CTIPilot
← Back to Daily brief 2026-07-17
NOTABLENATOA1incident

Garante fines Wind Tre EUR 1.7M over a vishing-enabled API-enumeration breach that exposed 365,048 telco customers

Italian DPA fines Wind Tre EUR 1.7M, retail-staff vishing led to enumeration of an unprotected secondary API (365,048 customers)

Analysis

The Garante's decision gives a rare, fully technical account of a telco breach. Initial access was voice social engineering: attackers phoned staff at two retail points of sale, posed as internal support technicians, and "convinced operators at two retail points of sale to allow access to company systems" (Garante, 2026-07-16). That remote access yielded the point-of-sale device's installed client digital certificate plus login credentials (reportedly recoverable in cleartext from the desktop or browser rather than held in an OS certificate store) which the attackers then used as valid, MFA-satisfied access to a customer-facing web application. In the first incident that access ran 66 targeted lookups (~23 customers). In the second, days later, the attackers pivoted from the primary (protected) search API to an unprotected secondary API invoked by the same search function and "executed about 2 million total requests following an enumeration logic, i.e. progressively incrementing the customer code identifier ('customerId')," compromising 365,048 customers and, for 41,359 of them, payment-instrument data (Garante, 2026-07-16). The Garante rejected Wind Tre's defense that its API design followed OWASP practice, finding the enumeration-reachable secondary endpoints were "reasonably identifiable" by a vulnerability assessment and penetration test scoped to the API surface, not just the primary documented interfaces.

Cited evidence

gli hacker, fingendosi tecnici dell'assistenza, hanno convinto gli operatori di due punti vendita a consentire l'accesso ai sistemi aziendali

Garante per la protezione dei dati personali (Newsletter n.549) 2026-07-16

gli attaccanti sono riusciti ad eseguire circa 2 milioni di richieste totali seguendo una logica di enumeration, ovvero andando ad aumentare progressivamente l'identificativo del codice cliente (c.d. "customerId") violando i dati personali di 365.048 clienti

Garante per la protezione dei dati personali (Provvedimento n.348, 14 May 2026) 2026-07-16

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.