Key dates
- 16 July 2026
- - BaFin imposes a €240,000 administrative fine on TeamViewer SE for violating Article 17(1) MAR by failing to disclose a cyberattack without delay
- 20 July 2026
- - BaFin publishes the enforcement notice detailing the breach, the nature of the inside information (cyberattack), and the applicable fine range under MAR
Suggested considerations
- Conduct an immediate review of incident classification frameworks to ensure that significant cyberattacks are systematically assessed for MAR “inside information” criteria, including likely price impact.
- Update ad hoc disclosure policies and procedures to explicitly cover cyber incidents, including clear triggers, escalation paths, and decision-making timelines for potential MAR disclosures.
- Implement or enhance cross-functional incident response governance so that Security / IT, Legal, Compliance and Investor Relations jointly evaluate cyber events for ad hoc disclosure obligations.
- Review and, where necessary, revise Board and senior management training to cover MAR Article 17 obligations in the context of cyber incidents and operational disruptions.
- Test existing “ad hoc announcement” workflows (including drafting, approval and publication mechanisms) to confirm the firm can publish inside information on cyberattacks “as soon as possible” in practice, including outside normal business hours.
What changed
- - BaFin has explicitly treated a material cyberattack on a listed software company as *inside information* that must be disclosed without delay under Article 17(1) MAR.
- The decision confirms that failure to publish inside information “as soon as possible” constitutes a contravention of subparagraph 1 of Article 17(1) MAR and is subject to administrative fines.
- BaFin reiterates that issuers based in Germany with securities traded on an organised market in Germany are subject to an ad hoc disclosure obligation for inside information.
- BaFin highlights that inside information includes precise, non-public information directly or indirectly relating to an issuer or its instruments, which would likely have a significant price effect...
- The enforcement action illustrates BaFin’s willingness to use its full MAR toolkit on disclosure failures, with potential maximum fines of €2.5 million or up to 2% of total revenue for similar...
Compliance impact
The compliance impact is high: BaFin has clearly signalled that failures to promptly disclose price-sensitive cyber incidents will trigger enforcement and potentially substantial fines relative to issuer revenue. Beyond financial penalties, late or missing disclosures can increase litigation risk and damage market confidence in the issuer’s governance and transparency.