Products Intelligence Pricing Methodology Contact
Cresthaven Analytics Intelligence Brief

BaFin German Financial Brief

July 20, 2026 · Federal Financial Supervisory Authority · EU

BaFin fines TeamViewer SE €240,000 for failing to disclose a cyberattack as inside information under MAR

BaFin imposed a €240,000 administrative fine on TeamViewer SE on July 16, 2026 for violating the Market Abuse Regulation. The violation concerned TeamViewer SE's failure to disclose a cyberattack as inside information without delay.

BaFin's action places cyberattacks within the inside information perimeter of the Market Abuse Regulation for listed issuers, with the disclosure obligation attaching at the point the issuer becomes aware of the incident. Issuers that defer disclosure pending technical remediation or legal review carry the same enforcement exposure as TeamViewer SE faced. The action applies to all EU-listed issuers subject to MAR, not solely German-domiciled companies, because MAR is a directly applicable EU regulation across all member states.

  • Cyberattack Disclosure Is an Inside Information Obligation: BaFin's action confirms that a material cyberattack constitutes inside information under the Market Abuse Regulation, triggering an immediate ad hoc disclosure obligation for listed issuers. Issuers that delay disclosure pending internal investigation or remediation carry a direct enforcement exposure.
  • Listed Technology and Software Firms Face Elevated Scrutiny: TeamViewer SE operates a widely deployed remote-access platform, making the cyberattack operationally significant to its business. BaFin's action signals that sector-specific operational incidents at technology issuers are within scope of MAR's disclosure perimeter, not solely financial or governance events.
  • The €240,000 Fine Reflects MAR's Administrative Penalty Tier: The penalty sits within MAR's administrative fine framework for natural and legal persons. The figure does not represent the ceiling of available sanctions; BaFin retains authority to impose higher penalties for more serious or repeated violations.
  • Disclosure Timing Is the Core Compliance Variable: BaFin's stated ground is the absence of disclosure without delay, not the cyberattack itself. Issuers must assess whether a security incident meets the inside information threshold at the point of discovery, not after containment or public reporting by third parties.

- BaFin has previously enforced MAR ad hoc disclosure obligations against issuers for financial and governance events. Applying that obligation explicitly to a cyberattack extends enforcement into operational security incidents.

- The action establishes that the moment of discovery — not remediation or public knowledge — is the relevant disclosure trigger for cyber incidents under MAR.

- ESMA's supervisory convergence work on MAR enforcement, combined with its ongoing coordination with national competent authorities on the scope of inside information, positions this action as a reference point for NCAs across the EU.

HIGH — cross-region regulatory nexus (rule G)

Monitor BaFin and ESMA for further enforcement actions or supervisory guidance addressing the intersection of cyber incident management and MAR ad hoc disclosure obligations.

Regulation (EU) No 596/2014 (Market Abuse Regulation), Article 17; German Securities Trading Act (Wertpapierhandelsgesetz, WpHG), Section 40c

www.bafin.de — Source ↗

This is a sample intelligence brief from Cresthaven Analytics. Live subscribers receive briefs like this on a daily or weekly cadence depending on tier.