[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTx_F3abRaqcx8B0b1eKm50Qe-emTCFVndG3Ylp4XWNs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"0a156257-76ef-4530-9def-1df77a5b786f","ptsb-fined-277500-after-social-engineering-attacks-bypass-contact-centre-authentication","73bc785a-fc45-4239-a784-cbe34558404f","PTSB Fined €277,500 After Social Engineering Attacks Bypass Contact Centre Authentication","Permanent TSB failed to implement sufficient identity verification controls at its Open24 Contact Centre, allowing malicious actors to impersonate customers and gain unauthorized access to sensitive financial accounts. The root cause was a combination of weak authentication procedures and inadequate staff training to detect and resist social engineering attempts. This incident demonstrates that technical security controls must be complemented by robust human-layer defenses, particularly in customer-facing roles where verbal or remote authentication is common. Compounding the breach, PTSB's delayed notification to the DPC violated GDPR Article 33 requirements, resulting in additional regulatory liability. Financial institutions must treat timely breach reporting as a non-negotiable compliance obligation, not an afterthought.","**Immediate actions:**\n- Replace single-factor verbal authentication at contact centres with multi-factor or knowledge-based authentication protocols that are resistant to social engineering.\n- Establish and enforce a mandatory 72-hour breach notification workflow to ensure GDPR Article 33 reporting deadlines are met without delay.\n\n**Long-term improvements:**\n- Implement continuous staff training programs specifically targeting social engineering scenarios, including impersonation and pretexting attacks.\n- Deploy call analytics and anomaly detection tools to flag suspicious account access patterns or repeated failed authentication attempts at contact centres.\n- Develop and maintain a formal Identity Verification Policy that defines escalation steps when agent confidence in caller identity is low.\n\n**Detection & monitoring measures:**\n- Establish centralized logging of all contact centre authentication events to enable post-incident forensic review and pattern detection.\n- Conduct regular tabletop exercises and red-team social engineering simulations to assess staff resilience and identify procedural gaps.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"GDPR Article 5(1)(f) – Integrity and confidentiality principle","GDPR Article 25 – Data protection by design and by default","GDPR Article 32 – Security of processing","GDPR Article 33 – Notification of a personal data breach to the supervisory authority","NIST SP 800-53 IA-2 – Identification and Authentication","NIST SP 800-53 AT-2 – Security Awareness Training","NIST SP 800-53 IR-6 – Incident Reporting","CIS Control 6 – Access Control Management","CIS Control 14 – Security Awareness and Skills Training","CIS Control 17 – Incident Response Management","ISO\u002FIEC 27001:2022 A.6.1 – Screening and awareness","ISO\u002FIEC 27001:2022 A.8.2 – Privileged access rights","ITIL 4 – Incident Management Practice","published","2026-07-06T14:20:24.608038+00:00","2026-07-06T14:20:24.268+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DPC_(Ireland)_-_IN-22-7-3&diff=52071&oldid=52069","dpc-ireland-in-22-7-3-acdddf","DPC (Ireland) - IN-22-7-3",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",[]]