Cybercrime

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies

If you are currently affected by a ransomware attack, we are available to you at any time by phone available. We take over the coordination of an incident response team and guide you through all aspects of damage management.

240,000 euros fine – that is how much TeamViewer SE has to pay to the German financial supervisory authority BaFin. Not because of the cyberattack itself, but because the company failed to publish it in a timely manner as an ad-hoc announcement. BaFin imposed the fine on July 16, 2026, and published the measure on July 20, 2026. The case is a prime example of what many companies think too little about: a cyberattack is not just an IT security problem. It regularly triggers multiple, parallel reporting obligations – under capital market law, data protection law, and in the future also under the new Austrian cybersecurity law. Anyone who does not know these obligations or reacts too late risks severe sanctions and a substantial loss of trust.

This article provides a legal classification of the TeamViewer case, explains the reporting obligations that exist in the event of cyber attacks in Austria, and outlines the steps affected companies should take now.

Cyberattack reporting obligations NIS GDPR MAR

Table of Contents

The case: Why BaFin took action against TeamViewer

The trigger was a cyberattack on TeamViewer's internal IT infrastructure in June 2024. The company suspected the alleged Russian group APT29, also known as „Midnight Blizzard,“ to be behind the attack. According to TeamViewer's own statements, only the internal IT system was affected—names, contact details, and employee passwords were compromised. The product environment, communication platform, and customer data were reportedly not affected.

TeamViewer initially informed only via its own website and the so-called „Trust Center“ – not via a formal ad-hoc announcement. The company justified this by stating that it had carefully examined whether there was any ad-hoc-relevant information, and that the chosen communication via the Trust Center corresponded to the customs of the technology industry. Following the disclosure, the share price temporarily lost around 10 percent in value.

BaFin saw this differently. In its assessment, the cyberattack—precisely because TeamViewer is a software company—was price-sensitive inside information within the meaning of the Market Abuse Regulation (MAR). This should have been disclosed immediately. The fine decision is based on Article 17(1), subparagraph 1 of the MAR, with the statutory fine ranging up to 2.5 million euros or up to 2 percent of total turnover. TeamViewer can still appeal the fine.

Why this case is relevant beyond TeamViewer

The case is not an isolated German event. It demonstrates a regulatory approach that is also of direct relevance to Austrian companies: a cyberattack can constitute insider information subject to mandatory disclosure, even if it is initially unclear whether customer or product data is affected. The decisive factor is not the technical severity of the attack, but its potential price relevance—in other words, whether the information, if made public, would be capable of significantly influencing the price of a financial instrument.

For corporate management, this means: The decision on an ad-hoc disclosure cannot wait until a forensic investigation of an incident is fully complete. It must be continuously reassessed based on the current level of knowledge—and it must be evaluated from a legal perspective, not a communication strategy one.

The MAR also applies directly in Austria

The Market Abuse Regulation is an EU regulation and therefore applies directly to Austrian issuers as well – without a national implementing act. The competent supervisory authority in Austria is the Financial Market Authority (FMA), not BaFin. BaFin is exclusively responsible for issuers based in Germany or primarily listed there. A publicly traded Austrian company affected by a comparable cyber attack would be subject to the same substantive obligations under Art. 17 MAR – just with the FMA as the competent authority and under Austrian administrative criminal law as the sanctioning framework.

Specifically, this means that the legal logic of the TeamViewer case is directly applicable to Austrian issuers, even though the specific fine decision concerns a German authority.

Cyberattacks rarely trigger just a single reporting obligation

The second key point: A cyberattack is practically never relevant solely under capital markets law. In most cases, multiple reporting obligations apply simultaneously, with different deadlines, recipients, and prerequisites. This significantly increases the complexity for company management—and this is precisely where the biggest mistakes happen in practice.

GDPR – Notification obligation in the event of a personal data breach If personal data is affected—as in the TeamViewer case involving employee contact details and passwords—Article 33 of the GDPR also applies. The controller must generally notify the competent data protection authority of the breach within 72 hours of becoming aware of it, provided there is a risk to the rights and freedoms of the data subjects. In Austria, the Austrian Data Protection Authority is responsible for this. If there is a high risk, there is also an obligation to notify the data subjects themselves (Article 34 GDPR).

NIS2 / NISG 2026 – the new reporting obligation for cybersecurity incidents in Austria Austria has implemented the EU's NIS2 Directive with the Network and Information Systems Security Act 2026 (NISG 2026). The law was passed by the National Council in December 2025 and will fully enter into force on October 1, 2026. It affects medium and large enterprises in specific sectors – roughly starting from 50 employees or more than 10 million euros in annual turnover or balance sheet total. The competent authority is the newly created Federal Office for Cybersecurity, subordinate to the Federal Ministry of the Interior; CERT.at acts as the operational reporting office (CSIRT).

From the date of entry into force, a three-stage reporting procedure applies to significant cybersecurity incidents: an early warning within 24 hours, a more detailed report within 72 hours, and a final report no later than one month after the early warning. Affected entities must also register by December 31, 2026, at the latest.

For companies already affected by a cyber incident, this means: The NIS2 reporting obligation is largely a matter of the near future—whereas the obligations under capital market and data protection law already apply without restriction today.

Reporting obligations compared: MAR, GDPR and NIS2/NISG 2026

  MAR (Market Abuse Regulation) GDPR (Art. 33/34) NIS2 / NISG 2026
Who is affected Issuers of financial instruments on a regulated market Each controller who processes personal data Medium and large enterprises in NIS sectors (from 50 employees or > €10 million annual turnover/balance sheet total)
What needs to be reported Inside information – price-sensitive, non-public, precise information Personal data breach Significant cybersecurity incident pursuant to the NIS Act 2026
First Without undue delay Within 72 hours of becoming known Early warning within 24h, notification within 72h, final report within 1 month
Competent authority in Austria FMA Austrian Data Protection Authority Federal Office for Cybersecurity / CERT.at
sanctions framework Up to €2.5 million or up to 2 % of total revenue Up to €20 million or 4 % of global annual revenue Administrative fines under NISG 2026, including up to €50,000 or €100,000 for violation of the registration obligation; further penalties for breach of reporting and risk management obligations

Note: The information regarding NISG 2026 refers to a law that will only fully enter into force on October 1, 2026. Details may be specified by pending regulations.

Common mistakes in practice

From the legal support of cyber incidents, recurring sources of error can be identified:

  • Communication via the website instead of formal notification. Information on one's own homepage does not replace a legally required ad-hoc announcement, a GDPR notification, and a NIS2 notification. Exactly this mistake was at the center of the TeamViewer case.
  • Wait until complete forensic clarification. The reporting obligation is regularly tied to becoming aware of an incident—not to its complete clarification. Anyone who delays the report until the forensic investigation is concluded risks a breach of the deadline.
  • Separate consideration of reporting obligations. MAR, GDPR and in future NIS2 run in parallel and with different deadlines. An isolated review of only one legal area regularly overlooks further obligations.
  • Lack of documentation of the decision-making process. Whether and when information was classified as inside information or as a reportable incident should be documented comprehensively – also to provide a traceable record for a subsequent regulatory review.

What affected companies should do now

In an emergency, every hour counts. A structured approach makes sense:

  1. Immediate assessment of whether inside information pursuant to MAR could exist – regardless of the status of the technical clarification.
  2. Parallel check on whether personal data is affected and a GDPR notification within 72 hours becomes necessary.
  3. For companies within the scope of the NISG 2026: timely preparation of internal reporting processes for the procedure applicable from October 1, 2026.
  4. Complete documentation of all decisions, timestamps, and verification steps.
  5. Early involvement of legal advisors specializing in cybercrime and capital markets law to coordinate deadlines, reporting content, and external communication.

Conclusion: Legal certainty in an emergency requires preparation

The TeamViewer case shows that regulatory authorities are increasingly and consistently measuring cyber incidents against capital markets disclosure obligations. For Austrian companies, this means: the MAR is already directly applicable today, the GDPR reporting obligation is established practice, and with the NISG 2026, a third, independent reporting level will be added starting in October 2026. Anyone who is not prepared in an emergency loses valuable time – precisely the time that is crucial for a timely and legally secure report.

ATB.LAW supports companies in Austria with the legal assessment and management of cyber incidents – from the initial risk assessment and coordination with the data protection authority, FMA, and CSIRT, to communication with customers and investors. In the event of an acute ransomware or cyber incident, ATB.LAW can be reached around the clock. Contact us early on – especially in the first hours after an incident, the course is set for the subsequent legal assessment.

Affected individuals can contact ATB.LAW 24/7 – We are at your disposal at any time by phone available.

FAQ:

Does every cyber attack have to be reported?

No, not every cyberattack is automatically reportable. The deciding factor in each case is whether the legal requirements of the respective regulation are met—such as whether there is inside information relevant to the share price within the meaning of the MAR, whether personal data is affected (GDPR), or whether there is a significant cybersecurity incident within the meaning of the NISG 2026. In practice, however, severe incidents are frequently relevant from several of these perspectives simultaneously.


What is the deadline for reporting a cyber attack?

That depends on the respective legal basis. According to the MAR, inside information must be disclosed immediately, without undue delay. Under the GDPR, there is generally a 72-hour deadline from becoming aware of a data breach. According to the NISG 2026, a three-tier procedure applies from October 1, 2026, with an initial early warning within 24 hours.


What happens if a cyberattack is not reported in time?

Regulatory sanctions are threatened, the amount of which varies greatly depending on the legal basis – from high five- to six-figure fines under the Market Abuse Regulation (MAR) to fines of up to 20 million euros or 4 percent of annual global turnover under the GDPR. In addition, there is typically reputational damage and a loss of trust among investors, customers, and regulatory authorities.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
cPanel/WHM leads to ransomware attacks on websites - ATB.LAW supports victims

cPanel ransomware attack

Critical vulnerability CVE-2026-41940 puts websites at risk
Picture of Roman Taudes
Roman Taudes