V-Bank Munich: the bank confirms, a cloud vendor was the target
German bank V-Bank Munich confirmed unauthorized access to its data, caused by
a cyberattack on one of its cloud vendors. Names, birth dates and
account information exposed β but no account access or fund transfers,
according to the bank.
β οΈ Confirmed directly by the bank, in precise
language. V-Bank Munich publicly acknowledged the incident and detailed what was
NOT affected β a rare level of transparency that allows for a particularly well-sourced
case file.
The numbers
Jun 10
Date of the attack on V-Bank's external IT vendor.
it-finanzmagazin.de, 06/2026.
1
Vendor targeted: a certified cloud services provider for the bank
β not the core banking system.
axia-am.de, 06/2026.
0
Accounts, login credentials, or tax data affected, according to
V-Bank. No fund transfers recorded.
V-Bank statement.
BaFin
Germany's banking regulator issued a warning about cyber risks
following this incident.
private-banking-magazin.de.
Timeline
CONFIRMED
June 10, 2026
An external IT vendor of V-Bank, a certified cloud services
provider for the bank, is targeted by a cyberattack. This vendor had access to a
V-Bank database hosted externally, separate from the core banking system.
CONFIRMED
Follow-up
V-Bank publicly confirms: "We can confirm that our bank was the
target of unauthorized data access following a cyberattack on an external IT service
provider." Affected data includes names, birth dates, contact information, and
account-related information (asset status, transaction data, reference accounts). No
access to accounts, login credentials, or tax data; no fund transfers.
βοΈThe same pattern, this time in banking
This case confirms, in a different country and sector, the pattern already documented
with MGP and
CEVA Logistics: the
institution itself isn't directly breached β a technical vendor, here a cloud provider,
is. The separation between the compromised external database and the core banking
system is precisely what limited the damage.
What it changes for you
If you're a V-Bank customer, the exposed data β identity, contact details, general
asset status β doesn't allow direct access to your account, but is enough to fabricate a
credible call posing as your account manager. That's the same mechanism documented in
From Leak to Scam.
π A call "from your bank" that cites your real data remains a
possible impersonation if it asks for a login, password, or verification code. Always
call your bank back through a number you already know. See
how Medusa links channels together.
Frequently asked questions
Is the V-Bank breach confirmed?
Yes, directly by the bank, with a precise public statement about the incident and
its vendor.
Is my money safe?
According to V-Bank, yes: no account access or fund transfers occurred.
What's the connection to the IT vendor?
The vendor provided cloud services to V-Bank and had access to an external
database, separate from the core banking system β that database was
compromised.
π Last checked: August 21, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio β The Threat Laboratory, "V-Bank Munich: the bank confirms, a cloud vendor was the target," egidio.app/en/laboratoire/vbank-munich-vendor-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.