Bottom line: TeamViewer failed to publicly disclose a cyberattack by Russian hackers in accordance with WpHG requirements, for which BaFin imposed an administrative fine.
The Federal Financial Supervisory Authority (BaFin) has fined TeamViewer €240,000 because the company failed to timely notify the capital market of a cyberattack. The delayed ad hoc disclosure violates the Securities Trading Act (WpHG).
TeamViewer was targeted by a cyberattack perpetrated by Russian hackers. The company did not notify the stock exchange supervisory authority immediately upon becoming aware of the incident, but rather with a delay. This constitutes a breach of the ad hoc disclosure obligations under the Securities Trading Act (WpHG), which requires listed companies to disclose events of material significance within an appropriate timeframe on a quarterly basis.
BaFin views the delayed disclosure as a violation of capital market transparency requirements. The administrative fine of €240,000 is intended to ensure the company complies with its notification obligations. For CISOs and compliance officers in listed companies, this case makes clear: cyberattacks must be recognized as material events and reported without delay, not retrospectively.
The case illustrates the intersection between cybersecurity incident response and capital market regulation. Companies must design their incident response processes to ensure that critical security incidents are escalated not only for technical analysis, but also immediately to compliance and investor relations channels.
Source: www.golem.de · Published 20 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.