[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftpsR5xVUPpT28qLG4dV7F-RpqGYwjSOb-KQFN36oQ6o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"8f9df5af-908d-4661-a295-6710779f93b7","orange-spain-fined-230k-for-weak-identity-verification-leading-to-sim-swap-fraud","5ad1d246-d338-4296-a423-e6860426e6b4","Orange Spain Fined €230K for Weak Identity Verification Leading to SIM Swap Fraud","Orange Spain suffered a security breach where attackers exploited weak identity verification controls to fraudulently obtain a duplicate eSIM card and conduct unauthorized transactions. Despite the company's systems detecting potential identity theft and issuing internal warnings, employees still proceeded to issue the duplicate SIM card, demonstrating systemic failures in access controls and incident response procedures. This case highlights how inadequate security measures and poor response to fraud indicators can lead to significant regulatory penalties and customer harm.","**Immediate actions:**\n- Implement multi-factor authentication for all SIM card duplication requests\n- Establish mandatory fraud prevention training for customer service representatives\n- Create hard stops in systems that prevent SIM issuance when fraud alerts are active\n\n**Long-term improvements:**\n- Deploy automated identity verification systems with biometric or document validation\n- Establish clear escalation procedures for suspected identity theft cases\n- Implement real-time monitoring of SIM swap requests with behavioral analytics\n\n**Governance measures:**\n- Conduct regular audits of customer authentication processes\n- Create incident response playbooks specifically for SIM swap fraud attempts\n- Establish clear accountability measures for employees who override security warnings",[12,13,14,15,16,17],"GDPR Article 32","CIS Control 6","NIST AC-2","NIST IR-4","ISO 27001 A.9.2.1","PCI DSS 8.2","published","2026-03-31T10:09:14.461346+00:00","2026-03-31T10:09:14.363+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_EXP202305035&diff=51180&oldid=0","aepd-spain-exp202305035","AEPD (Spain) - EXP202305035",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]