Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
wind tre

wind tre Vendor Cyber Rating & Cyber Score

windtregroup.it

WINDTRE è l’operatore italiano che offre connessioni, energia e prodotti assicurativi*. Un punto di riferimento per le famiglie che chiedono affidabilità, convenienza e trasparenza nelle offerte e che possono usufruire di consulenza e supporto capillare grazie alle centinaia di WINDTRE Store sul territorio nazionale. WINDTRE si posiziona tra i principali operatori mobili in Italia e dal 2025 WINDTRE è il primo operatore in Italia a offrire servizi mobili su rete 5G Stand Alone, un’infrastruttura nativa del tutto indipendente dal 4G, in grado di supportare soluzioni evolute su slice di rete dedicati. WINDTRE ha rivoluzionato il proprio approccio al lavoro con il modello “Human Working”, che mette al centro il benessere delle persone e


wind tre A.I CyberSecurity Scoring

wind tre
Company Information
Website:https://www.windtregroup.it
Employees number:7,160
Number of followers:106,790
NAICS:517
Industry Type:Telecommunications
Homepage:windtregroup.it
wind tre Risk Score (AI oriented)
Between 650 and 699
logo
wind treTelecommunications
Updated:
20/07/2026
685/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
wind tre Global Score (TPRM)
xxxx
logo
wind treTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

wind tre
wind treWeak
Current Score
685B (WEAK)
01000
2 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
682Before Incident
JULY 2026
685Before Incident
Vulnerability
22 Jul 2026wind tre
Check Point: CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks

Critical Check Point Authentication Flaw Actively Exploited in the Wild

681After Incident
CRITICAL-4
CHE1784787889
Critical Check Point Authentication Flaw Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about CVE-2026-16232, a critical authentication vulnerability in Check Point SmartConsole that is being actively exploited. The flaw, rated 9.3 on the CVSS scale, affects Check Point Security Management and Multi-Domain Management platforms, allowing unauthenticated remote attackers to obtain an application login token and gain full administrative access to affected systems. The vulnerability was discovered during an internal BLAST (Business Logic Attack Surface Testing) review under Check Point’s Frontier AI Readiness Program. Exploitation has been confirmed in real-world attacks, though limited to environments where management interfaces are exposed to the internet without IP-based restrictions. Attackers could leverage this access to modify security policies, deploy malicious configurations, or pivot deeper into enterprise networks, risking full infrastructure compromise. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the need for immediate patching. Affected versions include R81.10, R81.20, R82, and R82.10, with older versions also potentially vulnerable. Check Point has released a Jumbo Hotfix (July 22, 2026) to remediate the issue and strengthen system resilience. In the same advisory, Check Point disclosed two additional high-severity vulnerabilities: - CVE-2026-62144 (CVSS 9.3): Another authentication bypass and privilege escalation flaw in management systems, though not yet exploited. - CVE-2026-62145 (CVSS 7.5): A local privilege escalation issue in GaiaOS WebUI, currently unexploited. Security teams are advised to restrict SmartConsole and management access to trusted IP addresses, enforce firewall protections, and monitor for indicators of compromise, including: - 151.241.99[.]207 - 151.241.99[.]233 - 158.62.198[.]182 - 192.142.10[.]99 - 139.28.37[.]250 - 194.213.18[.]137 The incident underscores the risks of exposed management interfaces and the necessity of proactive patching, strict access controls, and continuous monitoring to mitigate evolving threats.
INCIDENT DETAILS -
TYPE
Authentication Bypass
IMPACT
Systems Affected: Check Point Security Management and Multi-Domain Management platformsOperational Impact: Full administrative access, modification of security policies, deployment of malicious configurations, potential full infrastructure compromise
JUNE 2026
684Before Incident
MAY 2026
682Before Incident
APRIL 2026
681Before Incident
MARCH 2026
679Before Incident
FEBRUARY 2026
677Before Incident
JANUARY 2026
675Before Incident
DECEMBER 2025
673Before Incident
NOVEMBER 2025
671Before Incident
OCTOBER 2025
669Before Incident
SEPTEMBER 2025
667Before Incident
FEBRUARY 2025
771Before Incident
Breach
01 Feb 2025wind tre
WINDTRE: Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

WINDTRE Fined €1.7M Over Dual Data Breaches Affecting 365,000 Customers

650After Incident
CRITICAL-121
WIN1784558266
Italian Telecom Giant WINDTRE Fined €1.7M Over Dual Data Breaches Affecting 365,000 Customers Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, imposed a €1.7 million fine on WINDTRE, one of the country’s largest telecom operators, for "serious data security shortcomings" that enabled two separate breaches in February 2025. The attacks compromised the personal data of over 365,000 customers, with payment details exposed for 41,359 individuals. The breaches stemmed from social engineering tactics rather than software vulnerabilities. Attackers posed as support technicians, tricking staff at two WINDTRE stores into granting access to internal systems. Once inside, they extracted customer names, contact details, and in some cases postal payment slips, IBAN numbers, partially masked credit card numbers, and card expiry dates. The regulator’s investigation uncovered critical flaws in WINDTRE’s security practices. Despite the company’s claims of robust defenses including three-factor authentication, firewalls, and access restrictions audits revealed lapses in credential and certificate management. Digital certificates and private keys were not stored in encrypted vaults, leaving them vulnerable if devices were compromised. Additionally, internal APIs, which facilitated a large-scale enumeration attack (roughly 2 million requests), lacked rate-limiting and CAPTCHA protections, violating OWASP’s API Security Top 10 standards. WINDTRE argued that the incidents resulted from human error, not systemic failures, and noted challenges in enforcing password managers for independently run stores. However, the regulator dismissed these defenses, ruling that the company violated GDPR’s data integrity, confidentiality, and security requirements. As part of the ruling, WINDTRE was ordered to strengthen credential and certificate protection, implement secure password management tools, and enhance cybersecurity procedures. The fine amount reflected the company’s prompt breach reporting, post-incident remediation efforts, cooperation during the investigation, and lack of prior privacy violations.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: €1.7 million fineData Compromised: Personal data of 365,000 customers, payment details of 41,359 individualsSystems Affected: Internal systems, APIsBrand Reputation Impact: YesLegal Liabilities: GDPR violationsIdentity Theft Risk: YesPayment Information Risk: Yes
DATA BREACH
Customer namesContact detailsPostal payment slipsIBAN numbersPartially masked credit card numbersCard expiry datesNumber Of Records Exposed: 365,000Sensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for wind tre ?
?
What was wind tre's A.I Rankiteo Cyber Score in July 2026 ?
?
What was wind tre's A.I Rankiteo Cyber Score in June 2026 ?
?
What was wind tre's A.I Rankiteo Cyber Score in May 2026 ?
?
What was wind tre's A.I Rankiteo Cyber Score in April 2026 ?
?
What was wind tre's A.I Rankiteo Cyber Score in March 2026 ?
?
What was wind tre's A.I Rankiteo Cyber Score in February 2026 ?
?
What was wind tre's A.I Rankiteo Cyber Score in January 2026 ?
?
What was wind tre's A.I Rankiteo Cyber Score in December 2025 ?
?
What was wind tre's A.I Rankiteo Cyber Score in November 2025 ?
?
What was wind tre's A.I Rankiteo Cyber Score in October 2025 ?
?
What was wind tre's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on wind tre's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with wind tre ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view wind tre's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?