[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUt7oWBKeb4do6QhP12Kp2VYhdM_CLf2n2xRQ32kEd8I":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"062fee36-6a56-48f9-94ca-d26108a88974","sim-swap-fraud-exposes-weak-identity-verification-at-digi-spain-telecom","f7073d97-6eed-4479-acc0-c6430dbe6d75","SIM Swap Fraud Exposes Weak Identity Verification at DIGI Spain Telecom","DIGI Spain Telecom failed to implement adequate identity verification controls before issuing a duplicate SIM card, allowing an unauthorized third party to impersonate a legitimate customer and commit identity theft. The root cause was insufficient access control around a sensitive, high-risk process — SIM swapping — despite the telecommunications industry being well aware of this attack vector. This failure directly violated GDPR Article 6(1) by processing personal data (and enabling access to the victim's accounts) without a lawful basis. The €140,000 fine underscores that regulators expect organisations to implement proportionate safeguards for known, documented risks, and that ignorance of industry-wide threats is not a credible defence.","**Immediate actions:**\n- Implement multi-factor, in-person or government-ID-verified identity checks before issuing any duplicate or replacement SIM card.\n- Introduce real-time fraud detection alerts that notify the legitimate account holder via an out-of-band channel (e.g., email) whenever a SIM swap request is initiated.\n\n**Long-term improvements:**\n- Conduct a formal Data Protection Impact Assessment (DPIA) specifically covering SIM swap and account takeover scenarios, as required under GDPR Article 35.\n- Establish a dedicated anti-fraud policy for high-risk operations (SIM replacement, porting, account changes) with documented staff training and periodic review.\n- Integrate a centralised identity verification platform that logs, scores, and audits every SIM swap request for compliance and forensic purposes.\n\n**Detection & response measures:**\n- Deploy anomaly detection rules to flag unusual patterns such as multiple SIM swap requests from the same agent or location within a short timeframe.\n- Define and rehearse an incident response playbook specifically for SIM swap fraud, including customer notification timelines that meet GDPR Article 33\u002F34 breach reporting obligations.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"GDPR Article 5(1)(f) — Integrity and confidentiality","GDPR Article 6(1) — Lawfulness of processing","GDPR Article 24 — Responsibility of the controller","GDPR Article 25 — Data protection by design and by default","GDPR Article 32 — Security of processing","GDPR Article 33\u002F34 — Breach notification","GDPR Article 35 — Data Protection Impact Assessment (DPIA)","NIST SP 800-63-3 — Digital Identity Guidelines (IAL\u002FAAL levels)","NIST AC-2 — Account Management","NIST AC-17 — Remote Access controls","CIS Control 6 — Access Control Management","CIS Control 14 — Security Awareness and Skills Training","ISO\u002FIEC 27001:2022 — A.5.17 Authentication information","ITIL 4 — Risk Management and Service Design practices","published","2026-09-16T09:22:25.503653+00:00","2026-09-16T09:22:25.394+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_EXP202310345&diff=53059&oldid=52199","aepd-spain-exp202310345-787288","AEPD (Spain) - EXP202310345",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":47,"name":48,"slug":49,"description":50,"color":51},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]