Marius (windsheep)
@windsheep@infosec.exchange
Personal account. A helpful person in Information Security & Digital Forensics. A trader who minds market fundamentals. AI / ML dev. SDR nerd. Humor. Short retention.
infosec.exchange
TMV aka TeamViewer was breached. In Germany, not only do you need to disclose to Data Privacy Adminstrations (DPAs). Either federal or locally, depending on size and proportion. You also must inform the BaFin, the SEC equivalent.
The BaFin is aware of cyber incidents and will apply rigorous assessments under MAR if you fail. TeamViewer is not a bank, but gets held to a similar standard (here).
As a takeaway: even larger German companies remain unaware of their duties to report cyberattacks. Not because they lack resources. They don't assess the incidents to the end. Many legal professionals I know are surprised by this:
https://www.bafin.de/SharedDocs/Veroeffentlichungen/EN/Massnahmen/40c_neu_124_WpHG/meldung_2026_07_20_team_viewer_en.html
TeamViewer SE: Bafin imposes administrative fine
On 16 July 2026, the Federal Financial Supervisory Authority (Bafin) imposed an administrative fine amounting to €240,000 on TeamViewer SE on the grounds that the company had violated the Market Abuse Regulation (MAR). The fact that TeamViewer SE had fallen victim to a cyberattack should have been disclosed by the company without delay as inside information.
#bafin #teamviewer #tmv #fine #breach