BaFin German Financial Brief
Headline
BaFin fines TeamViewer SE €240,000 for failing to disclose a cyberattack as inside information under MAR
Executive Summary
BaFin imposed a €240,000 administrative fine on TeamViewer SE on July 16, 2026 for violating the Market Abuse Regulation. The violation concerned TeamViewer SE's failure to disclose a cyberattack as inside information without delay.
Bottom Line
BaFin's action places cyberattacks within the inside information perimeter of the Market Abuse Regulation for listed issuers, with the disclosure obligation attaching at the point the issuer becomes aware of the incident. Issuers that defer disclosure pending technical remediation or legal review carry the same enforcement exposure as TeamViewer SE faced. The action applies to all EU-listed issuers subject to MAR, not solely German-domiciled companies, because MAR is a directly applicable EU regulation across all member states.
Key Regulatory Signals
- Cyberattack Disclosure Is an Inside Information Obligation: BaFin's action confirms that a material cyberattack constitutes inside information under the Market Abuse Regulation, triggering an immediate ad hoc disclosure obligation for listed issuers. Issuers that delay disclosure pending internal investigation or remediation carry a direct enforcement exposure.
- Listed Technology and Software Firms Face Elevated Scrutiny: TeamViewer SE operates a widely deployed remote-access platform, making the cyberattack operationally significant to its business. BaFin's action signals that sector-specific operational incidents at technology issuers are within scope of MAR's disclosure perimeter, not solely financial or governance events.
- The €240,000 Fine Reflects MAR's Administrative Penalty Tier: The penalty sits within MAR's administrative fine framework for natural and legal persons. The figure does not represent the ceiling of available sanctions; BaFin retains authority to impose higher penalties for more serious or repeated violations.
- Disclosure Timing Is the Core Compliance Variable: BaFin's stated ground is the absence of disclosure without delay, not the cyberattack itself. Issuers must assess whether a security incident meets the inside information threshold at the point of discovery, not after containment or public reporting by third parties.
Regulatory Delta
- BaFin has previously enforced MAR ad hoc disclosure obligations against issuers for financial and governance events. Applying that obligation explicitly to a cyberattack extends enforcement into operational security incidents.
- The action establishes that the moment of discovery — not remediation or public knowledge — is the relevant disclosure trigger for cyber incidents under MAR.
- ESMA's supervisory convergence work on MAR enforcement, combined with its ongoing coordination with national competent authorities on the scope of inside information, positions this action as a reference point for NCAs across the EU.
Materiality Classification
HIGH — cross-region regulatory nexus (rule G)
Intelligence Outlook
Monitor BaFin and ESMA for further enforcement actions or supervisory guidance addressing the intersection of cyber incident management and MAR ad hoc disclosure obligations.