logo

Intesa Sanpaolo Missed Unauthorized Access for 2 Years, Regulator Reveals

ID: 9a0eee02-7ae2-5637-b261-8bd9399c8b2d

STIX ID: report--9a0eee02-7ae2-5637-b261-8bd9399c8b2d

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-04-02

Date Updated: 2026-05-05

Author: Samiksha Jain

...
...

The Intesa Sanpaolo incident involved a single employee who made unauthorized repeated access to over 3,500 customer records across more than two years without detection due to monitoring systems that focused on volume rather than time-distributed anomalous behavior; the Italian Data Protection Authority fined the bank €31.8M, flagged inadequate alert thresholds and access controls, and recorded post-incident remediation measures while noting no confirmed external data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.