ctipilot.ch

BaFin TeamViewer MAR Article 17 disclosure fine

policy · policy:bafin-teamviewer-mar-disclosure-fine-2026

BaFin fined TeamViewer SE EUR 240,000 on 2026-07-16 (announced 2026-07-20) for violating EU Market Abuse Regulation Article 17(1) by not distributing ad-hoc disclosure of its mid-2024 cyberattack (publicly attributed to APT29/Cozy Bear) through the required regulated electronic information system, despite posting a website notice.

Coverage timeline
1
first 2026-07-26 → last 2026-07-26
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
weekly-policy
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Affected products
TeamViewer

Story timeline

  1. 2026-07-26BaFin fined TeamViewer EUR 240,000 for how it disclosed its 2024 nation-state breach — a website notice did not satisfy the ad-hoc-disclosure duty, setting a breach-disclosure-mechanics precedent for any SIX/EU-listed software or CI supplier
    weekly-policyA EUR 240k BaFin fine makes a vendor's nation-state breach 'inside information' requiring formal multi-channel ad-hoc disclosure — not just a website post

Where this entity is cited

  • weekly-policy1

Source distribution

  • bafin.de1 (50%)
  • heise.de1 (50%)

explore in graph

Entries about BaFin TeamViewer MAR Article 17 disclosure fine (1)

2026-07-26 · view entry permalink →

NOTABLENATOA1

BaFin fined TeamViewer EUR 240,000 for how it disclosed its 2024 nation-state breach — a website notice did not satisfy the ad-hoc-disclosure duty, setting a breach-disclosure-mechanics precedent for any SIX/EU-listed software or CI supplier

Germany's Federal Financial Supervisory Authority, BaFin, announced on 2026-07-20 that it had fined TeamViewer SE EUR 240,000 — "Die Finanzaufsicht Bafin hat am 16. Juli 2026 eine Geldbuße in Höhe von 240.000 Euro gegen die TeamViewer SE festgesetzt" — for violating the EU Market Abuse Regulation (MAR) (BaFin, 2026-07-20). The underlying event is TeamViewer's confirmed mid-2024 compromise of its internal IT environment, attributed at the time to the Russia-nexus actor APT29/Cozy Bear — but that breach is not the point of this item. The fresh, in-window fact is the enforcement action and the disclosure-mechanics precedent it sets.

BaFin's finding is narrow and specific: the violation was of MAR Article 17(1), the duty to publish inside information immediately, and the deficiency was in the channel, not the speed. TeamViewer posted a notice on its own website, but as heise summarised the rule, "Ad-hoc-Meldungen müssen über ein elektronisches Informationssystem an Medien und an die Bafin verteilt sowie auf der Unternehmenswebseite veröffentlicht werden" (heise online, 2026-07-21) — an ad-hoc disclosure must be distributed simultaneously through a regulated electronic information system to media and to BaFin itself, so a website post alone does not discharge the obligation. TeamViewer retains appeal rights, so the precedent is not yet final, but the principle BaFin has asserted is clear: a nation-state compromise of a widely-deployed software vendor is market-moving inside information that requires formal, immediate, multi-channel disclosure.

Die Finanzaufsicht Bafin hat am 16. Juli 2026 eine Geldbuße in Höhe von 240.000 Euro gegen die TeamViewer SE festgesetzt.

BaFin

Ad-hoc-Meldungen müssen über ein elektronisches Informationssystem an Medien und an die Bafin verteilt sowie auf der Unternehmenswebseite veröffentlicht werden.

heise online 2026-07-21
policy26 Jul 23:49Zmulti-sourceOpen finding ↗