Intesa Sanpaolo insider accessed 3,500 accounts including Italy's prime minister

Organization
Intesa Sanpaolo
Exploit
Malicious Insider
Industry
Banking

Prosecutors in Bari opened an investigation in October 2024 into an employee of Intesa Sanpaolo, Italy's largest bank, accused of repeatedly looking at customer account data he had no business reason to see.

The employee, a 52-year-old man, was alleged to have accessed the account information of about 3,500 customers roughly 6,000 to 6,600 times between February 2022 and April 2024. Those affected included Prime Minister Giorgia Meloni and her sister Arianna, former Prime Minister Mario Draghi, Senate President Ignazio La Russa, Defence Minister Guido Crosetto, and officers of the Carabinieri and Guardia di Finanza.

Intesa Sanpaolo said there had been no cybersecurity breach. The employee worked in agricultural lending, where reviewing customer account data forms part of the job, and held legitimate access rights. Reuters reported that the bank's monitoring flagged anomalies but that the accesses were spread thinly across about 500 working days, staying under alerting thresholds, and that the control system carried no specific flag for politically exposed customers. People close to the matter told Reuters that no data appeared to have been downloaded.

The bank suspended the employee, dismissed him in August for what it called serious and repeated violations of internal rules, regulations and procedures, and filed a complaint with prosecutors. It apologised publicly and set up a security division headed by a recently retired senior police officer.

Sources