Skip to content

BaFin Imposes €240,000 Fine Against TeamViewer for Delayed Disclosure

Summary: Publicly listed IT companies must immediately disclose cyberattacks as price-sensitive insider information, otherwise they face a fine under the Market Abuse Regulation.

On 16 July 2026, BaFin fined TeamViewer €240,000 for delayed ad hoc disclosure of a cyberattack. The company had violated the Market Abuse Regulation by failing to promptly disclose the security incident.

The Federal Financial Supervisory Authority (BaFin) has imposed a fine of €240,000 on TeamViewer SE. The allegation: the software company violated Article 17, paragraph 1 of the Market Abuse Regulation (MAR) by failing to promptly disclose a cyberattack. Under the MAR, publicly listed companies must immediately disclose inside information – data that could materially affect the stock price.

The focus is on an attack from June 2024, when TeamViewer discovered an irregularity in its internal IT environment. The company stated at the time that the production environment and customer data were unaffected. According to reports, the attack was carried out by the APT group Cozy Bear, attributed to the Russian foreign intelligence service SVR. The significance lies in the fact that TeamViewer software is widely used for remote administration in enterprises – access to such remote access infrastructure could lead to data breaches in case of misuse.

For software companies, BaFin assessed security incidents as fundamentally price-relevant and thus as inside information. The authority could have imposed a fine of up to €2.5 million or two percent of annual turnover for a violation of Article 17 MAR. At €240,000, the fine remained well below that threshold.

The disclosure obligation serves two purposes: it is intended to prevent insiders from gaining unfair advantage in share trading through prior knowledge, and it is intended to ensure that investors are fully and promptly informed. Cyber incidents at publicly listed companies therefore require rapid disclosure – particularly in companies whose security is directly market-relevant.


Source: www.it-daily.net · Published 20 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: