Wind Tre: €1.72M GDPR Fine After Social Engineering Attack

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/6 · Initial Access via Social Engineering

Attackers called branch employees, posed as support technicians and tricked them into granting remote access to company devices.

T1566.004 – Phishing: Spearphishing Voice T1656 – Impersonation
  • Vishing (voice phishing) via phone against two branches
  • Impersonation of support technicians
  • Two incidents in quick succession (reported Feb 20 and Feb 28, 2025)
PHASE 2/6 · Remote Access and Credential Theft

After gaining remote access, attackers found certificates and credentials stored in plaintext on the devices.

T1219 – Remote Access Software T1552.001 – Unsecured Credentials: Credentials In Files T1552.004 – Private Keys
  • Digital certificates and private keys stored unencrypted
  • No use of KMS or HSM (key management systems / hardware security modules)
  • All factors of the three-factor authentication captured
PHASE 3/6 · Login to Internal Web Application

Using the stolen factors, attackers logged into the internal web application and ran database queries.

T1078 – Valid Accounts T1550 – Use Alternate Authentication Material
  • Used valid certificates and passwords for authentication
  • First incident: 66 targeted database queries
  • Approximately 23 customer records accessed
PHASE 4/6 · Mass Enumeration of Unprotected APIs

Exploiting a flaw in secondary APIs, attackers systematically incremented the customer ID to retrieve data en masse.

T1190 – Exploit Public-Facing Application T1213 – Data from Information Repositories
  • Enumeration by incrementally increasing customerId
  • Around 2 million requests to secondary internal APIs
  • No rate limiting and no CAPTCHA protection on secondary APIs
  • Secondary APIs not covered by vulnerability assessments / pentests
PHASE 5/6 · Data Exfiltration

Attackers exfiltrated the personal and partly financial data of 365,048 customers.

T1041 – Exfiltration Over C2 Channel T1567 – Exfiltration Over Web Service
  • 365,048 affected customers (names and contact details)
  • 41,359 customers with payment data: IBAN, postal orders, partially redacted credit card numbers with expiry dates
  • Mass retrieval without triggering any alarm
PHASE 6/6 · Impact and Regulatory Consequences

The data breach resulted in a GDPR fine of €1,715,600 against Wind Tre.

  • Garante fine: €1,715,600 (Decision No. 348)
  • Issued May 14, 2026, published July 16, 2026
  • Authority rejected the 'just human error' defense
  • Mitigating: prompt notification, corrective measures, cooperation
Short & clear answers
Frequently asked questions about this incident
As an SME website operator, am I affected by this issue?
The specific incident involved Wind Tre, but the underlying mistakes occur just as often at SMEs. If your website runs APIs, login forms or customer areas without rate-limiting or CAPTCHA, attackers can extract data en masse through enumeration. Storing certificates and credentials in plaintext is also a widespread risk.
How do I check whether my APIs are vulnerable to enumeration attacks?
Create a complete inventory of all APIs in your web applications – both primary and secondary interfaces. For each, verify that rate-limiting (a cap on requests per time period), CAPTCHA and authentication protection are active. At Wind Tre it was precisely the untested secondary APIs that received around 2 million requests during the attack.
What exactly should I do now to protect myself?
Store digital certificates and private keys only in encrypted vaults, a KMS or HSM – never in plaintext on desktops or in the browser. Enable rate-limiting and CAPTCHA on all APIs and login forms, and ensure your security tests cover ALL endpoints. Also run simulated phishing and vishing tests for your staff.
Isn't multi-factor authentication enough to keep me safe?
No. Wind Tre had three-factor authentication including a certificate and passwords, but these were stored in plaintext on the devices. Once remote access was granted, attackers held all factors at once and could log in. Safeguards only work if central gaps like unprotected credentials and untested APIs are closed.
Can I excuse a data breach as 'human error'?
No. Wind Tre argued the incidents were pure human error with no system flaws – the Garante explicitly rejected this. The authority pointed to two technical failings: inadequate certificate management and the lack of protection for secondary APIs. The fine amounted to 1,715,600 euros.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.