L’Autorità Garante della Privacy e il caso Revolut
L’Autorità Garante della Privacy e il caso Revolut
NEWS
L’Autorità Garante della Privacy e il caso Revolut
Sul caso Revolut si è mossa l’Autorità Garante della Privacy. E’ partita una verifica immediata su eventuali falle nella sicurezza degli accessi delle banche italiane. Sia per appurare se vi siano stati altri casi di tentata infiltrazione, come nella vicenda Revolut. Sia per richiamare gli istituti bancari a un controllo efficace al proprio interno.
Dagli uffici dell’Autorità Garante è partita una comunicazione alla rete dei responsabili di protezione dati (Dpo) degli istituti bancari invitando a procedere ad una solerte verifica all’interno sui propri sistemi e, nel caso di falle accertate, a provvedere a prendere subito contatto con l’Autorità. Già da mesi sta lavorando una task force Autorità- banche che, sulla scia di quanto già fatto nel caso Intesa San Paolo, con le migliaia di accessi ai conti dei clienti e l’intervento del Garante, sia all’erta nel rafforzare le difese.
Considerato che le modalità utilizzate per l'acquisizione illecita di dati personali risultano particolarmente insidiose e non si può escludere a priori che siano stati fatti tentativi analoghi anche nei confronti di altri istituiti di credito, l’Autorità ha chiesto agli istituti bancari di avviare una verifica all’interno dei sistemi per escludere la eventuale presenza di comunicazioni "anomale" provenienti dalla stessa casella pec ed effettuare gli opportuni approfondimenti. Nel caso in cui dovessero emergere situazioni simili a quelle del caso Revolut Bank, banche e i istituti finanziari sono chiamati ad adottare tempestivamente le misure per attenuare i possibili effetti negativi per gli interessati e informare l'Autorità, ai sensi degli artt. 33 del Regolamento.
L’Autorità Garante si è fatta promotrice di un’azione con l’Autorità omologa lituana (dove si trova la sede legale principale di Revolut), informando delle informazioni in possesso del Garante italiano, e invitando ad uno scambio di informazioni, così da rafforzare l’azione di contrasto.
Inoltre, l’Autorità si è mossa sul fronte del Ministero degli Interni per inquadrare più approfonditamente la vicenda Revolut e appurare se vi sono altre banche o istituti finanziari coinvolti, circoscrivendo il danno avvenuto facendo emergere quanti e quali dati sono stati compromessi.
La vicenda, infatti, ha evidenziato alcuni lati deboli delle Pec ufficiali in uso, e su questo occorrerà lavorare approfonditamente.
_______
Italian Data Protection Authority and the Revolut case
The Data Protection Authority has taken action in response to the Revolut case. An immediate investigation has been launched into potential security breaches in the access systems of Italian banks. The aim is to ascertain whether there have been other cases of attempted infiltration similar to the Revolut incident and to urge banking institutions to implement effective internal controls.
The Data Protection Authority has issued a notice to the Data Protection Officer network at banking institutions, urging them to carry out a thorough internal audit of their systems. In the event of confirmed breaches, they must contact the Authority immediately. Following the example set by the Intesa San Paolo case, which involved thousands of unauthorised accesses to customer accounts and intervention by the Data Protection Authority, a joint Authority-bank task force has been working for several months now to strengthen defences.
As the methods used to unlawfully acquire personal data are insidious, and similar attempts against other credit institutions cannot be ruled out a priori, the Authority has asked banking institutions to audit their systems to rule out the presence of 'anomalous' communications from the same certified email account, and to conduct the necessary investigations.
In situations similar to those in the Revolut Bank case, banks and financial institutions must take prompt measures to mitigate any potential adverse effects and inform the Authority, as required by Article 33 of the Regulation.
The Data Protection Authority has initiated cooperation with its Lithuanian counterpart, where Revolut’s principal place of business is located. The Italian Data Protection Authority has shared information with its Lithuanian counterpart and invited an exchange of information, with a view to strengthening enforcement efforts.
Pending the outcome of GPDP’ investigation (as well as of the parallel investigation being conducted by the police on the related possible crimes), the Italian Authority requested the Lithuanian Authority to: a) confirm whether it has received a data breach notification (or other communications on the case) from Revolut Lithuania; b) share with the Italian Authority any information in possession that might assist our Authority in further examining the matter, including in determining whether other banks operating in Italy have also been affected. The Italian GPDP is commited to sharing with the Lithuanian Authority information and the results of the investigations currently underway in Italy about this case.
Furthermore, the Authority has liaised with the Ministry of the Interior to gain a more detailed understanding of the Revolut case, ascertain whether any other banks or financial institutions are involved and assess the extent of the damage by identifying what kind and how much data has been compromised.
This incident has highlighted certain weaknesses in the official certified email (PEC) system currently in use and will require in-depth attention.
Condividi