Iberdrola Fined €1M for Weak Phone-Based Identity Verification Allowing Unauthorized Account Changes
Iberdrola Clientes failed to implement sufficiently strong authentication controls for customer identity verification over the phone, relying solely on static, easily obtainable data that could be exploited by unauthorized parties to alter sensitive contact details. This represents a fundamental failure in access control design, where knowledge-based authentication (KBA) using predictable or publicly accessible information provided no meaningful security barrier. The breach exposed customers to risks including account takeover, fraud, and privacy violations — all preventable with stronger multi-factor or dynamic verification methods. Under GDPR Article 25 (Data Protection by Design and by Default) and Article 32 (Security of Processing), organizations are legally obligated to implement appropriate technical and organizational measures, and failure to do so can result in substantial regulatory penalties as demonstrated by this €1,000,000 fine.
Tactical Insight
Immediate actions
- Replace static knowledge-based authentication (KBA) for phone verification with dynamic, time-sensitive one-time passcodes (OTPs) sent to a pre-registered channel.
- Conduct an urgent audit of all customer-facing authentication processes to identify and remediate reliance on easily accessible static data.
Long-term improvements
- Implement multi-factor authentication (MFA) for all sensitive account operations, including contact detail changes via any channel.
- Embed Privacy by Design principles into all customer interaction workflows, ensuring security controls are evaluated before deployment.
- Establish a formal identity verification policy with defined minimum standards reviewed annually against emerging threat intelligence.
Detection & monitoring measures
- Deploy anomaly detection to flag unusual patterns in account modification requests (e.g., bulk changes, after-hours activity, or mismatched caller data).
- Implement comprehensive audit logging for all account changes, with alerts for high-risk operations such as contact detail updates, and retain logs in accordance with GDPR requirements.