HotInfo Menu
✍️ EDITORIAL PICKS
A banker peered into the accounts of Italy's president and prime minister. He did it for four years, the authority fined the bank for it, and the prosecution called it the sole injured party

A banker peered into the accounts of Italy's president and prime minister. He did it for four years, the authority fined the bank for it, and the prosecution called it the sole injured party

The prosecution in Bari has, after more than two years, closed the investigation into a former Intesa Sanpaolo bank employee. According to the prosecution, he accessed the banking data of 3,572 clients without authorization. Among them were President Sergio Mattarella, Prime Minister Giorgia Meloni, Senate President Ignazio La Russa, and Defense Minister Guido Crosetto. ANSA ↗ The charge is not curiosity or theft of money, but an attack on infrastructure classified within the national cybersecurity perimeter and the unlawful acquisition of information concerning state security. Corriere della Sera ↗
Key actors — tap for context

What the logs showed

Vincenzo Coviello worked at the Agribusiness office in Bisceglie, Apulia, and according to the investigation used his work access credentials to open the accounts of people he did not manage. The prosecution dates the start to January 2020 and the end to April 2024. The Data Protection Authority counted differently: within a narrower window from February 21, 2022 to April 24, 2024, it counted more than 6,600 accesses and one more affected client, that is, 3,573. Il Post ↗

The list of names is longer than the four constitutional officials. It includes former prime ministers Mario Draghi, Matteo Renzi, Giuliano Amato, and Enrico Letta, former ministers Umberto Bossi, Luigi Di Maio, Carlo Calenda, Mara Carfagna, Raffaele Fitto, Daniela Santanchè, and Mariastella Gelmini, then-central bank governor Ignazio Visco, and a number of members of parliament. Investigators date accesses to Silvio Berlusconi's data between 2022 and 2023, one of them falling on the day of his death. Corriere della Sera ↗

The investigation did not start from the bank's internal checks. It was triggered in July 2024 by a report from a client who had been notified of anomalous access to their account. Only then did the carabinieri, with the help of cybercrime experts, go through the system logs and reconstruct the scope. For this conduct, the prosecution uses the term "asset espionage," which is not a legal classification of the charge but a description of its nature. It speaks of the "compulsive and repetitive nature" of the accesses, which multiplied "almost obsessively," and writes that obtaining this data endangered "not only individuals' right to privacy, but the very security of democratic institutions." Il Fatto Quotidiano ↗

Six months after the reprimand

In October 2023, an alert was triggered at the Bisceglie branch due to an unusual concentration of queries, and the branch manager knew about the accesses. Coviello received a verbal reprimand and later claimed that he stopped after the conversation with his supervisor.

That claim was disproved not by the investigation, but by the bank itself. Already in October 2024, it stated that between November 2023 and April 2024 he made a further 347 unauthorized accesses to the accounts of 261 clients he did not manage. Il Sole 24 Ore ↗ He was dismissed on August 8, 2024, ten months after the alert was triggered.

Two verdicts on the same bank

The Data Protection Authority ruled on March 26, 2026, and fined the bank 31.8 million euros for "serious shortcomings in personal data security caused by the inadequacy of the technical and organizational measures adopted." According to the authority, the unauthorized accesses were not caught by internal control systems, and the operating model, which allowed operators to search the entire client base, was not balanced by controls capable of detecting them. The incident report was incomplete and delayed, and it took a separate order from the authority in November 2024 to get the bank to individually inform all affected clients. ANSA ↗ Il Post ↗

The prosecution reached the opposite assessment of the same measures. It was not weighing the same legal question as the authority: the authority ruled on a breach of data protection rules, while the prosecution ruled on the company's criminal liability for its employee's conduct. It discontinued proceedings against the bank on June 10, 2026, stating that it has "technical and organizational measures of demonstrable solidity" and that "no reproach can be addressed to the bank for neglected or insufficient organization." According to the prosecution, Coviello's conduct is not "a symptom of a structural shortcoming or a systemic crack," but a circumvention of robust measures from within, and the bank is "the real and sole injured party." Il Fatto Quotidiano ↗

The two assessments thus stand side by side. The fine has not been annulled, but the bank does not yet have to pay it: on July 13, 2026, the Turin court suspended the enforceability of the decision by way of a preliminary injunction, and the authority has since withdrawn the text from its own website, where a notice about the court order now hangs in its place. The appeal proceedings are ongoing, so the public cannot currently read the reasoning on which the fine is based. Garante per la protezione dei dati personali ↗

It's not just one employee

In the same report, the carabinieri state that seven other bank employees behaved the same way. They speak of "a worrying vulnerability to the lure of forbidden curiosity," albeit with lower frequency and severity and without targeting sensitive institutional figures. Their files were formally separated out and referred, according to jurisdiction, to other judicial offices across Italy, so seven cases that share a common origin will from now on be assessed separately. Corriere della Sera ↗

Moreover, the fine over the Coviello case was not the only one in March. Two weeks earlier, the same authority had imposed a further 17.6 million euros on the bank for profiling around 2.4 million people without an adequate legal basis when automatically transferring clients to the digital bank Isybank. In that case, it was not an employee acting against the bank, but a decision by the institution itself. This fine, too, is currently suspended, and the bank is contesting it. Il Post ↗

Limits of this account

The closing of the investigation is neither an indictment nor a verdict. Coviello is charged and defends himself by saying that he acted on his own initiative, did not print or store anything, and did not pass the data on to anyone. He has challenged his dismissal and submitted a psychological assessment. Il Messaggero ↗ After more than two years of investigation, even the most basic question remains open: why he did it, and whether any of that data went further. Nothing published so far shows that he handed it over to anyone.

For the Slovak reader, the case has one factual connection that needs to be stated precisely. The ultimate parent company of VÚB is Intesa Sanpaolo, and the sole shareholder of the Slovak bank is the Luxembourg-based Intesa Sanpaolo Holding International, which holds a 100 percent stake. Výročná správa VÚB za rok 2025 ↗ Nothing suggests that anything similar has happened at VÚB, and claiming so would be unfounded. The relevant question is a different one. The arrangement that the Italian authority identified as the core of the problem — that a rank-and-file employee can see the entire client base and controls do not detect it on their own — is not an Italian invention or the fault of a single bank. It is the common way retail banks are built, and whether controls keep it in check is not a question that concerns Italy alone.

What hotinfo is following

0/5 completedcheck by 15.12.2026
  • Prosecutors in Bari have either indicted Vincenzo Coviello or dropped the case.
  • The Turin court has ruled on the challenge to the 31.8-million-euro fine imposed on Intesa Sanpaolo.
  • The reasoning of Garante decision no. 208 of 26 March 2026 is publicly available again.
  • The judicial offices have decided the severed files of the seven other bank employees.
  • At least one affected client has obtained damages from the bank or from Coviello.
How it continues — the full tracker →

*Illustrative photo: the Intesa Sanpaolo skyscraper in Turin, headquarters of the bank's retail division. Author Zairon, Wikimedia Commons, CC BY-SA 4.0.*

On Record

👤
Guido Crosetto Minister obrany Talianska
29.05.2026
„Esprimo la più ferma condanna per il drone russo che ha colpito un edificio residenziale nella città di Galati"

Odsúdenie útoku na rumunskom území

👤
Vincenzo Coviello Bývalý zamestnanec Intesa Sanpaolo
14.10.2024
„Ho agito di mia iniziativa"

Obhajoba v disciplinárnom konaní: tvrdil, že konal sám, nič netlačil ani neuchovával a údaje nikomu neposkytol. Banka to spochybnila — od novembra 2023 do apríla 2024 mal urobiť ďalších 347 neoprávnených prístupov.

1

Geographic locations

Location: Bari
Bari, Puglia, Italia
Open in Google Maps
Location: Bisceglie
Bisceglie, Barletta-Andria-Trani, Puglia, 76011, Italia
Open in Google Maps
Location: Luxembourg
World Economy & Business 👤 carlo calenda 👤 coviello 👤 daniela santanchèová 👤 enrico letta 👤 giorgia meloni 👤 giuliano amato 👤 guido crosetto 👤 ignazio la russa 👤 ignazio visco 👤 luigi di maio 📍 bari 📍 bisceglie 📍 luxemburg 📍 talianskej republiky 📍 turín 🏢 fratelli d'italia 🏢 intesa sanpaolo 🏢 intesa sanpaolo holding international 🏢 isybank 🏢 talianskej centrálna banky 🏢 úrad na
🕒

Live Updates

LIVE