Poste Italiane's Fraud Prevention Center — €25 Million Blocked, Then a €12.5 Million Fine Over Device Scanning
Italy
Poste Italiane's 24/7 Fraud Prevention Center blocked about €25 million in fraud across 2 billion transactions in 2024 via ML …
Canada · Ottawa · See the Canada profile · See the Ottawa profile
Evidence: Descriptive / self-reported Top 12% 80/100 · Ask Evidence Copilot about this practice
Canada's signals-intelligence agency runs Assemblyline, an open-sourced ML malware triage platform, plus a separate classifier flagging threats commodity antivirus misses across ~900,000 government devices, blocking 6.6 billion malicious actions daily.
The Canadian Centre for Cyber Security, part of the Communications Security Establishment (CSE), operates sensors across Government of Canada networks and open-sourced Assemblyline in 2017, a machine-learning malware-analysis platform used to triage suspicious files at scale for government agencies and critical-infrastructure partners.
Alongside Assemblyline, CSE data scientists built a separate machine-learning malware-classification model specifically aimed at catching custom, nation-state malware that commodity antivirus tools (built for generic threats) do not detect.
Flagged files from the ML classifier are quarantined, and the model is refined once commercial antivirus vendors catch up to the same threats, per CSE's own AI Strategy.
CSE's Annual Report 2023-2024 states Assemblyline scanned over 1 billion suspicious files that year, with 308 partner organisations (58 government, 250 critical infrastructure) — up 35% year-on-year — and sensors covering roughly 900,000 devices across 167 federal institutions and Crown corporations. The Cyber Centre reports blocking an average of 6.6 billion potentially malicious actions per day, up from 6.3 billion in 2022-23. Independent reporting by the ICTC-CTIC policy institute and the Canadian magazine The Walrus corroborates the order of magnitude of blocked activity and sensor deployment, drawing on the same annual reports and an interview with CSE's chief.
CSE has not published a false-positive or accuracy rate specific to the ML classifier, nor a breakdown of how much blocked activity is specifically machine-learning-driven versus signature- or rule-based detection. No independent audit of detection accuracy exists; media corroboration confirms scale, not ML-specific performance claims.
National / regional programmes
Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.
Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.
Where this practice's information was retrieved from, and when.
Italy
Poste Italiane's 24/7 Fraud Prevention Center blocked about €25 million in fraud across 2 billion transactions in 2024 via ML …
Estonia
Estonia's paying agency ARIB uses a deep-learning system built with Tartu Observatory and KappaZeta to check mowing compliance on all …
Denmark
Denmark's Agricultural Agency uses DHI's VeriCAP platform to satellite-monitor roughly 600,000 farm fields nationwide, verifying over €800 million a year …
Ireland
Since 2011, Ireland's Revenue Commissioners have used AI risk scoring (REAP) to target tax-compliance interventions; 290,000 data-analytics-driven interventions in 2023 …
Open full copilot Grounded in cited practices — always check the sources.