On February 15, 2025, an unauthorized individual used the credentials of an employee from our call center service provider to access our customer data management system (“CRM”) and download a significant amount of personal data related to Maserati customers and potential customers. The unauthorized access occurred from an IP address located in India. <br> <br> We discovered the incident on February 19, 2025, and immediately initiated appropriate investigations and containment measures and informed the competent Authority.

The incident involved a series of personal data stored in Maserati's CRM system. <br> <br>The categories of data that could be present in the system and therefore potentially affected include: <br> <br> <ul> <li>Identifying and contact data (e.g., name, surname, email address, phone number)</li> <li>Additional personal data (gender, nationality, language)</li> <li>Vehicle data (vehicle identification number (VIN), license plate number)</li> <li>Contact data of dealers and their employees (name, surname, and email addresses)</li> </ul> <br> <b>Bank account or credit card details (e.g., card numbers, CVV, IBAN, or other sensitive banking information) were not affected.</b> <br> <br> It is important to note that not all this data was present for every individual concerned: their potential compromise depends on the specific presence of such information in the database at the time of the breach.

The potential risks for individuals whose personal data was involved include: <br> <br> <ul> <li>Phishing and targeted cyber attacks, using obtained contact information.</li> <li>Possible unauthorized exposure of personal data.</li> <li>Loss of control over personal data, which may result in receiving unwanted marketing communications.</li> </ul>

We recommend adopting the following security measures: <br> <br> <ul> <li><b>Be cautious of phishing attempts</b>, such as suspicious emails or messages requesting personal information.</li> <li><b>Avoid sharing sensitive data online</b> and always verify the authenticity of received communications.</li> </ul>

We immediately deactivated the compromised account and are working with our cybersecurity experts to implement additional security measures to prevent future breaches. <br> <br> As required by Regulation (EU) 2016/679 (GDPR), we have notified the incident to the Data Protection Authority.

Maserati is committed to ensuring maximum transparency in managing the incident. <br> <br> For this reason, Maserati has made a channel available for individuals to request information regarding the involvement of their personal data in the incident. <br> <br> <b><u>How to submit an information request:</u></b> <br> <br> Individuals can send their requests via email to the following addresses: <br> <br><ul> <li>For the United States and Canada:mymaserati@maserati.com</li> <li>For Korea: infokorea@maserati.com</li> <li>For Japan: info.japan@maserati.com</li> <li>For China: info@maserati.com</li> <li>For other countries: info@maserati.com</li></ul> <br> To ensure a prompt and accurate response, requests must: <br> <br> <ul> <li>Have <b>“Information Request FAQ”</b> as the <b>subject of the email</b>.</li> <li>Include the necessary information for Maserati to verify the identity of the requester (e.g., name, surname, email used for interaction with Maserati).</li> <li>Maserati is committed to providing a response as quickly as possible.</li> </ul>

Maserati S.p.A.
Viale Ciro Menotti, 322 – 41121, Modena (MO), Italy

Company registered under Italian law - VAT: IT 08245890010 R.E.A. Modena 347990

Share capital: 80.000.000 €, fully paid-up
Direction and coordination under Article 2497 of the Italian Civil Code: Stellantis N.V.

maserati@pec.fcagroup.com
www.maserati.com