Italy’s Garante hit WindTre with a €1,715,600 penalty on May 14, 2026, for security failures that let attackers breach the telecom twice and pull personal data on more than 365,000 customers, 41,359 of them with payment details attached.
I read the decision (reg. 348/2026, doc-web 10263796) this week, and the fact pattern is almost boring: no zero-day, no exotic exploit. Attackers posed as support technicians and talked staff at two retail stores into granting system access. That’s the old yardstick. WindTre’s defense leaned on it too, telling the Garante the incidents were “human error” and that it couldn’t force independently run stores to adopt password managers.
The new yardstick is what got them fined. The Garante found the second intrusion ran roughly 2 million enumeration requests against internal APIs that weren’t covered by WindTre’s own vulnerability testing, only the customer-facing ones were. Rate-limiting and CAPTCHA on those endpoints, standard under OWASP’s API Security Top 10, would have caught it. Certificates and private keys sat outside encrypted vaults, too. That’s a straight Article 5(1)(f) and Article 32 security-of-processing violation, not a social engineering excuse.
The penalty landed at just 1% of the statutory maximum, credited for fast breach notification, post-incident fixes, and a clean prior record. Regulators are increasingly treating API inventory gaps, not just perimeter defenses, as the compliance failure. Worth auditing which of your own internal APIs sit outside the pen-test scope this quarter.
— Rebecca Lauren