Back to Feed

Tag

Privacy Fines

DPA enforcement actions and penalties

27 items tagged #privacy-fines

Articles

FBI: Cybercrime Losses Neared $21 Billion in 2025

FBI reports $20.9 billion in cybercrime losses from 1M complaints in 2025, up 26% YoY.

Garante per la protezione dei dati personali (Italy) - 10234984

Italian DPA fines Intesa Sanpaolo €31.8M for inadequate safeguards allowing employee unauthorized financial data access.

Garante per la protezione dei dati personali (Italy) - 10234984

Italian DPA fines Intesa Sanpaolo €31.8M for data breach affecting 3,500+ customers and delayed notification.

Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs From 15+ Banks

Threat actor selling 1.2M French FICOBA banking records with IBANs, SSNs, and tax IDs from 15+ banks.

Garante per la protezione dei dati personali (Italy) - 10234984

Italy's DPA fines Intesa Sanpaolo €31.8M for inadequate security and delayed breach notification.

AEPD (Spain) - EXP202308705

Spain's AEPD fines Vodafone €200K for SIM-swap fraud enabling unauthorized bank access.

Alleged Breach of KBank Vietnam Exposes 10.1 Million Credit Registration Records With National IDs, Salaries, Credit Scores, and Employer Details

KBank Vietnam breach exposes 10.1M credit records with national IDs, salaries, and credit scores.

Rb. Amsterdam - C/13/783613 / KG ZA 26-120

Dutch court bans X's Grok from generating non-consensual intimate and CSAM imagery in Netherlands.

AEPD (Spain) - EXP202307472

Spain's AEPD fines utilities company €220,000 for unlawful direct marketing and lack of legal basis under GDPR.

Garante per la protezione dei dati personali (Italy) - 10233396

Italian DPA fines Enel Energia €563,052 for unlawful marketing calls and processor oversight failures.

AEPD (Spain) - EXP202305035

Spain's AEPD fines Orange Espagne €230K for weak eSIM security enabling identity theft.

AEPD (Spain) - EXP202305035

AEPD fines Orange España €230K for issuing duplicate eSIM without consent.

Healthcare tech firm CareCloud says hackers stole patient data

CareCloud discloses data breach affecting patient health records after March 16 intrusion.

ANSPDCP (Romania) - fine against Renault Commercial Roumanie SRL

Romania fines Renault €125K for inadequate data security measures after cyberattack.

‼️ Footage of the LeakBase domain administrator getting arrested in Taganrog, Russia. https://t....

LeakBase domain administrator arrested in Taganrog, Russia.

Garante per la protezione dei dati personali (Italy) - 10230206

Italy's DPA fines two airlines €1.25M for unlawful employee data sharing during asset sale.

ICO (UK) - Reddit, Inc

UK ICO fines Reddit £14.5M for unlawful processing of children's personal data.

‼️🇨🇱 A threat actor group using the handle "NyxarGroup" has leaked the database of Universidad...

NyxarGroup leaks 70,000 student records from Chilean university on dark web.

AEPD (Spain) - PS/00552/2023

Spanish DPA fines e-commerce company €1.09M for legacy system breach exposing 1M+ records on dark web.

AEPD (Spain) - EXP202408496

Spanish DPA fines BBVA €100,000 for unlawfully redirecting SEPA payments without consent.

AEPD (Spain) - PS/00552/2023

Spanish DPA fines e-commerce company €1.09M for data breach affecting 1M+ records and GDPR violations.

3.1 Million Impacted by QualDerm Data Breach

QualDerm Partners reports 3.1M patient records stolen in December 2025 breach.

‼️🇩🇪 Threat Actors Claim Expanded BMW Breach With IDOR Exploit, Employee and Customer PII, and...

Threat actors claim expanded BMW breach via IDOR exploit affecting multiple automakers.

AEPD (Spain) - PS/00552/2023

Spanish DPA fines e-commerce firm €1.09M for exposed million-record database and GDPR breach notification failures.

AEPD (Spain) - PS/00552/2023

Spain's AEPD fines e-commerce firm €1.09M for dark web database breach and delayed notification.

ICO (UK) - Reddit, Inc

UK ICO fines Reddit £14.5M for unlawful processing of children's personal data without parental consent.

Garante per la protezione dei dati personali (Italy) - 10230412

Italian DPA fines bank €17.6M for GDPR violations in customer profiling and account transfers.