A cyber attack on TeamSystem led to the theft of personal and banking data contained in the Cloud Accounting software, used by companies and professionals for administrative and accounting management. Among the information that ended up in the hands of the authors of the intrusion there would also be IBAN coordinates and details of accounting operations, data that could be exploited to build particularly credible scams.
The incident was detected starting from the afternoon of August 24, 2026. According to the communication sent by TeamSystem to its customers, unauthorized access to the software occurred followed by the exfiltration of personal data, i.e. its copying and removal from the systems. The checks are still ongoing and the number of companies or people involved has not been disclosed.
The data involved, the communication specifies, correspond to that entered by users into the program and may include personal data, contact details, IBAN bank details and content of accounting movements, including, for example, reasons, amounts and counterparties. At present, access to accounts is not compromised: TeamSystem states that the checks did not reveal any involvement of user credentials.
This means that there is no evidence that attackers can directly enter accounts using stolen usernames and passwords. The main problem is another: the quantity and precision of the information stolen can make subsequent scams much more effective.
The IBAN scam that worries the Cybersecurity Agency
The National Cybersecurity Agency, consulted by Adnkronos, indicated phishing campaigns aimed at financial fraud and in particular the so-called “Iban swapping” among the main dangers.
The mechanism may be relatively simple. A criminal presents himself as a supplier the company actually works with and reports that the bank details have changed, asking for the next invoice to be paid into a new bank account. By already knowing the vendor’s name, business relationships and other authentic details, the message can be much more convincing than a regular phishing email.
The fundamental precaution is therefore not to change an Iban based on a simple email or message received, but to verify the request by contacting the supplier directly through an already known number or channel. ACN also recommends that you do not click on links that ask you to enter personal or banking information.
The presence of accounting movements makes the problem even more delicate. Reasons, amounts and counterparties can in fact allow us to at least partially reconstruct who pays whom, for which services and for what amounts, providing useful material for impersonating customers, suppliers, banks or consultants.
“Supervise bank movements”
Ranieri Razzante, university professor and cybercrime expert, also calls for caution. Interviewed by Adnkronos, Razzante defined the incident as serious, underlining that TeamSystem is a highly structured company active in the management of particularly delicate information for businesses and professionals.
Above all, the expert invites interested parties to monitor banking movements with particular attention and to intervene immediately in the presence of suspicious transactions.