Germany’s Federal Financial Supervisory Authority (BaFin) has accused TeamViewer of failing to promptly inform the public about a cyberattack. The software company has now been ordered to pay a financial penalty.
On July 16, 2026, BaFin imposed a fine of 240,000 Euro on TeamViewer SE, stating that the company had violated the European Market Abuse Regulation (MAR).
Ad Hoc Disclosure Filed Too Late
According to BaFin, TeamViewer should have immediately disclosed the cyberattack affecting its own corporate environment. The regulator considers such an incident to be insider information because it has the potential to significantly influence a company’s share price. BaFin noted that this is especially relevant for a software company like TeamViewer, where cybersecurity incidents can quickly become material to investors.
Under the Market Abuse Regulation (MAR), publicly traded companies are required to disclose such information without undue delay. Failing to do so constitutes a violation of Article 17(1) of the regulation. BaFin is authorized to impose penalties of up to 2.5 million Euro or 2% of a company’s annual revenue for such violations. The 240,000 Euro fine imposed on TeamViewer was well below the maximum allowed.
The 2024 Cyberattack
The incident dates back two years. In late June 2024, TeamViewer announced that its security team had detected an irregularity within the company’s internal IT environment. The company immediately activated its incident response team and launched an investigation.
At the time, TeamViewer emphasized that its internal IT environment was isolated from its production environment. The company stated:
“There is no evidence to suggest that our product environment or customer data has been affected.”
TeamViewer
Reports later indicated that the attack was linked to an Advanced Persistent Threat (APT) group. APT groups are typically state-sponsored cyber actors known for conducting sophisticated and long-term intrusion campaigns. The group allegedly involved was Cozy Bear, which is widely associated with Russia’s Foreign Intelligence Service (SVR).
TeamViewer’s remote access software is widely used by businesses to connect to corporate systems for technical support and remote administration. If compromised, such access could potentially be exploited to obtain sensitive corporate data, making the attack particularly significant.
Why Timely Disclosure Matters
The requirement to rapidly disclose market-relevant information serves two key purposes. First, it helps prevent individuals with insider knowledge from gaining an unfair advantage in securities trading. Second, it ensures that investors are not misled by missing or delayed information, allowing markets to operate fairly and transparently.
(lb)