Egidio
Case file Β· August 21, 2026

V-Bank Munich: the bank confirms, a cloud vendor was the target

German bank V-Bank Munich confirmed unauthorized access to its data, caused by a cyberattack on one of its cloud vendors. Names, birth dates and account information exposed β€” but no account access or fund transfers, according to the bank.

⚠️ Confirmed directly by the bank, in precise language. V-Bank Munich publicly acknowledged the incident and detailed what was NOT affected β€” a rare level of transparency that allows for a particularly well-sourced case file.

The numbers

Jun 10
Date of the attack on V-Bank's external IT vendor.
it-finanzmagazin.de, 06/2026.
1
Vendor targeted: a certified cloud services provider for the bank β€” not the core banking system.
axia-am.de, 06/2026.
0
Accounts, login credentials, or tax data affected, according to V-Bank. No fund transfers recorded.
V-Bank statement.
BaFin
Germany's banking regulator issued a warning about cyber risks following this incident.
private-banking-magazin.de.

Timeline

CONFIRMED
June 10, 2026
An external IT vendor of V-Bank, a certified cloud services provider for the bank, is targeted by a cyberattack. This vendor had access to a V-Bank database hosted externally, separate from the core banking system.
CONFIRMED
Follow-up
V-Bank publicly confirms: "We can confirm that our bank was the target of unauthorized data access following a cyberattack on an external IT service provider." Affected data includes names, birth dates, contact information, and account-related information (asset status, transaction data, reference accounts). No access to accounts, login credentials, or tax data; no fund transfers.

☁️The same pattern, this time in banking

This case confirms, in a different country and sector, the pattern already documented with MGP and CEVA Logistics: the institution itself isn't directly breached β€” a technical vendor, here a cloud provider, is. The separation between the compromised external database and the core banking system is precisely what limited the damage.

What it changes for you

If you're a V-Bank customer, the exposed data β€” identity, contact details, general asset status β€” doesn't allow direct access to your account, but is enough to fabricate a credible call posing as your account manager. That's the same mechanism documented in From Leak to Scam.

πŸ”’ A call "from your bank" that cites your real data remains a possible impersonation if it asks for a login, password, or verification code. Always call your bank back through a number you already know. See how Medusa links channels together.

Frequently asked questions

Is the V-Bank breach confirmed?

Yes, directly by the bank, with a precise public statement about the incident and its vendor.

Is my money safe?

According to V-Bank, yes: no account access or fund transfers occurred.

What's the connection to the IT vendor?

The vendor provided cloud services to V-Bank and had access to an external database, separate from the core banking system β€” that database was compromised.

πŸ“Œ Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "V-Bank Munich: the bank confirms, a cloud vendor was the target," egidio.app/en/laboratoire/vbank-munich-vendor-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.