Live Updates

TeamViewer SE: Bafin imposes administrative fine

AI Analysis

Executive Summary

BaFin has imposed a €240,000 administrative fine on TeamViewer SE for failing to disclose a significant cyberattack as inside information without delay under Article 17(1) MAR. The case materially raises the bar for ad hoc disclosure of cyber incidents for German-listed issuers, confirming that major cyberattacks on technology-driven businesses are presumptively inside information requiring rapid public disclosure.

What Changed

  • - BaFin has explicitly treated a material cyberattack on a listed software company as *inside information* that must be disclosed without delay under Article 17(1) MAR.
  • The decision confirms that failure to publish inside information “as soon as possible” constitutes a contravention of subparagraph 1 of Article 17(1) MAR and is subject to administrative fines.
  • BaFin reiterates that issuers based in Germany with securities traded on an organised market in Germany are subject to an ad hoc disclosure obligation for inside information.
  • BaFin highlights that inside information includes precise, non-public information directly or indirectly relating to an issuer or its instruments, which would likely have a significant price effect if made public – explicitly including serious cyber
  • The enforcement action illustrates BaFin’s willingness to use its full MAR toolkit on disclosure failures, with potential maximum fines of €2.5 million or up to 2% of total revenue for similar breaches.
  • Cybersecurity events are now clearly positioned within BaFin’s market abuse supervisory focus, reinforcing the intersection between Technology & Cyber and Market Abuse / Disclosure obligations.

Suggested Considerations

  • Conduct an immediate review of incident classification frameworks to ensure that significant cyberattacks are systematically assessed for MAR “inside information” criteria, including likely price impact.
  • Update ad hoc disclosure policies and procedures to explicitly cover cyber incidents, including clear triggers, escalation paths, and decision-making timelines for potential MAR disclosures.
  • Implement or enhance cross-functional incident response governance so that Security / IT, Legal, Compliance and Investor Relations jointly evaluate cyber events for ad hoc disclosure obligations.
  • Review and, where necessary, revise Board and senior management training to cover MAR Article 17 obligations in the context of cyber incidents and operational disruptions.
  • Test existing “ad hoc announcement” workflows (including drafting, approval and publication mechanisms) to confirm the firm can publish inside information on cyberattacks “as soon as possible” in practice, including outside normal business hours.
  • Strengthen documentation practices so that all MAR-related disclosure decisions on cyber incidents (including rationale for disclosure or delay) are recorded and auditable for supervisory review.

Key Dates

16 July 2026
- BaFin imposes a €240,000 administrative fine on TeamViewer SE for violating Article 17(1) MAR by failing to disclose a cyberattack without delay
20 July 2026
- BaFin publishes the enforcement notice detailing the breach, the nature of the inside information (cyberattack), and the applicable fine range under MAR

Compliance Impact

The compliance impact is high: BaFin has clearly signalled that failures to promptly disclose price-sensitive cyber incidents will trigger enforcement and potentially substantial fines relative to issuer revenue. Beyond financial penalties, late or missing disclosures can increase litigation risk and damage market confidence in the issuer’s governance and transparency.

Who is Affected

German-incorporated issuers whose shares, debt securities, or other financial instruments are admitted to trading on an organised market in Germany (e.g. on regulated markets such as Frankfurt).EU/EEA issuers with a German listing where Germany is the home Member State for MAR purposes and BaFin is the competent authority.Listed technology, software, IT services and other digital infrastructure firms whose business models make cyber incidents more likely to be price-sensitive.Boards, senior management and compliance / legal functions responsible for MAR ad hoc disclosures and incident response.Investor relations and communications teams involved in drafting and publishing ad hoc announcements.

AI-generated analysis. May contain errors or omissions — verify with the original BaFin source before acting. Full disclaimer.

Summary

On 16 July 2026, the Federal Financial Supervisory Authority (Bafin) imposed an administrative fine amounting to €240,000 on TeamViewer SE on the grounds that the company had violated the Market Abuse Regulation (MAR). The fact that TeamViewer SE had fallen victim to a cyberattack should have been disclosed by the company without delay as inside information.

View Original on BaFin Back to Feed

Share this update