Finnish SA fines S-Bank €1.8m for mobile banking authentication vulnerability
The Finnish Supervisory Authority (SA) has fined S-Bank EUR 1.8m and issued a reprimand for breaches of the EU General Data Protection Regulation (EU) 2016/679 (EU GDPR) after investigating a personal data breach reported in August 2022. The breach occurred when a new login function introduced in April 2022 contained a software flaw allowing customers to access others’ online banking accounts using strong authentication, leaving the vulnerability exploitable for more than three months and affecting a significant number of users. The SA found that S-Bank had failed to implement adequate safeguards, properly test the software, or respond appropriately to customer reports of login anomalies, violating Articles 5(1)(f), 25(1), 32(1), and 32(2) of the EU GDPR. The penalty reflected the seriousness of the breach, the protection of individuals’ rights, a prior reprimand, and consideration of a related EUR 7.67m fine imposed by the Finnish Financial Supervisory Authority in May 2025 for negligence in managing operational risks.