News

Cybersecurity

TeamSystem Data Breach: The Stolen Details That Can Make Fraud Look Legitimate

Hacker accessing personal data, IBANs and accounting records beside a phishing warning
Stolen financial and accounting data can be used to create highly convincing phishing and payment-redirection scams.

An attack on Contabilità in Cloud exposed personal information, IBANs and, according to TeamSystem’s notification, accounting records. Passwords reportedly survived. The information needed to construct convincing payment fraud may not have.

Cybersecurity — 4 September 2026

When an IBAN is stolen, the first reassurance normally offered is that an IBAN is not a banking password. That is correct, but it risks missing the real significance of the TeamSystem data breach. The problem is not simply that criminals may now possess bank-account coordinates. According to the notification sent by TeamSystem to affected customers, the attackers may also have obtained the context surrounding those accounts: names, contact details, transaction descriptions, amounts and counterparties. That combination could allow criminals to produce fraudulent emails, invoices and telephone calls containing enough genuine information to appear legitimate.

What happened to TeamSystem

TeamSystem says it detected what it described as a sophisticated security incident during the afternoon of 24 August 2026. The incident involved unauthorised access to systems associated with Contabilità in Cloud, its cloud accounting service, followed by the exfiltration of data stored in the software.

The company informed affected customers by email on 26 August, approximately two days after detecting the incident. The story subsequently became public through social-media posts and reporting by Sky TG24, Adnkronos, Fanpage, Corriere della Sera, La Repubblica and specialist cybersecurity publications.

The confirmed scope is important. Public reporting identifies Contabilità in Cloud as the affected service. It does not establish that every TeamSystem product, every company system or every TeamSystem customer was compromised.

TeamSystem says on its website that more than three million customers use its products. That number illustrates the company’s importance in the Italian business-software market, but it must not be confused with the number of customers affected by this breach, which has not been disclosed.

What information was taken

The customer notification, as reproduced publicly and reported by several outlets, identifies four principal categories of exposed information:

  • personal and identifying information;
  • contact details, including email addresses and telephone numbers;
  • banking coordinates, including IBANs;
  • accounting transactions recorded in the platform, potentially including descriptions, amounts and counterparties.

TeamSystem reportedly said that, based on the investigation available at the time of the notification, customers’ login credentials did not appear to have been compromised. That reduces the immediate risk of criminals entering accounts with stolen passwords, but it does not eliminate the risk created by information already removed from the platform. There is also a discrepancy worth highlighting.

Sky TG24 and Adnkronos, reporting comments from Italy’s National Cybersecurity Agency, listed personal details, contact information and IBANs as the affected categories. The TeamSystem customer notification reproduced elsewhere also included the contents of accounting transactions.

Those descriptions do not entirely match. Until TeamSystem publishes a comprehensive public technical update, customers should rely principally on the individual notification they received and on the data they actually stored in the service. Exposure may differ from one customer environment to another.

An IBAN alone is not the biggest problem

Knowing an IBAN does not normally allow someone to log into a bank account or authorise a payment. Customers should therefore not interpret the breach as meaning that criminals can automatically withdraw money from their accounts. The greater danger is informed impersonation.

Imagine that an attacker knows that Company A regularly pays Supplier B, understands the approximate value and timing of those payments and has the email address and telephone number of the person handling the account.

The attacker can then contact Company A while pretending to be Supplier B. The message might refer to a genuine commercial relationship, quote a realistic amount and announce that the supplier has changed bank account. The next legitimate payment is then redirected to an account controlled by the criminal.

No bank account needs to be technically hacked. The victim voluntarily authorises the transfer because the request appears consistent with information that only a trusted party should possess.

This is commonly described as invoice-redirection fraud, supplier impersonation, IBAN swapping or a form of business email compromise. The National Cybersecurity Agency specifically warned about phishing and financial fraud involving fraudulent changes to payment coordinates.

The transaction data potentially makes these attacks more convincing. A generic phishing email may contain obvious errors. A message that names a real supplier, refers to a genuine service and requests an amount resembling previous payments is much harder for an accounts department to dismiss immediately.

The unanswered questions

More than a week after the incident was detected, several fundamental details remain absent from the public record.

TeamSystem has not publicly disclosed:

  • how the attackers initially entered the environment;
  • whether they exploited a software vulnerability, compromised an account or entered through a third party;
  • when the unauthorised access actually began;
  • how long the intruders remained inside the environment;
  • the number of customers, records or individuals affected;
  • the total quantity of information exfiltrated;
  • whether the affected information was encrypted at rest;
  • whether every Contabilità in Cloud environment was exposed or only a limited subset;
  • who carried out the attack.

The date of 24 August represents the reported detection date. It should not automatically be interpreted as the date on which the intrusion began. Determining how long the attackers had access will be essential when assessing the true scale of the incident.

The reports reviewed for this article also do not identify a verified ransomware claim, named threat actor or public ransom demand. Until supporting evidence appears, attributing the incident to a particular criminal group would be speculation.

The public communication is not good enough

Sending a direct notification to affected customers within approximately two days of detection was necessary and useful. Direct communication is more important than a polished press release when organisations need immediate information about their own data. However, direct email should not be the end of the communication process.

As of 4 September, TeamSystem has not published a clearly visible incident page, public security advisory or press release explaining what happened, which products are affected, what customers should do, what has been contained and when further updates will be provided.

The breach became publicly documented because recipients and cybersecurity researchers shared the customer notification. Punto Informatico also reported that no official notice was available on TeamSystem’s corporate website.

There may be further information inside authenticated customer portals or in subsequent private correspondence. That does not replace a stable public source that customers, suppliers, accountants, banks and other potentially involved organisations can consult and verify.

The absence is particularly awkward because TeamSystem’s homepage currently tells prospective customers that they can rely on the “total security” of their data. No cloud provider can realistically guarantee total security. The credible promise is not that an incident can never occur, but that it will be detected, contained, explained and communicated transparently when it does.

What affected businesses should do now

Changing a TeamSystem password is a reasonable precaution, particularly when the same password has been used elsewhere, but password changes do not address the principal risk identified in this incident. TeamSystem says login credentials currently do not appear to have been taken. The most important protections concern payments and identity verification.

Businesses using Contabilità in Cloud should warn their finance teams, accountants and employees responsible for supplier payments that genuine commercial information may now be used in fraudulent requests.

Any request to change a supplier’s bank details should be verified through a previously known and independent channel. Staff should call a trusted telephone number already held in company records, not a number contained in the email requesting the change.

Changes to payment information and unusual transfers should require approval from at least two people. This is particularly important when a request is described as urgent, confidential or linked to the TeamSystem incident.

Unexpected emails, telephone calls or messages claiming to come from TeamSystem, a bank, an accountant or a supplier should be treated cautiously. A legitimate security process should not require customers to disclose passwords, one-time codes or payment authorisations, or to install remote-access software following an unsolicited contact.

Businesses should also monitor the bank accounts and IBANs entered in the platform. Suspicious payments or attempted fraud should be reported immediately to the relevant bank and authorities. The longer a fraudulent transfer remains undisputed, the more difficult recovery may become.

Independent telephone verification, separation of payment responsibilities and dual authorisation are more reliable controls than simply expecting every employee to recognise a professionally constructed phishing email.

Customers may have their own GDPR responsibilities

The notification reportedly refers to Article 33(2) of the GDPR. That provision applies when a data processor becomes aware of a personal-data breach and must inform the relevant data controller.

This distinction matters because TeamSystem may be processing information on behalf of businesses, accountants and professional firms that remain controllers of the personal data entered into the software.

According to the Italian Data Protection Authority, a controller must notify a breach to the authority without undue delay and, where possible, within 72 hours of becoming aware of it, unless the breach is unlikely to create a risk to people’s rights and freedoms. Where the risk is high, affected individuals may also need to be informed directly.

That does not mean every TeamSystem customer automatically has identical notification obligations. Each organisation needs to determine what information it stored, whose information was involved, what risks have arisen and whether its own regulator, customers, employees or suppliers must be notified.

The breach is not only TeamSystem’s problem

TeamSystem must explain how the intrusion occurred, establish the full affected population and provide continuing information to its customers. But the consequences will not remain contained inside TeamSystem’s systems.

The stolen records may describe relationships between businesses, customers, suppliers, accountants and banks. That means an organisation that has never purchased a TeamSystem product could still receive a convincing fraudulent message because its details appeared as a customer, supplier or counterparty in somebody else’s accounting records. This is why describing the incident simply as the theft of a collection of IBANs understates the danger.

An IBAN is a coordinate. An IBAN connected to a real identity, a genuine supplier, a plausible amount and an established payment relationship is a ready-made story. Criminals do not always need to break into a bank account when they possess enough accurate information to persuade somebody else to send them the money.

TeamSystem’s investigation will eventually need to explain the technical failure. In the meantime, customers should assume that the greatest immediate risk will arrive through apparently normal business communication, and may look far more credible than ordinary phishing.


Sources and further reading

Source: teamsystem.com
Hardware

Mirari PowerPC Board Moves Toward 100-Unit Production Run

Mirari PowerPC mainboard promotional image highlighting AmigaOS 4.x, MorphOS, PPC Linux, NVMe, USB 3 and PCIe support.
Mirari is preparing a new production run of 100 Proto2 PowerPC boards, designed for AmigaOS 4.x, MorphOS and PPC Linux.

The Mirari, a new community-driven PowerPC mainboard designed with AmigaOS 4.x and MorphOS in mind, is moving closer to wider availability. The board combines the PowerPC platform with more modern hardware features including NVMe storage, USB 3, PCIe and U-Boot 2024, while also supporting PPC Linux.

In its latest update, dated 17 August 2026, the Mirari team confirmed that preparations are underway for a new run of 100 Proto2 boards. Most of the CPUs have already been secured, with assembly planned locally in the Netherlands so the team can oversee testing and quality assurance. Boards will then be allocated according to the order in which people originally registered their interest.

Anyone interested in getting hold of a Mirari can register through the official interest form, while development updates, specifications and videos can be found on the main Mirari website.

Register your interest: Mirari Interest Form

Source: mirari.vitasys.nl
Retrogaming

THEC64 Handheld Now Available to Pre-Order

THEC64 Handheld beige clamshell gaming console with retro game on screen and pre-order details for £104.95, 25 built-in games and 15 October 2026 release.
THEC64 Handheld brings Commodore-inspired portable gaming to a clamshell system with 25 built-in games, launching on 15 October 2026.

THEC64 Handheld, a new portable system inspired by Commodore’s legendary 8-bit computer, is now available to pre-order from Amazon UK. At the time of writing, it is listed for £104.95, with its release scheduled for 15 October 2026 and Amazon’s Pre-order Price Guarantee included.

The clamshell handheld features a 4.3-inch 840×480 IPS display, traditional gaming controls, four remappable function buttons and 25 built-in C64 games. Highlights include A Pig QuestSam’s JourneySuper Boulder DashSpeedball 2: Brutal DeluxeParadroidGalencia and Steel Ranger. Additional games can be loaded through microSD, while a rear USB-A port supports an external keyboard or joystick.

An official announcement was issued by Blaze Entertainment and HyperMegaTech, with the product licensed by Retro Games Ltd. The official recommended price is £109.99, making Amazon’s current pre-order price slightly cheaper.

Disclosure: This article is not sponsored. I do not receive any commission, payment or other benefit from the links above or from any of the companies mentioned.

Source: hypermegatech.com
Retrocomputing

AmiGmail brings native Gmail access to AmigaOS 3.2+

Classic Amiga computer running AmiGmail, a native Gmail client for AmigaOS 3.2+ with Inbox, labels, attachments and IMAP/SMTP support.
AmiGmail gives classic Amiga systems direct access to Gmail through a native ReAction interface using IMAP, SMTP and AmiSSL.

AmiGmail, a new native Gmail client for classic Amiga systems, has arrived on Aminet. Developed by Andreas “Andiweli” Stürmer, the application uses the AmigaOS ReAction interface and connects directly to Gmail through IMAP and SMTP over AmiSSL/TLS. Messages remain on Gmail’s servers and are accessed live, rather than being downloaded into a local offline database.

The client supports Gmail’s Inbox, Sent, All Mail, Trash, Spam and Drafts folders, together with expandable nested labels. Users can compose and reply to messages, edit drafts, move or delete emails, mark messages as read or unread, sort message lists and send or save file attachments. It also supports clickable URLs, mailto: integration and automatic Inbox checks at startup or every five minutes.

AmiGmail can continue checking for mail while iconified on Workbench and optionally play a notification sound when new messages arrive. More recent additions include a local contacts manager with CSV and VCF importing, allowing recipients to be selected directly while composing or replying to an email.

Version 1.7, uploaded to Aminet on 17 August 2026, fixes notification sounds for the first new email received after restarting the application. It also increases the Workbench icon stack to 100,000 bytes to avoid stability problems. Development is moving quickly, however: version 1.8 was released through GitHub on 18 August, adding Reply All, message forwarding, email signatures, a startup splash screen and notification sounds bundled directly inside the archive.

Running AmiGmail requires AmigaOS 3.2 or later, a 68020 processor or better, ReAction, a working TCP/IP stack and AmiSSL 5.x. Gmail two-step verification must be enabled so that the application can connect using a dedicated App Password instead of the account’s normal password. Stored account information is protected using PBKDF2-HMAC-SHA256 key derivation and AES-256-GCM encryption.

There are some deliberate limitations. AmiGmail supports only one Gmail account, cannot be used with other email providers, does not offer an offline message cache and uses plain-text composition rather than an HTML editor. The interface is available in English and German.

Even with those restrictions, AmiGmail provides a surprisingly capable and genuinely native way to access modern Gmail services from a real Amiga. The project is open source under the GPL-3.0 licence and is not affiliated with Google.

Source: aminet.net
Retrogaming

GoldenEye 007 N64 Decompilation Reaches 100%

GoldenEye 007 N64 decompilation featured image celebrating the project reaching 100% completion, with Nintendo 64 hardware, source code and action imagery.
The GoldenEye 007 Nintendo 64 decompilation project has reached 100%, completing years of reverse-engineering work.

One of the Nintendo 64’s most important games has just reached a major preservation milestone. The long-running GoldenEye 007 decompilation project has reached 100%, completing the effort to reconstruct Rare’s 1997 classic into readable C source code.

The project makes it possible for developers to understand and modify the game at a much deeper level than traditional ROM hacking allows, opening the door to extensive mods, bug fixes, improvements and, potentially, native ports to modern platforms. The repository supports the original NTSC-US, Japanese and PAL versions of GoldenEye 007.

This does not mean GoldenEye itself has suddenly become a freely downloadable open-source game. Copyrighted game assets are not included in the repository, and anyone building it must provide an appropriate original copy of the game from which the required assets can be extracted.

For GoldenEye fans, however, reaching 100% is a significant moment. After years of reverse-engineering work, developers now have a complete foundation upon which much more ambitious GoldenEye projects can be built — and native ports are likely to be where things get particularly interesting.

Source: github.com

Fresh news from technology, retrocomputing, gaming and digital culture — covering new releases, projects, hardware, software and the stories worth knowing.