The Italian authority sanctions NIER Ingegneria for a personal data breach following a ransomware attack
A ransomware attack, facilitated by insufficient fundamental security measures, led to the compromise of personal data, including special categories. The authority notably noted the absence of systematic deployment of multi-factor authentication, ineffective network segregation, and an unformalized vulnerability management process.
Facts and context
The Italian data protection authority (Garante per la protezione dei dati personali) published a decision finding breaches against the company NIER Ingegneria S.p.a. Società Benefit for security failures that led to a ransomware attack and the publication of data on the dark web.
The case originated from a personal data breach notification made by the company on October 11, 2024, following the detection of a "BlackBasta" ransomware attack that resulted in system encryption and data exfiltration.
Grounds for the decision
Obligation to ensure the security of processing (Article 32 of the GDPR): The authority considered that the technical and organizational measures implemented by the company were not appropriate to guarantee a level of security appropriate to the risk. The investigation revealed several critical failures: multi-factor authentication was active only for a limited number of "critical" profiles on Microsoft 365 services and was not extended to other systems, notably remote access via virtual private network (VPN), which was the probable attack vector. Moreover, although network segmentation into several virtual local networks (VLANs) was implemented, domain controllers had extensive access to all these networks, nullifying the effectiveness of the measure and allowing lateral movements by the attacker. Finally, the vulnerability management process was described as "partial and unformalized," relying on manual activities, and the backup system was also compromised, with restore points dating two months before the incident.
Obligation to ensure the integrity and confidentiality of data (Article 5(1)(f) of the GDPR): The authority concluded that the breaches of the security obligations under Article 32 of the GDPR directly resulted in a violation of the principle of integrity and confidentiality. The inability to prevent unauthorized access, data encryption (compromising their availability and integrity), and their exfiltration followed by publication on the dark web (compromising their confidentiality) constitute a materialization of risks that adequate security measures should have prevented. The breach affected a wide variety of data, including health data, trade union membership, and criminal convictions, which increases the severity of the breach.
Authority's decision
Consequently, the authority found breaches of Articles 5(1)(f) and 32(1)(b) of the GDPR against NIER Ingegneria S.p.a. Società Benefit.
Lessons learned
This decision reminds that:
- Multi-factor authentication must be systematically deployed on all external accesses, notably VPN accesses, and not limited to certain profiles or systems deemed "critical."
- A network segregation policy is effective only if flow rules are strictly controlled, including for administrative accounts and systems such as domain controllers, to prevent lateral movements by an attacker.
- Vulnerability management must rely on a formalized and tool-supported process, not on manual and ad hoc actions, to ensure effective identification and remediation of security flaws.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire