TeamSystem Data Breach: The Stolen Details That Can Make Fraud Look Legitimate

An attack on Contabilità in Cloud exposed personal information, IBANs and, according to TeamSystem’s notification, accounting records. Passwords reportedly survived. The information needed to construct convincing payment fraud may not have.
Cybersecurity — 4 September 2026
When an IBAN is stolen, the first reassurance normally offered is that an IBAN is not a banking password. That is correct, but it risks missing the real significance of the TeamSystem data breach. The problem is not simply that criminals may now possess bank-account coordinates. According to the notification sent by TeamSystem to affected customers, the attackers may also have obtained the context surrounding those accounts: names, contact details, transaction descriptions, amounts and counterparties. That combination could allow criminals to produce fraudulent emails, invoices and telephone calls containing enough genuine information to appear legitimate.
What happened to TeamSystem
TeamSystem says it detected what it described as a sophisticated security incident during the afternoon of 24 August 2026. The incident involved unauthorised access to systems associated with Contabilità in Cloud, its cloud accounting service, followed by the exfiltration of data stored in the software.
The company informed affected customers by email on 26 August, approximately two days after detecting the incident. The story subsequently became public through social-media posts and reporting by Sky TG24, Adnkronos, Fanpage, Corriere della Sera, La Repubblica and specialist cybersecurity publications.
The confirmed scope is important. Public reporting identifies Contabilità in Cloud as the affected service. It does not establish that every TeamSystem product, every company system or every TeamSystem customer was compromised.
TeamSystem says on its website that more than three million customers use its products. That number illustrates the company’s importance in the Italian business-software market, but it must not be confused with the number of customers affected by this breach, which has not been disclosed.
What information was taken
The customer notification, as reproduced publicly and reported by several outlets, identifies four principal categories of exposed information:
- personal and identifying information;
- contact details, including email addresses and telephone numbers;
- banking coordinates, including IBANs;
- accounting transactions recorded in the platform, potentially including descriptions, amounts and counterparties.
TeamSystem reportedly said that, based on the investigation available at the time of the notification, customers’ login credentials did not appear to have been compromised. That reduces the immediate risk of criminals entering accounts with stolen passwords, but it does not eliminate the risk created by information already removed from the platform. There is also a discrepancy worth highlighting.
Sky TG24 and Adnkronos, reporting comments from Italy’s National Cybersecurity Agency, listed personal details, contact information and IBANs as the affected categories. The TeamSystem customer notification reproduced elsewhere also included the contents of accounting transactions.
Those descriptions do not entirely match. Until TeamSystem publishes a comprehensive public technical update, customers should rely principally on the individual notification they received and on the data they actually stored in the service. Exposure may differ from one customer environment to another.
An IBAN alone is not the biggest problem
Knowing an IBAN does not normally allow someone to log into a bank account or authorise a payment. Customers should therefore not interpret the breach as meaning that criminals can automatically withdraw money from their accounts. The greater danger is informed impersonation.
Imagine that an attacker knows that Company A regularly pays Supplier B, understands the approximate value and timing of those payments and has the email address and telephone number of the person handling the account.
The attacker can then contact Company A while pretending to be Supplier B. The message might refer to a genuine commercial relationship, quote a realistic amount and announce that the supplier has changed bank account. The next legitimate payment is then redirected to an account controlled by the criminal.
No bank account needs to be technically hacked. The victim voluntarily authorises the transfer because the request appears consistent with information that only a trusted party should possess.
This is commonly described as invoice-redirection fraud, supplier impersonation, IBAN swapping or a form of business email compromise. The National Cybersecurity Agency specifically warned about phishing and financial fraud involving fraudulent changes to payment coordinates.
The transaction data potentially makes these attacks more convincing. A generic phishing email may contain obvious errors. A message that names a real supplier, refers to a genuine service and requests an amount resembling previous payments is much harder for an accounts department to dismiss immediately.
The unanswered questions
More than a week after the incident was detected, several fundamental details remain absent from the public record.
TeamSystem has not publicly disclosed:
- how the attackers initially entered the environment;
- whether they exploited a software vulnerability, compromised an account or entered through a third party;
- when the unauthorised access actually began;
- how long the intruders remained inside the environment;
- the number of customers, records or individuals affected;
- the total quantity of information exfiltrated;
- whether the affected information was encrypted at rest;
- whether every Contabilità in Cloud environment was exposed or only a limited subset;
- who carried out the attack.
The date of 24 August represents the reported detection date. It should not automatically be interpreted as the date on which the intrusion began. Determining how long the attackers had access will be essential when assessing the true scale of the incident.
The reports reviewed for this article also do not identify a verified ransomware claim, named threat actor or public ransom demand. Until supporting evidence appears, attributing the incident to a particular criminal group would be speculation.
The public communication is not good enough
Sending a direct notification to affected customers within approximately two days of detection was necessary and useful. Direct communication is more important than a polished press release when organisations need immediate information about their own data. However, direct email should not be the end of the communication process.
As of 4 September, TeamSystem has not published a clearly visible incident page, public security advisory or press release explaining what happened, which products are affected, what customers should do, what has been contained and when further updates will be provided.
The breach became publicly documented because recipients and cybersecurity researchers shared the customer notification. Punto Informatico also reported that no official notice was available on TeamSystem’s corporate website.
There may be further information inside authenticated customer portals or in subsequent private correspondence. That does not replace a stable public source that customers, suppliers, accountants, banks and other potentially involved organisations can consult and verify.
The absence is particularly awkward because TeamSystem’s homepage currently tells prospective customers that they can rely on the “total security” of their data. No cloud provider can realistically guarantee total security. The credible promise is not that an incident can never occur, but that it will be detected, contained, explained and communicated transparently when it does.
What affected businesses should do now
Changing a TeamSystem password is a reasonable precaution, particularly when the same password has been used elsewhere, but password changes do not address the principal risk identified in this incident. TeamSystem says login credentials currently do not appear to have been taken. The most important protections concern payments and identity verification.
Businesses using Contabilità in Cloud should warn their finance teams, accountants and employees responsible for supplier payments that genuine commercial information may now be used in fraudulent requests.
Any request to change a supplier’s bank details should be verified through a previously known and independent channel. Staff should call a trusted telephone number already held in company records, not a number contained in the email requesting the change.
Changes to payment information and unusual transfers should require approval from at least two people. This is particularly important when a request is described as urgent, confidential or linked to the TeamSystem incident.
Unexpected emails, telephone calls or messages claiming to come from TeamSystem, a bank, an accountant or a supplier should be treated cautiously. A legitimate security process should not require customers to disclose passwords, one-time codes or payment authorisations, or to install remote-access software following an unsolicited contact.
Businesses should also monitor the bank accounts and IBANs entered in the platform. Suspicious payments or attempted fraud should be reported immediately to the relevant bank and authorities. The longer a fraudulent transfer remains undisputed, the more difficult recovery may become.
Independent telephone verification, separation of payment responsibilities and dual authorisation are more reliable controls than simply expecting every employee to recognise a professionally constructed phishing email.
Customers may have their own GDPR responsibilities
The notification reportedly refers to Article 33(2) of the GDPR. That provision applies when a data processor becomes aware of a personal-data breach and must inform the relevant data controller.
This distinction matters because TeamSystem may be processing information on behalf of businesses, accountants and professional firms that remain controllers of the personal data entered into the software.
According to the Italian Data Protection Authority, a controller must notify a breach to the authority without undue delay and, where possible, within 72 hours of becoming aware of it, unless the breach is unlikely to create a risk to people’s rights and freedoms. Where the risk is high, affected individuals may also need to be informed directly.
That does not mean every TeamSystem customer automatically has identical notification obligations. Each organisation needs to determine what information it stored, whose information was involved, what risks have arisen and whether its own regulator, customers, employees or suppliers must be notified.
The breach is not only TeamSystem’s problem
TeamSystem must explain how the intrusion occurred, establish the full affected population and provide continuing information to its customers. But the consequences will not remain contained inside TeamSystem’s systems.
The stolen records may describe relationships between businesses, customers, suppliers, accountants and banks. That means an organisation that has never purchased a TeamSystem product could still receive a convincing fraudulent message because its details appeared as a customer, supplier or counterparty in somebody else’s accounting records. This is why describing the incident simply as the theft of a collection of IBANs understates the danger.
An IBAN is a coordinate. An IBAN connected to a real identity, a genuine supplier, a plausible amount and an established payment relationship is a ready-made story. Criminals do not always need to break into a bank account when they possess enough accurate information to persuade somebody else to send them the money.
TeamSystem’s investigation will eventually need to explain the technical failure. In the meantime, customers should assume that the greatest immediate risk will arrive through apparently normal business communication, and may look far more credible than ordinary phishing.
Sources and further reading
- TeamSystem customer notification reproduced on X
- Sky TG24: Attacco hacker a TeamSystem
- Adnkronos: TeamSystem sotto attacco
- Fanpage: trafugati IBAN e dati personali
- Corriere della Sera: rubati IBAN e movimenti contabili
- Federprivacy: esposti IBAN e dati contabili
- Matrice Digitale: analysis of the customer notification
- Agenda Digitale: preventing fraud using stolen accounting data
- Italian Data Protection Authority: data-breach guidance











