What the logs showed
Vincenzo Coviello worked at the Agribusiness office in Bisceglie, Apulia, and according to the investigation used his work access credentials to open the accounts of people he did not manage. The prosecution dates the start to January 2020 and the end to April 2024. The Data Protection Authority counted differently: within a narrower window from February 21, 2022 to April 24, 2024, it counted more than 6,600 accesses and one more affected client, that is, 3,573. Il Post ↗The list of names is longer than the four constitutional officials. It includes former prime ministers Mario Draghi, Matteo Renzi, Giuliano Amato, and Enrico Letta, former ministers Umberto Bossi, Luigi Di Maio, Carlo Calenda, Mara Carfagna, Raffaele Fitto, Daniela Santanchè, and Mariastella Gelmini, then-central bank governor Ignazio Visco, and a number of members of parliament. Investigators date accesses to Silvio Berlusconi's data between 2022 and 2023, one of them falling on the day of his death. Corriere della Sera ↗
The investigation did not start from the bank's internal checks. It was triggered in July 2024 by a report from a client who had been notified of anomalous access to their account. Only then did the carabinieri, with the help of cybercrime experts, go through the system logs and reconstruct the scope. For this conduct, the prosecution uses the term "asset espionage," which is not a legal classification of the charge but a description of its nature. It speaks of the "compulsive and repetitive nature" of the accesses, which multiplied "almost obsessively," and writes that obtaining this data endangered "not only individuals' right to privacy, but the very security of democratic institutions." Il Fatto Quotidiano ↗
Six months after the reprimand
In October 2023, an alert was triggered at the Bisceglie branch due to an unusual concentration of queries, and the branch manager knew about the accesses. Coviello received a verbal reprimand and later claimed that he stopped after the conversation with his supervisor.That claim was disproved not by the investigation, but by the bank itself. Already in October 2024, it stated that between November 2023 and April 2024 he made a further 347 unauthorized accesses to the accounts of 261 clients he did not manage. Il Sole 24 Ore ↗ He was dismissed on August 8, 2024, ten months after the alert was triggered.
Two verdicts on the same bank
The Data Protection Authority ruled on March 26, 2026, and fined the bank 31.8 million euros for "serious shortcomings in personal data security caused by the inadequacy of the technical and organizational measures adopted." According to the authority, the unauthorized accesses were not caught by internal control systems, and the operating model, which allowed operators to search the entire client base, was not balanced by controls capable of detecting them. The incident report was incomplete and delayed, and it took a separate order from the authority in November 2024 to get the bank to individually inform all affected clients. ANSA ↗ Il Post ↗The prosecution reached the opposite assessment of the same measures. It was not weighing the same legal question as the authority: the authority ruled on a breach of data protection rules, while the prosecution ruled on the company's criminal liability for its employee's conduct. It discontinued proceedings against the bank on June 10, 2026, stating that it has "technical and organizational measures of demonstrable solidity" and that "no reproach can be addressed to the bank for neglected or insufficient organization." According to the prosecution, Coviello's conduct is not "a symptom of a structural shortcoming or a systemic crack," but a circumvention of robust measures from within, and the bank is "the real and sole injured party." Il Fatto Quotidiano ↗
The two assessments thus stand side by side. The fine has not been annulled, but the bank does not yet have to pay it: on July 13, 2026, the Turin court suspended the enforceability of the decision by way of a preliminary injunction, and the authority has since withdrawn the text from its own website, where a notice about the court order now hangs in its place. The appeal proceedings are ongoing, so the public cannot currently read the reasoning on which the fine is based. Garante per la protezione dei dati personali ↗
It's not just one employee
In the same report, the carabinieri state that seven other bank employees behaved the same way. They speak of "a worrying vulnerability to the lure of forbidden curiosity," albeit with lower frequency and severity and without targeting sensitive institutional figures. Their files were formally separated out and referred, according to jurisdiction, to other judicial offices across Italy, so seven cases that share a common origin will from now on be assessed separately. Corriere della Sera ↗Moreover, the fine over the Coviello case was not the only one in March. Two weeks earlier, the same authority had imposed a further 17.6 million euros on the bank for profiling around 2.4 million people without an adequate legal basis when automatically transferring clients to the digital bank Isybank. In that case, it was not an employee acting against the bank, but a decision by the institution itself. This fine, too, is currently suspended, and the bank is contesting it. Il Post ↗
Limits of this account
The closing of the investigation is neither an indictment nor a verdict. Coviello is charged and defends himself by saying that he acted on his own initiative, did not print or store anything, and did not pass the data on to anyone. He has challenged his dismissal and submitted a psychological assessment. Il Messaggero ↗ After more than two years of investigation, even the most basic question remains open: why he did it, and whether any of that data went further. Nothing published so far shows that he handed it over to anyone.For the Slovak reader, the case has one factual connection that needs to be stated precisely. The ultimate parent company of VÚB is Intesa Sanpaolo, and the sole shareholder of the Slovak bank is the Luxembourg-based Intesa Sanpaolo Holding International, which holds a 100 percent stake. Výročná správa VÚB za rok 2025 ↗ Nothing suggests that anything similar has happened at VÚB, and claiming so would be unfounded. The relevant question is a different one. The arrangement that the Italian authority identified as the core of the problem — that a rank-and-file employee can see the entire client base and controls do not detect it on their own — is not an Italian invention or the fault of a single bank. It is the common way retail banks are built, and whether controls keep it in check is not a question that concerns Italy alone.
What hotinfo is following
- Prosecutors in Bari have either indicted Vincenzo Coviello or dropped the case.
- The Turin court has ruled on the challenge to the 31.8-million-euro fine imposed on Intesa Sanpaolo.
- The reasoning of Garante decision no. 208 of 26 March 2026 is publicly available again.
- The judicial offices have decided the severed files of the seven other bank employees.
- At least one affected client has obtained damages from the bank or from Coviello.
*Illustrative photo: the Intesa Sanpaolo skyscraper in Turin, headquarters of the bank's retail division. Author Zairon, Wikimedia Commons, CC BY-SA 4.0.*







