UniCredit Fined €2.8 Million Over 2018 Data Breach in Italy, Plans Appeal

Italy's data protection authority has levied a fine of 2.8 million euros ($3.1 million) against UniCredit (CRDI.MI), the nation's second-largest bank, citing a data breach incident dating back to 2018. The breach affected thousands of customers and former clients, announced the authority on Thursday.
UniCredit swiftly responded, declaring its intention to contest the decision in court. The bank assured that no bank data had been compromised during the incident, which it claimed to have promptly resolved.
In its statement, the authority underscored the obligation of banks to implement robust technical and organizational security measures to safeguard customer data against unlawful breaches.
The breach, characterized as a massive cyber attack on the bank's mobile banking platform, resulted in the unauthorized acquisition of sensitive information, including names, tax codes, and other identification details, of approximately 778,000 individuals.
Acknowledging the severity of the breach and the extensive number of people impacted, the authority factored in the swift implementation of corrective actions while imposing the sanction.
UniCredit emphasized its unwavering commitment to prioritizing customer data security, disclosing its substantial investment of 2.8 billion euros in a comprehensive program aimed at bolstering protection measures.
Subscribe Now

