Publicité
ERP IMPLEMENTATION
🇫🇷 Lire en français

TeamSystem Data Breach: IBAN and Cloud Accounting Data Exfiltrated

TeamSystem detected unauthorised access to Contabilità in Cloud on 24 August 2026. IBAN numbers, emails and accounting transactions were exfiltrated. What CFOs and CIOs must do now.

TeamSystem Data Breach: IBAN and Cloud Accounting Data Exfiltrated

TeamSystem, the leading business management software vendor for SMEs in Italy — covering payroll, accounting and tax compliance — detected unauthorised access to its cloud application Contabilità in Cloud on 24 August 2026. The vendor notified affected customers on 26 August. Exfiltrated data includes IBAN numbers, accounting transactions and personal information (email addresses and phone numbers), according to Adnkronos, published 27 August 2026.

Context: a breach at the heart of SME financial data

Contabilità in Cloud is one of the flagship modules in the TeamSystem ecosystem, used by thousands of Italian SMEs and accounting firms for day-to-day bookkeeping, cash management and tax obligations. The data processed by this type of application is among the most sensitive a company handles: complete bank account details, transaction records (amounts, counterparties, transaction descriptions) and contact information for finance directors and their teams.

The unauthorised access was detected at the end of the day on 24 August 2026 — two days before TeamSystem formally notified its customers. The full scope of the exfiltration and the identity of the threat actors had not been disclosed in the vendor’s official communications at the time of writing.

Impact for affected businesses: IBAN fraud and targeted phishing

The highest-priority risk identified is IBAN substitution fraud. Ranieri Razzante, a cybersecurity expert quoted by Adnkronos, warned affected companies: exfiltrated IBAN numbers can be used to submit fraudulent bank account change requests, impersonating a legitimate supplier or customer.

Two concrete attack scenarios that CIOs and CFOs should anticipate:

Payment diversion fraud. An attacker who holds a supplier’s IBAN, their email address and data on typical transaction amounts can contact an accounts payable team to “update” banking details ahead of a payment. The baseline rule: any request to change an IBAN must be validated by a phone call to a known number — never by email alone.

Targeted phishing (spear phishing). Highly convincing fraudulent emails can be constructed from the exfiltrated accounting data (contact names, invoice amounts, transaction descriptions). This level of contextual detail makes such attacks extremely difficult to distinguish from genuine business communications.

Ranieri Razzante recommends “monitoring bank transactions closely over the coming days” and “verifying the identity of anyone requesting changes to banking details.”

What to monitor closely

GDPR notification and data protection authority. TeamSystem is subject to GDPR and Italian notification requirements from the Garante per la protezione dei dati personali. Any affected customer has the right to request precise information from the vendor on which of their data was exposed.

Official communication from TeamSystem. As of 27 August 2026, details on the full scope of the breach, containment measures taken and the number of affected companies had not been officially published. A more complete disclosure is expected in the coming days.

Questions to ask your cloud ERP vendor. This incident is an opportunity to challenge your ERP vendor on three fronts: their penetration testing programme (frequency, scope, and whether a summary is available), their incident response plan (detection and notification timelines), and the contractual protections in the event of a breach affecting your data.


For a deeper dive into securing your management systems, see our complete ERP cybersecurity guide and our analysis of Italy’s e-invoice data use rules.