UniCredit S.p.A. – €2,800,000 Fine (Italy, 2024)

€2,800,000Garante per la protezione dei dati personali8 February 2024Italy
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

UniCredit S.p.A. was fined for a data breach that exposed customer information due to security flaws. This case is important because it shows how critical it is for companies to secure their systems against cyberattacks to protect customer data.

What happened

UniCredit S.p.A. experienced a cyberattack that compromised customer data due to vulnerabilities in its mobile banking portal.

Who was affected

Customers whose personal data, including names and tax codes, were exposed during the breach.

What the authority found

The authority found that UniCredit S.p.A. did not take adequate measures to protect personal data, violating GDPR's security requirements.

Why this matters

This case serves as a reminder for all businesses to prioritize cybersecurity. Companies must regularly assess and strengthen their security measures to prevent data breaches and protect customer information.

GDPR Articles Cited

AI-verified

Art. 34(GDPR)
Art. 5(1)(f) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 32(1) GDPR
Art. 32(2) GDPR
Art. 34(GDPR)

Original data from scraper before AI verification against source document.

Source verified 2 April 2026
articles corrected
Full Legal Summary
Detailed

On 22 October 2018, UniCredit S.p.A. ("controller") notified the Italian DPA of a personal data breach that occurred on 21 October 2018. The breach occurred due to a cyberattack on the controller’s mobile banking portal for customers. Third parties tried to access customer accounts by attempting automatically-generated simple PINs. The mobile banking portal had two vulnerabilities that facilitated the breach. First, the portal made customers’ personal data (first name, surname, tax code, and internal bank identification code) available in HTML responses to authentication attempts, including where attempts were unsuccessful. Second, the controller did not limit the use of simple PINs, making accounts vulnerable to cyberattacks aimed at identifying customer login information (brute force attacks). Due to the HTML response vulnerability, every login attempt gave cyber attackers access to the names, tax codes, and internal bank identification codes of 777,765 present and former customers. In the case of 6,959 of those customers, the cyber attackers also successfully identified the portal PINs. The controller subsequently blocked the identified PINs. The breach did not include the data subjects’ banking data. The controller did not consider the breach high-risk pursuant to Article 34 GDPR. It posted a general notice on its website and gave direct notice only to the 6,959 data subjects whose passwords were identified. The DPA disagreed, finding the breach likely to present a high risk to data subject rights after a preliminary investigation. On 13 December 2018, it enjoined the controller to communicate the personal data breach to all data subjects. The controller subsequently prepared differentiated notices, which the DPA found complied with Article 34(2) GDPR. In a defense brief, the controller argued that it took preventive measures and mitigating controls which exceeded market standards at the time of the breach. Additionally, the controller argued that the breach

Violations (1)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Details

Fine Date

8 February 2024

Authority

Garante per la protezione dei dati personali

Fine Amount

€2,800,000

GDPRhub ID

gdprhub-7707

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. UniCredit S.p.A. - Italy (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: