← N26

2019 Internal access control breach

2019 Unknown records affected Share on X

Data compromised

Account info, transaction data

Technical writeup

Autumn 2019. Employees without proper security clearance gained access to unencrypted customer account information. More than 300 authorized employees had access; unauthorized staff could view transaction data via customer name or email. Took over a week to fix after employee report; not immediately reported to regulators. BaFin later fined N26 €9.2M (2024) for compliance issues.

Root cause

Overly broad access controls; inadequate data access restrictions.

References