Cyber Incident Victim: TPL FVG
Date:
Mar 2025
Location:
Italy
Summary
TPL FVG experienced a cybersecurity incident involving its mobile ticketing service provider, where unauthorized access occurred at the provider's data center level, leading to the exfiltration of personal and contact data, specifically email addresses and phone numbers. Payment information remained secure as it is held separately by Payment Service Providers. The provider implemented containment measures and enhanced technical and organizational security following the breach. The organization advises vigilance against potential phishing attempts leveraging the exposed data and remains in contact with the provider to monitor the situation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Between March 29 and March 30, 2025, a cybersecurity breach occurred at the data center of TPL FVG's mobile ticketing service provider. This incident involved unauthorized access to the provider's systems, leading to the exfiltration of data to a remote cloud environment. The compromised data consisted of personal information and contact details, specifically names, email addresses, and telephone numbers belonging to individuals associated with TPL FVG's services. Payment information and credit card data were not affected in this breach, as these details are stored separately by Payment Service Providers and were not accessed. The provider informed TPL FVG about the incident, confirming the unauthorized data extraction and the scope of the exposed information.

Upon discovering the breach, the mobile ticketing service provider implemented measures designed to contain the incident and mitigate its effects. These actions included strengthening technical and organizational security protocols to prevent similar future occurrences. TPL FVG publicly disclosed the breach on April 15, 2025, advising customers to exercise heightened caution regarding potential phishing attempts, suspicious messages, or unsolicited phone calls requesting personal information. The company maintains ongoing communication with the provider to monitor the progress of investigations and assess any further necessary actions to protect affected individuals. TPL FVG directed customers to its website and contact numbers for more information, committing to publish any updates regarding the incident on its official site.
