Breaking
BackBanca Intesa, employee spies on the accounts of politicians and high state officials
Banca Intesa, employee spies on the accounts of politicians and high state officials
Developing
Il Sole 24 Ore45 minutes agoCrime3 min readItalyView original

Banca Intesa, employee spies on the accounts of politicians and high state officials

The notice of conclusion of the investigation was served on Vincenzo Coviello, accused of unauthorized access to a computer system for having spied on 3,572 customers, including Mattarella and Meloni.

Quick Look

An employee of Banca Intesa San Paolo in Bitonto was fired in August 2024 for spying on the accounts of over 3,500 customers, including political and institutional leaders, between January 2020 and April 2024.

AI-generated summary

Why It Matters

The investigations began in July 2024 after a complaint from an account holder, revealing abusive access that had continued since 2020.

Font size

Vincenzo Coviello, 54 years old, from Bitonto, in the province of Bari, was fired in August 2024, the employee of the Agribusiness branch of Banca Intesa San Paolo di Barletta, branch office in Bisceglie, in the Bat, who allegedly repeatedly spied on the current accounts of political figures and institutional representatives at the highest national levels such as the President of the Republic, the President of the Senate, the Prime Ministers, the President of the Constitutional Court, various ministers (Defense, Foreign Affairs, Tourism, Regional Affairs etc.), deputies, senators, MEPs, the governor of the Bank of Italy.

A notice of conclusion of the preliminary investigations was served against the man, with an invitation to present himself for questioning, by the prosecutor of the Republic of Bari Roberto Rossi and by the deputy prosecutor of the District Anti-Mafia Directorate Bruna Manganelli. The charges, among others, include abusive access to a computer system, continued and aggravated, and abusive access to the financial data of numerous institutions which are the foundation of the Republic.

The investigations developed thanks to the acquisition and analysis of the credit institution's system logs and computer traces, data which allowed the investigators to reconstruct in detail the intricate network of the alleged intrusions. The investigation was triggered by an account holder's complaint in July 2024. The investigation required "a huge operational effort", underlines the Prosecutor's Office. "In this context, it seems necessary to emphasize the crucial role and the very high professionalism of the Carabinieri Judicial Police Section in headquarters. The judicial police, operating with absolute dedication and with the support of technical consultants specialized in combating cybercrime, was able to unravel an impressive amount of digital data, decrypting an investigation of exceptional technical complexity which made it possible to shed light on a compromise of the company's IT systems of unprecedented proportions".

The scenario that emerged is defined as "absolutely serious", and characterized "by the compulsive and repeated nature of the abusive accesses, which multiplied in an almost obsessive manner on a vast audience of subjects".

The intrusions continued in silence for years: the investigations made it possible to ascertain that they began in January 2020 and continued constantly until the end of April 2024. By exploiting his operational credentials and company duties, the unfaithful employee was responsible for covert, systematic and prolonged monitoring, repeatedly and in a targeted manner violating the sensitive and financial data of as many as 3,572 customers, including high-ranking state figures, representatives of the institutions and members of the current political-executive summit.

The acquisition of this sensitive data would have exposed "not only the right to privacy of individuals, but the very security of democratic institutions, to serious risk. The gravity and extent of the intrusions gave the investigation inevitable national prominence, attracting the utmost attention of institutional leaders". Demonstrating the primary interest in putting a definitive stop to such an alarming and widespread illicit phenomenon, the investigation saw the intervention of the National Anti-Mafia and Anti-Terrorism Directorate (DNA).

The involvement of the latter body "certifies, unequivocally, how the protection of cyber security and the fight against every form of financial espionage represent an absolute and essential requirement for the defense of the country", highlights the Prosecutor's Office. "The incessant work of the investigators has also made it possible to ascertain that we are not dealing with an isolated phenomenon." During the investigations, profiles of responsibility emerged against seven other people, all employees of the same credit institute. The latter were the protagonists of conduct completely similar to that of the main suspect, "a symptom of a worrying vulnerability to the allure of illicit curiosity or dossier-gathering, albeit characterized by less offensiveness, frequency and extent, and not aimed at sensitive institutional objectives".

For these reasons, in order to guarantee maximum procedural speed, the position of these seven suspects was formally removed and the related files already transmitted for jurisdiction to the other judicial offices located throughout the national territory. The main suspect is now accused, in a single accusatory framework, of the crimes of unauthorized access to a computer or telematic system, aggravated by the fact that the affected banking infrastructure is formally included within the National Cyber Security Perimeter, making the attack a direct threat to the country's critical infrastructures, the illicit procurement of information concerning the security of the State for having acquired secret information focused in particular on the transactions of the members of the national political board and, finally, multiple and systematic violations of the legislation protecting privacy, for having carried out the illicit processing and potential dissemination of highly sensitive personal data.

The facts would have occurred more intensely from 2018 to 2023. Between 21 February 2022 and 24 April 2024, Coviello would have carried out a total of 6,573 accesses and abusive queries on the banking relationships of 3,541 customers of 685 Intesa San Paolo branches. Among the 'spied' political and institutional personalities, Sergio Mattarella, Giorgia Meloni, Mario Draghi, Luigi Di Maio, Guido Crosetto, Ignazio La Russa, Matteo Renzi, Silvio Berlusconi, Ignazio Visco, Giuliano Amato, Maria Stella Gelmini, Daniela Santanchè, Mara Carfagna, Marta Fascina, Vittorio Sgarbi, Enrico Letta, Umberto Bossi, Francesco Boccia, Carlo Calenda, Raffaele Fitto.

What to Watch

AI outlook — possibilities, not facts

  • Formal interrogation of the main suspect by the Prosecutor's Office

    Very likely · Within days

Open Questions

  • What were the real motivations behind Coviello's outbursts?
  • Has the stolen data been passed on to third parties?

Related Topics

This article was originally published by Il Sole 24 Ore.

Related Stories

More on this topicBanca Intesa San Paolo