Report them to the authorities. This is extortion of private data and needs to be investigated.
Free and Open Source Software
If it's free and open source and it's also software, it can be discussed here. Subcommunity of Technology.
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
The authorities are probably the ones compelling them to collect this information.
In which case Nexi should be able to state clearly that they are required to ask for this data by law.
Yes they should, however often they are not allowed to disclose such information. Over the last couple of decades, governments have realised that they can sidestep onerous legal principles such as innocent until proven guilty by requiring financial services companies to enforce KYC rules and the like. These rules were sold to us as a way to prevent the mega rich from dodging tax and organised crime from freely spending and moving their money, but surprise surprise governments have no qualms using them against people who are not so clearly in the wrong.
So Nexi can't justify it. FSFe would be entirely within their rights to seek a judicial path.
I'd happily contribute towards that case.
Same here
The authorities should not be asking for passwords. FSF should not have those to give.
Here's a list of usernames, and here's a list of salted and hashed passwords. There is no correlation between the usernames and the passwords. Each password salt is unique.
The decisions that Nexi has made are incomprehensible to us. Over the last months, as part of a security audit that Nexi claimed to be conducting, we have provided them with large amounts of the FSFE’s financial documentation, which even included private information of our executive staff. We have answered all of their questions. But we have to draw a line when private companies like Nexi demand access to the sensitive and private data of our supporters.
Almost sounds like they're being socially engineered by an impostor. Bizarre behaviour.
Nexi seems like a really bad company, at least it became one...
Nexi sounds hackable and flush with money for a scam audit. I sincerity hope no randsomeware befalls them.
specifically the usernames and passwords of our supporters
If FSFE is even able to provide passwords for user accounts in the first place, they're doing password security wrong.
Having gotten that off my chest, of there is nothing missing from this story and it's a complete picture of events, Nexi needs to be investigated for extortion.
Nexi ratings: BBB- (Fitch, 2024)
Ba1 (Moody's, 2025
BBB- S&P, 2025)
Even the rating whores think Nexi is trash.