FB pixel

Italian digital identity provider suffers data breach, 5.5M customers affected

Italian digital identity provider suffers data breach, 5.5M customers affected
 

InfoCert has had millions of its customers’ personal data stolen and put up for sale.

A leading European certification authority and provider of digital identity services such as Italy’s SPID (Public Digital Identity System), InfoCert posted a public notice on its website detailing the data breach on December 27. However, the notice has since been taken down.

Seen by Biometric Update, the notice said there had been an “unauthorized publication of personal data related to customers.” The personal data – which includes full names, tax codes, phone numbers and email addresses – of 5.5 million customers were taken.

According to a source, part of the stolen data was published and advertised on a dark web forum, with the entire database on sale for a price.

InfoCert claimed the leak came about via the systems of a third-party supplier, to which customers were registered, and that “illicit activity” had been committed against this supplier. InfoCert said that its own systems had not been compromised and nor had its service access credentials or passwords.

The company said that it is investigating the matter, and will report to the relevant authorities.

InfoCert is part of Tinexta Group and an Italian company operating in the IT security, digital signatures, and digital identity industry. It manages some 1.8 million active SPID identities and is one of the 12 accredited providers of such services in Italy where there are 39 million active SPID.

Cybersecurity and trust is an ongoing challenge in the digital identity market and analysts have elaborated on the global trends going into 2025, with use of AI and lack of understanding around cybersecurity cited as some major concerns.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Deepfake penetration outpacing security preparedness: GetReal Security

GetReal Security’s new Deepfake Readiness Benchmark Report confirms what many businesses are saying: convincing AI deepfakes are no longer a…

 

VPNs on regulatory block in EU, UK as lawmakers address age check circumvention

A philosophical tug-of-war is at play in the debate over whether Virtual Private Networks (VPNs) enable easy circumvention of age…

 

Thailand mandates biometric IDV for all social media advertisers to curb scams

Social media platforms in Thailand, such as Facebook, will need to introduce identity verification for advertisers, according to a new…

 

City of London seeks digital ID orchestrator as reusable identity push accelerates

The City of London is calling on tech companies to build a reusable digital identity verification service for the financial…

 

Jordan grants legal status to Sanad digital ID as users pass 2.6M

Jordan’s Sanad digital identity app, which operates using iris biometrics from IrisGuard, now has full legal status. A report from…

 

Face biometrics use cases outnumbered only by important considerations

With face biometrics now used regularly in many different sectors and areas of life, stakeholders are asking questions about a…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events