
When a Cyberattack Becomes Inside Information: What BaFin's €240,000 TeamViewer Fine Means for EU Issuers
TeamViewer SE went public about its cyberattack the day after detecting it. BaFin fined the company €240,000 anyway.
On 16 July 2026, Germany's Federal Financial Supervisory Authority (BaFin) imposed an administrative fine of €240,000 on TeamViewer SE, publishing the measure on 20 July 2026. The legal basis was Article 17(1) of the Market Abuse Regulation, the ad hoc disclosure obligation. In BaFin's words, the fact that TeamViewer SE had fallen victim to a cyberattack should have been disclosed by the company without delay as inside information.
The amount of the fine is not the most interesting part of the case. The reasoning is, because TeamViewer was not a company that stayed quiet.
1. What TeamViewer did, and when
TeamViewer detected an irregularity in its internal corporate IT environment on 26 June 2024.
A first public statement went out on the evening of 27 June 2024. In an update on 28 June, the company said it was attributing the activity to APT29, also tracked as Midnight Blizzard. A further update on 30 June said that a compromised employee account had been used to copy employee directory information including names, corporate contact details and encrypted employee passwords. On 4 July 2024 TeamViewer said the main incident response and investigation phase had concluded, and that its separated product environment, its connectivity platform and customer data had not been affected.
Those conclusions about the extent of the compromise are TeamViewer's own account of its investigation rather than findings independently established by a supervisor. What is not in dispute is the pace: the company communicated quickly and issued several detailed updates.
BaFin nonetheless found a breach of Article 17(1) MAR.
What this means in practice: The finding is not that TeamViewer said nothing. It is that a specific legal obligation was not discharged in the manner and within the timeframe Article 17 requires. Communicating and disclosing are related activities, but they are not the same legal act.
2. Communicating is not the same as disclosing
This is the distinction an incident response plan can easily blur.
A notice on a trust centre page is public, but publicity alone is not the legal test. The question under Article 17 is whether the inside information has been disseminated in accordance with the regulation and with Commission Implementing Regulation (EU) 2016/1055, which sets out the technical means for appropriate public disclosure.
Broadly, that means the information must reach the market on a wide, non-discriminatory and simultaneous basis across the European Union, through media that can reasonably be relied upon for effective distribution, and the communication must be clearly identified as inside information, with the issuer named and the release properly dated and timed. It then has to be posted and maintained on the issuer's website.
None of that turns on the label. A document called a press release can perfectly well form part of a compliant Article 17 disclosure, provided it is distributed and identified in the way the regulation requires. A website-only notice, however detailed, generally will not be sufficient on its own.
Article 17 also carries its own documentation burden where disclosure is delayed, which is dealt with below.
3. When does a cyber incident meet the Article 7 test?
It is worth being precise here, because the headline version of this case tends to become "a cyberattack is inside information". That is not what MAR says, and it is not what BaFin decided.
Article 7 still requires a case-by-case assessment. Information is inside information where it is precise, not public, relates directly or indirectly to the issuer, and would be likely, if made public, to have a significant effect on the price of the relevant instruments. A cyberattack can satisfy those criteria. Whether a particular attack does is a question of fact.
What this decision does show is that an EU competent authority was prepared to treat a cyberattack as price-sensitive inside information on the facts before it.
One temptation during an incident is to wait until its scope is fully understood. That instinct sits awkwardly with the Article 7 threshold, which does not require certainty. Information can be precise even where the eventual outcome is unknown, provided it is specific enough to support a conclusion about the possible effect on price. Uncertainty itself can be relevant to an investor's assessment.
What this means in practice: The first-day question is not "how bad is it?" It is whether the Article 7 criteria are met on the facts currently known. If they are, the Article 17 timing analysis has already started.
4. Who Article 17 actually binds
Article 17 is not a general obligation on regulated financial institutions. Being authorised and supervised is not itself the trigger.
The obligation attaches to issuers: those that have requested or approved admission of their financial instruments to trading on a regulated market and, in the circumstances MAR specifies, issuers whose instruments are traded on an MTF or an OTF. A bank, investment firm or fund manager carries the Article 17 disclosure obligation where it separately falls within that issuer scope, and not merely because it holds a licence.
That distinction matters for scoping the work. The incident response question for a listed issuer is different from the incident response question for an unlisted regulated firm, even where both are running the same forensic playbook.
5. Directly applicable, but not identical everywhere
MAR is a regulation rather than a directive, so Article 17 applies as EU law in every Member State without national transposition. The article a Frankfurt issuer reads is the article a Dublin, Paris, Amsterdam, Milan, Madrid, Athens or Nicosia issuer reads.
It does not follow that national law is irrelevant. Competent authority practice, procedural options and the sanctioning framework still vary. Article 17(4) is a concrete example: Member States may provide that the written explanation supporting a delayed disclosure is submitted only where the competent authority requests it, rather than automatically alongside the notification. Enforcement practice and procedure can differ too, which is part of why a German decision is useful reading elsewhere without being binding elsewhere.
The penalty framework is also worth stating precisely. For infringements of Article 17 by legal persons, Article 30 requires Member States to make available maximum administrative pecuniary sanctions of at least 2% of total annual turnover according to the last available accounts approved by the management body. Where a competent authority considers a turnover-based amount disproportionately low in light of the circumstances specified in Article 31, Member States must also ensure that the authority can impose administrative sanctions of at least €2.5 million. Separate treatment may be provided for SMEs. The amended regime is therefore no longer accurately summarised by the old shorthand of "€2.5 million or 2% of turnover, whichever is higher".
6. What changed on 5 June 2026
Anyone building an Article 17 process now should be working from the amended text, not the 2014 original. The Listing Act, Regulation (EU) 2024/2809, made changes to MAR that apply from 5 June 2026.
Two are directly relevant.
Intermediate steps. Revised Article 17(1) provides that the obligation to disclose as soon as possible does not apply to inside information concerning intermediate steps in a protracted process connected with bringing about a particular circumstance or event. In such a process, only the final circumstance or event has to be disclosed, though the issuer must keep the intermediate information confidential in the meantime. This is aimed at situations such as ongoing negotiations and stages of progress. A single externally caused cyberattack does not obviously fit that model. Regulation 2026/789, described below, does not identify cyber incidents among its examples, so whether a particular incident or investigation constitutes a protracted process would need to be assessed on its own facts.
Delayed disclosure. The Article 17(4) conditions now require that immediate disclosure is likely to prejudice the issuer's legitimate interests, that the information whose disclosure is delayed is not in contrast with the issuer's latest public announcement or other communication on the same matter, and that confidentiality can be ensured. The second limb replaced the older "not likely to mislead the public" formulation, and it is more objective: it measures the withheld information against what the issuer has actually said.
The amended MAR is now supplemented by Commission Delegated Regulation (EU) 2026/789, published on 16 July 2026. It provides non-exhaustive lists of final events and circumstances in protracted processes and of situations in which information intended to be delayed would contrast with an issuer's previous public communications. It also specifies the types of communications that have to be considered for that purpose, including press releases, website and social media communications, public interviews, roadshows, webinars, podcasts and regulatory filings.
That is particularly relevant in a cyber incident. What an issuer has already said through its trust centre, newsroom or other public channels may form part of the Article 17(4) analysis even though publication through those channels does not, by itself, satisfy the Article 17 dissemination requirement.
Whichever version applied to the conduct in question, the practical discipline is the same. A delay has to be a decision taken and recorded at the time, against the conditions in the regulation. A justification reconstructed afterwards is a weak position in front of a supervisor.
7. Which regulatory clocks actually apply?
A cyber incident is sometimes described as starting three parallel clocks under DORA, NIS2 and MAR. That is not the right analysis for a financial entity that falls within both DORA and the relevant NIS2 scope.
Article 1(2) of DORA provides that, for financial entities that are also essential or important entities under NIS2, DORA is a sector-specific Union legal act for the purposes of Article 4 of NIS2. The consequence is that DORA's ICT risk management, ICT incident management and major ICT-related incident reporting requirements apply instead of the corresponding NIS2 requirements, rather than on top of them.
A more accurate framing is this. A cyber incident may engage several regimes, but which ones depends on the entity and on the incident:
DORA governs ICT incident management and major incident reporting for financial entities in scope, through its structured sequence of initial, intermediate and final reports to the competent authority.
NIS2 applies to essential and important entities in its own scope, with an early warning within 24 hours, an incident notification within 72 hours and, subject to the Directive's detailed rules, a final report no later than one month after submission of that incident notification. Those deadlines are correct for NIS2 itself, but they should not be presented as running cumulatively alongside DORA for the same DORA-covered financial entity.
MAR can run alongside DORA where the entity is also an issuer within Article 17 and the incident constitutes inside information. It answers to the market rather than to a supervisor, and satisfying a supervisory reporting obligation does nothing to discharge it.
The GDPR may add a notification obligation where a qualifying personal data breach is involved.
The sequencing problem underneath all of this is organisational rather than legal. An incident response structure that routes the market disclosure assessment only after the technical and legal workstreams are already under way risks bringing Article 17 into the process too late. The person able to make the Article 7 call needs to be reachable in the first hours, not consulted once the forensic picture is settled.
8. Insider lists
One related obligation is frequently overstated. Article 18 does not sweep in every member of an incident response team by virtue of their involvement.
It applies to persons who actually have access to the inside information and who work for the issuer or otherwise perform tasks through which they receive it. Incident response personnel, external forensic providers and outside counsel may need to be included where they have access to the relevant inside information. The trigger is that access, not membership of a category.
The practical point survives the correction: between the moment an issuer knows and the moment the market knows, a defined group holds information the market does not, and that group needs to be identified rather than assumed.
9. What to change before the next incident
Five adjustments, none of which requires new systems.
Name a person, not a department. A specific individual, with a named deputy, responsible for the inside information assessment, and reachable out of hours.
Move the assessment forward. Run the Article 7 test in the first hours, in parallel with containment, rather than after the forensic picture is complete.
Pre-draft the disclosure. A skeleton release that can be completed and issued within the hour, through a distribution route that satisfies Implementing Regulation 2016/1055, is worth more than a polished one drafted under pressure.
Document any delay contemporaneously. Record the reasoning against each Article 17(4) condition, with the time and the decision-maker, at the moment the decision is taken.
Rehearse the disclosure decision. Include the Article 7 assessment explicitly in cyber exercises. A tabletop that tests containment and communications but never requires anyone to decide whether the known facts constitute inside information leaves an important part of the response process untested.
The test: If you cannot name the individual who makes the Article 17 call, and the hour by which they would make it, that is the gap this case points at.
10. Sources
| Enforcement measure | BaFin, TeamViewer SE: BaFin imposes administrative fine, 20 July 2026 |
| Incident chronology | TeamViewer security bulletin TV-2024-1005, June to July 2024 |
| Core obligation | Regulation (EU) No 596/2014 (MAR) as consolidated from 5 June 2026, Articles 7, 17, 18 and 30 |
| Amending act | Regulation (EU) 2024/2809 (Listing Act) |
| Protracted processes and delay | Commission Delegated Regulation (EU) 2026/789 of 8 April 2026, published 16 July 2026, including Annexes I, II and III |
| Dissemination rules | Commission Implementing Regulation (EU) 2016/1055 |
| ICT incident regime | Regulation (EU) 2022/2554 (DORA),in particular Article 1(2) |
| Cyber regime | Directive (EU) 2022/2555 (NIS2),including its interaction with sector-specific Union acts |
Know what is coming before it arrives. Our Market Abuse seminar works through real enforcement decisions, the Article 17 disclosure test, and how supervisors across the EU are applying it in practice, with CPD hours recognised for CySEC-licensed professionals.
Explore seminars at cpds.academy
This article is provided for general information and professional education purposes only. It reflects publicly available information as at the date of publication and does not constitute legal or compliance advice. Firms should assess their own obligations with reference to their regulatory permissions and, where appropriate, take independent advice.

Article by Nikolas Demetriades
Published 24 Aug 2026