UniCredit S.p.A. – €2,800,000 Fine (Italy, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
UniCredit S.p.A. was fined for a data breach that exposed customer information due to security flaws. This case is important because it shows how critical it is for companies to secure their systems against cyberattacks to protect customer data.
What happened
UniCredit S.p.A. experienced a cyberattack that compromised customer data due to vulnerabilities in its mobile banking portal.
Who was affected
Customers whose personal data, including names and tax codes, were exposed during the breach.
What the authority found
The authority found that UniCredit S.p.A. did not take adequate measures to protect personal data, violating GDPR's security requirements.
Why this matters
This case serves as a reminder for all businesses to prioritize cybersecurity. Companies must regularly assess and strengthen their security measures to prevent data breaches and protect customer information.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
On 22 October 2018, UniCredit S.p.A. ("controller") notified the Italian DPA of a personal data breach that occurred on 21 October 2018. The breach occurred due to a cyberattack on the controller’s mobile banking portal for customers. Third parties tried to access customer accounts by attempting automatically-generated simple PINs. The mobile banking portal had two vulnerabilities that facilitated the breach. First, the portal made customers’ personal data (first name, surname, tax code, and internal bank identification code) available in HTML responses to authentication attempts, including where attempts were unsuccessful. Second, the controller did not limit the use of simple PINs, making accounts vulnerable to cyberattacks aimed at identifying customer login information (brute force attacks). Due to the HTML response vulnerability, every login attempt gave cyber attackers access to the names, tax codes, and internal bank identification codes of 777,765 present and former customers. In the case of 6,959 of those customers, the cyber attackers also successfully identified the portal PINs. The controller subsequently blocked the identified PINs. The breach did not include the data subjects’ banking data. The controller did not consider the breach high-risk pursuant to Article 34 GDPR. It posted a general notice on its website and gave direct notice only to the 6,959 data subjects whose passwords were identified. The DPA disagreed, finding the breach likely to present a high risk to data subject rights after a preliminary investigation. On 13 December 2018, it enjoined the controller to communicate the personal data breach to all data subjects. The controller subsequently prepared differentiated notices, which the DPA found complied with Article 34(2) GDPR. In a defense brief, the controller argued that it took preventive measures and mitigating controls which exceeded market standards at the time of the breach. Additionally, the controller argued that the breach
Violations (1)
Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.
Art. 6(1) GDPR
Related Enforcement Actions (1)
Other enforcement actions involving UniCredit S.p.A. in IT
Similar Cases
Enforcement actions with similar violations
Details
Fine Date
8 February 2024
Authority
Garante per la protezione dei dati personali
Fine Amount
€2,800,000
GDPRhub ID
gdprhub-7707About this data
Cite as: Cookie Fines. UniCredit S.p.A. - Italy (2024). Retrieved from cookiefines.eu
Last updated: