2019 Internal access control breach
Data compromised
Account info, transaction data
Technical writeup
Autumn 2019. Employees without proper security clearance gained access to unencrypted customer account information. More than 300 authorized employees had access; unauthorized staff could view transaction data via customer name or email. Took over a week to fix after employee report; not immediately reported to regulators. BaFin later fined N26 €9.2M (2024) for compliance issues.
Root cause
Overly broad access controls; inadequate data access restrictions.