[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frNig1Xw9HN2DK7fH8bHO_sFM0REZ7el0B5ZCPoAWo0c":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"07376011-9ebd-4012-8bb4-a799a8c29bc9","phishing-attack-on-car-dealership-leads-to-gdpr-fine-for-inadequate-security-measures","97adc7e7-8b1a-4d61-a0d2-004bc95f2fdd","Phishing Attack on Car Dealership Leads to GDPR Fine for Inadequate Security Measures","A phishing attack successfully compromised an administrator account at Poliserv JG (PJG) SRL, exposing customer personal data and triggering a €3,000 GDPR fine from Romania's data protection authority. The root cause was a failure to implement adequate technical and organizational measures, as required by GDPR Article 32, including insufficient phishing awareness training and weak account protection. Administrator accounts are high-value targets and require layered defenses such as multi-factor authentication and regular security training. This case demonstrates that even smaller businesses handling customer data are held to GDPR standards, and negligence in basic security hygiene carries both financial and reputational consequences.","**Immediate actions:**\n- Enforce multi-factor authentication (MFA) on all administrator and privileged accounts immediately.\n- Conduct an emergency phishing simulation and awareness training session for all staff with access to personal data.\n- Audit and revoke any unnecessary administrative privileges to reduce the blast radius of future account compromises.\n\n**Long-term improvements:**\n- Establish a formal, recurring phishing awareness training program aligned with GDPR Article 32 organizational measures.\n- Implement a privileged access management (PAM) solution to monitor, control, and log all administrator account activity.\n- Develop and regularly review a Data Protection Impact Assessment (DPIA) and incident response plan covering phishing scenarios.\n\n**Detection measures:**\n- Deploy email security gateways with anti-phishing and anti-spoofing controls (SPF, DKIM, DMARC).\n- Enable login anomaly detection and alerting for administrator accounts to flag suspicious access attempts.\n- Maintain centralized logging of all access to systems containing personal data for forensic readiness.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 32 – Security of Processing","GDPR Article 83 – Administrative Fines","CIS Control 14 – Security Awareness and Skills Training","CIS Control 6 – Access Control Management","CIS Control 9 – Email and Web Browser Protections","NIST SP 800-53 AT-2 – Literacy Training and Awareness","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 IA-5 – Authenticator Management","NIST Cybersecurity Framework PR.AT-1 – Awareness and Training","ISO\u002FIEC 27001:2022 A.6.3 – Information Security Awareness, Education and Training","published","2026-08-21T12:20:58.121214+00:00","2026-08-21T12:20:57.838+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_ANSPDCP_(Romania)_-_Fine_against_Poliserv_JG_(PJG)_SRL&diff=52745&oldid=52742","anspdcp-romania-anspdcp-romania-fine-against-poliserv-jg-pjg-srl-574cfc","ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",[]]