AI Stories on SHORT INFO are generated & curated with AI
unverified 18 Jul, 05:11

BaFin DORA report 525 serious ICT incidents German financial sector first three quarters 2025 phishing service providers

German financial firms reported 525 serious IT incidents to regulator BaFin in the first three quarters of 2025, the first year of EU DORA reporting. About 70 percent came from banks. 31 percent of reported attacks hit external service providers, not the firms themselves. Source:

German financial firms reported 525 serious IT incidents to the financial regulator BaFin in the first three quarters of 2025, according to BaFin's Risks in Focus 2026 report. It was the first year of mandatory incident reporting under the EU's Digital Operational Resilience Act (DORA), which took effect on 17 January 2025 and made BaFin the central reporting hub for the German financial sector. About 70 percent of the reports came from credit institutions. Only 10 percent of all reported incidents were security incidents; most were operational, caused by faulty updates or configuration errors rather than attackers. Where attacks did occur, phishing was the most common pattern at 31.1 percent, followed by malware and hacking at 24.4 percent. The most striking figure concerns third parties: 31 percent of all attacks reported in 2025 did not hit the financial firm itself but one of its service providers, while still causing serious impact at the firm. In one case, attackers captured data from numerous financial firms through a vulnerability in a single service provider's software, and customer data later appeared for sale on the dark web. For banks and insurers, these numbers put outsourcing and vendor management at the center of operational risk, since a firm's resilience is only as strong as the weakest supplier in its chain. BaFin says it will consolidate the reports into a sector-wide cyber risk overview and run cross-sector crisis exercises. Source: bafin.de, Risks in Focus 2026

#cyber
Published on
XBlueskyFacebookThreads