TeamViewer SE: Bafin imposes administrative fine
Executive Summary
BaFin has imposed a €240,000 administrative fine on TeamViewer SE for failing to disclose a significant cyberattack as inside information without delay under Article 17(1) MAR. The case materially raises the bar for ad hoc disclosure of cyber incidents for German-listed issuers, confirming that major cyberattacks on technology-driven businesses are presumptively inside information requiring rapid public disclosure.
What Changed
- - BaFin has explicitly treated a material cyberattack on a listed software company as *inside information* that must be disclosed without delay under Article 17(1) MAR.
- The decision confirms that failure to publish inside information “as soon as possible” constitutes a contravention of subparagraph 1 of Article 17(1) MAR and is subject to administrative fines.
- BaFin reiterates that issuers based in Germany with securities traded on an organised market in Germany are subject to an ad hoc disclosure obligation for inside information.
- BaFin highlights that inside information includes precise, non-public information directly or indirectly relating to an issuer or its instruments, which would likely have a significant price effect if made public – explicitly including serious cyber
- The enforcement action illustrates BaFin’s willingness to use its full MAR toolkit on disclosure failures, with potential maximum fines of €2.5 million or up to 2% of total revenue for similar breaches.
- Cybersecurity events are now clearly positioned within BaFin’s market abuse supervisory focus, reinforcing the intersection between Technology & Cyber and Market Abuse / Disclosure obligations.
Suggested Considerations
- Conduct an immediate review of incident classification frameworks to ensure that significant cyberattacks are systematically assessed for MAR “inside information” criteria, including likely price impact.
- Update ad hoc disclosure policies and procedures to explicitly cover cyber incidents, including clear triggers, escalation paths, and decision-making timelines for potential MAR disclosures.
- Implement or enhance cross-functional incident response governance so that Security / IT, Legal, Compliance and Investor Relations jointly evaluate cyber events for ad hoc disclosure obligations.
- Review and, where necessary, revise Board and senior management training to cover MAR Article 17 obligations in the context of cyber incidents and operational disruptions.
- Test existing “ad hoc announcement” workflows (including drafting, approval and publication mechanisms) to confirm the firm can publish inside information on cyberattacks “as soon as possible” in practice, including outside normal business hours.
- Strengthen documentation practices so that all MAR-related disclosure decisions on cyber incidents (including rationale for disclosure or delay) are recorded and auditable for supervisory review.
Key Dates
Compliance Impact
The compliance impact is high: BaFin has clearly signalled that failures to promptly disclose price-sensitive cyber incidents will trigger enforcement and potentially substantial fines relative to issuer revenue. Beyond financial penalties, late or missing disclosures can increase litigation risk and damage market confidence in the issuer’s governance and transparency.
Who is Affected
References
AI-generated analysis. May contain errors or omissions — verify with the original BaFin source before acting. Full disclaimer.
Summary
On 16 July 2026, the Federal Financial Supervisory Authority (Bafin) imposed an administrative fine amounting to €240,000 on TeamViewer SE on the grounds that the company had violated the Market Abuse Regulation (MAR). The fact that TeamViewer SE had fallen victim to a cyberattack should have been disclosed by the company without delay as inside information.