Bank fined €31.8M after employee snooped on accounts

The Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for serious shortcomings in personal-data security. An employee accessed 3,573 customers' banking records without justification from Feb 2022 to Apr 2024, making over 6,600 consultations. The regulator found internal monitoring failed to detect the abuse and said notifications to affected customers were incomplete and late, including high‑risk public‑figure accounts.

Part of the PlainSec briefing for 2026-03-31

Sources