could affect their share price. BaFin said TeamViewer failed to meet this requirement, hence the fine.
SEBI fines CDSL 10M rupees over 2022 malware attack
India's markets regulator SEBI has fined Central Depository Services (India) Ltd (CDSL) 10 million rupees (about €90,800) over cybersecurity and compliance failures linked to a 2022 malware attack. SEBI said CDSL failed to identify and protect an internet-facing server as a critical asset, allowing hackers to gain access to the systems. The depository manages about 83 million investor accounts, around 70% of the country's total.
The regulator also found that CDSL failed to detect cyber intrusions in real time, properly analyze security alerts, and follow rules for restoring settlement operations through backup sites. The malware attack disrupted key depository services, including trade settlements, corporate actions, margin pledges and inter-depository transfers, delaying settlements scheduled for November 18, 2022.
SEBI said the incident was the result of repeated cybersecurity weaknesses, including poor monitoring, weak password controls and failure to implement required security measures.
Separately, India's Central Consumer Protection Authority (CCPA) has fined low-cost airline SpiceJet ₹1 lakh (about €908) for using dark patterns on its booking website. According to the CCPA, the company's booking page automatically enrolled customers in SpiceJet's frequent flyer program and pre-selected consent to receive promotional SMS, WhatsApp, and email messages.
The CCPA ruled the practices were an unfair trade practice, unfair contract, and misleading advertisement under the Consumer Protection Act, 2019. It also found that SpiceJet violated Rule 4(9) of the Consumer Protection (E-Commerce) Rules, 2020, which requires clear consumer consent and specifically bans pre-ticked checkboxes.
The regulator also found the booking interface used prohibited dark patterns under the Guidelines for Prevention and Regulation of Dark Patterns, 2023, and ordered the airline to submit a compliance report within 15 days.
ICASA fines Session Telecoms R6M for numbering rules breaches
South Africa's communications regulator ICASA has fined B2B telecoms provider Session Telecoms R6 million (€320,000) after finding the company misused telecommunications numbering resources in breach of the Numbering Plan Regulations.
The case followed a complaint filed by MTN, a South African subsidiary of the Johannesburg-based telecoms provider MTN Group, in April 2023. MTN alleged that Session was involved in practices linked to interconnect bypass operations, including Calling Line Identification (CLI) manipulation, call refiling and SIM-boxing. The complaint was investigated and heard by ICASA's Complaints and Compliance Committee (CCC) under Section 17B of the ICASA Act.
The CCC found that Session breached Regulation 6(3)(f) of the Numbering Plan Regulations by using invalid and unallocated numbers. It has also found that the company breached Regulation 6(3)(g) of the Numbering Plan Regulations by failing to ensure that numbering resources were used efficiently and effectively, resulting in communications not being routed through MTN's network as required.
ICASA imposed a R3 million (€160,000) fine for the breach of Regulation 6(3)(f) and a further R3 million for the breach of Regulation 6(3)(g). In addition to the fines, the regulator ordered Session to stop any further contraventions of the Numbering Plan Regulations; barred and, where appropriate, withdrew the affected numbering resources; and placed the company under close compliance monitoring.
Session must also submit monthly compliance reports for 24 months, including details of call records and international call traffic carried on its network.
AliExpress hit with a half-billion-euro EU penalty over the DSA breach
The EU has fined Chinese online shopping platform AliExpress a record €550 million for failing to stop illegal products from being sold on its website. The fine, issued under the EU's Digital Services Act, is the largest ever given under the law, which aims to protect consumers from unsafe products and misleading online practices.
The European Commission found that AliExpress did not have enough staff to properly check whether products met EU safety standards, with moderators sometimes spending only a few seconds reviewing items. As a result, dangerous cosmetics, unsafe toys, counterfeit goods, and other illegal products remained on the platform for weeks and were often recommended to customers through its advertising and recommendation systems.
Officials also said AliExpress failed to enforce penalties against sellers breaking the rules, allowing many of them to continue operating. The company’s checks for counterfeit and mislabeled products were found to be ineffective, making it easy for sellers to avoid detection. The Commission concluded that AliExpress did not take enough action to minimize the spread of illegal goods or accurately measure how well its moderation systems were working.
What’s next:
- Request a free product demo or pricing
- Register for our webinars and product trainings
- Read our Cybercrime Investigations weekly blog
- Follow us on LinkedIn, X, Telegram and WhatsApp
- Subscribe to our Newsletter
- Join our Partner Program
Amazon To Pay $2.25M For Withholding Records From Fraud Victims