TeamSystem Hacker Attack: Client Personal Data and IBANs Stolen
- TeamSystem, an enterprise software provider used by businesses and independent professionals, suffered a significant cybersecurity incident affecting its Contabilità in Cloud service.
- The company confirmed that user credentials and passwords remain safe.
- The breach exposed four main types of information stored within the software:
TeamSystem, an enterprise software provider used by businesses and independent professionals, suffered a significant cybersecurity incident affecting its Contabilità in Cloud
service. The intrusion began on the afternoon of August 24, 2026. It led to the unauthorized exfiltration of personal data, accounting histories, and banking information from the cloud-based accounting platform.
Cyberattack on TeamSystem Exposes Financial Data and Accounts
Compromised Records and Stolen Financial Files
The company confirmed that user credentials and passwords remain safe. Attackers likely cannot access individual user profiles directly. However, the stolen files include core identifiers and financial trails.
The breach exposed four main types of information stored within the software:
- Customer master data (dati anagrafici) including legal names and identification details.
- Contact information such as email addresses and telephone numbers.
- Banking coordinates, specifically International Bank Account Numbers (IBANs).
- Historical accounting movements, including transaction amounts and payment descriptions.
National Cybersecurity Agency Assesses Corporate Impact
The Agenzia per la cybersicurezza nazionale (ACN) stated that the cyberattack has no direct impact on individual citizens. Still, it presents risks for corporate clients utilizing TeamSystem applications. Technical teams at the agency noted that the scope of the exfiltrated files remains restricted to contact records, general master data, and bank routing numbers.
Unknown Entry Vectors and Silent Threat Actors
As of the initial disclosures, TeamSystem has not disclosed the initial vector of the attack, the specific vulnerability exploited, the total volume of stolen records, or the exact count of accounts impacted by the breach. The company has not received or reported any ransom demands or operational take-over claims from the threat actors involved.
Targeted Fraud and IBAN Swapping Threats
Because the hackers obtained records detailing commercial relationships, payment frequencies, and service types, criminals can craft targeted communication campaigns.

Fraudsters could inject themselves into ongoing financial workflows to redirect upcoming payments toward alternative, attacker-controlled bank accounts, a tactic known as IBAN swapping.
Phishing Warnings and Defense Guidance for Clients
Furthermore, the compromised contact and banking details heighten the threat of phishing campaigns. Attackers armed with authentic financial histories can impersonate accredited agencies or trusted partners.
Cybersecurity authorities advise business clients to verify any unexpected requests for billing changes or IBAN updates through separate communication channels and to avoid clicking unsolicited links requesting personal or financial credentials.
