Data Breaches · Insider Threat

Intesa Sanpaolo Fined €31.8M Over Employee Snooping

An Intesa Sanpaolo employee accessed 3,573 customers' banking data without justification between Feb 2022 and Apr 2024. The Italian Data Protection Authority found weak technical and organizational controls and failed monitoring of privileged access. The regulator also cited late and incomplete notifications to affected customers, including high‑risk public figures, and imposed a €31.8 million fine.

1 source · Mar 30

Timeline

Sources

Part of the PlainSec briefing for 2026-03-30

Every edition of this story: Intesa Sanpaolo Fined €31.8M Over Employee Snooping