Wire · founder news, decoded · regulatory
Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
◆ Published
20 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 20 July 2026 · Fusion42 review
Italy's data protection authority fined WINDTRE €1.7 million for security failures that enabled two separate data breaches affecting 365,000 customers. The regulator found critical gaps in certificate handling, API protection, and credential management that allowed social engineering attacks to scale across store systems.
This Wire brief sits within Fusion42's coverage of Enterprise Software. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you're a SaaS platform or telecom handling customer data in Europe, the regulator just set the bar for API and certificate security: unprotected secondary APIs and unencrypted keys are now €1.7m+ violations. Audit your internal APIs and key management this week—GDPR enforcement is getting granular on infrastructure, not just process.
◆ Related on Wire
- Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack21 July 2026
- European Commission fines AliExpress €550 million for DSA breaches21 July 2026
- ETid-3173: GDPR fine against Société Wallonne des Eaux (Belgium, 2026)19 July 2026
- Spain: AEPD fines Vodafone €1,050,000 for unlawful data disclosure and ...18 July 2026
- EU Fines AliExpress €550 Million Over Illegal Products in Landmark Digital Services Crackdown21 July 2026
- The EU has fined AliExpress a record €550 million for violating the law20 July 2026
◆ Topics
Enterprise Software · gdpr-enforcement · data-breach · api-security · certificate-management · telecom