Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
N26

N26 Vendor Cyber Rating & Cyber Score

n26.com

N26 SE is Europe’s leading digital bank with a full German banking licence. Built on the latest technology, N26’s mobile banking experience makes managing money easier, more secure and customer friendly. N26 is headquartered in Berlin with offices in multiple cities across Europe, including Vienna and Barcelona, and a 1,500-strong team of more than 90 nationalities. Founded by Valentin Stalf and Maximilian Tayenthal in 2013, N26 has raised close to US$ 1.8 billion from some of the world’s most renowned investors. Need support? Please send us a direct message over on our N26 Support LinkedIn page: http://www.linkedin.com/company/n26support. Our team is here to help. Social media imprint and privacy policy:


N26 A.I CyberSecurity Scoring

N26
Company Information
Website:https://n26.com/
Employees number:1,824
Number of followers:317,501
NAICS:52
Industry Type:Financial Services
Homepage:n26.com
N26 Risk Score (AI oriented)
Between 700 and 749
logo
N26Financial Services
Updated:
22/04/2026
712/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
N26 Global Score (TPRM)
xxxx
logo
N26Financial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

N26
N26Moderate
Current Score
712Ba (MODERATE)
01000
3 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
715Before Incident
MAY 2026
713Before Incident
APRIL 2026
731Before Incident
MARCH 2026
711Before Incident
FEBRUARY 2026
709Before Incident
JANUARY 2026
708Before Incident
DECEMBER 2025
706Before Incident
NOVEMBER 2025
704Before Incident
OCTOBER 2025
702Before Incident
SEPTEMBER 2025
722Before Incident
AUGUST 2025
721Before Incident
JULY 2025
719Before Incident
JANUARY 2024
700Before Incident
Cyber Attack
01 Jan 2024N26
N26 and Revolut: French Fintech Accounts Used to Launder Stolen Funds Before Detection

French Freelancer Fintech Accounts Exploited for Large-Scale Money Laundering

641After Incident
CRITICAL-59
N26REV1776860884
French Freelancer Fintech Accounts Exploited for Large-Scale Money Laundering Cybercriminals are increasingly hijacking French freelancer fintech accounts to launder stolen funds at high speed, often moving money within minutes before banks or victims detect the fraud. Platforms like Revolut, Wise, and N26 designed for fast onboarding, light-touch KYC, and instant SEPA transfers have become prime targets due to their business-level payment capabilities, despite being tied to individual users. In 2024, credit transfer fraud in the European Economic Area (EEA) reached €2.5 billion, with victims absorbing roughly 85% of losses. These accounts are more attractive to criminal networks than standard consumer accounts, as they enable cross-border transfers and payment processing under the guise of legitimate business activity. ### Industrial-Scale Mule Account Operations Fraudsters acquire verified freelancer accounts through a sophisticated, multi-stage process: - Identity Harvesting: Phishing sites and fake financial services (e.g., bogus mortgage portals) collect real French personal data. - SIM Farm Infrastructure: Criminals use SIM modem farms to generate French IP addresses and phone numbers, rotating connections to evade detection. - Social Engineering KYC: Victims are tricked into completing verification, making the process appear compliant to fintech platforms. - Account Handoff: Once verified, accounts are transferred to fraud rings via mobile apps, creating distinct device profiles in telemetry. Dark web markets, including the ASGARD network and actor @astarta_seller1, specialize in selling these accounts, with premium French freelancer profiles fetching $450–$700. France is the primary target, followed by Germany, Spain, Italy, Poland, and the UK. ### Detection Challenges & Broader Impact The fraud ecosystem exploits gaps in point-in-time checks, as each stage of the process sign-up, KYC, and login appears legitimate in isolation. Effective defense now requires linking signals across the full account lifecycle, including infrastructure, subnet continuity, and cross-account connections. The 2025 EBA/ECB Payment Fraud Report highlights the rapid growth of credit transfer fraud, driven by the abuse of instant payment rails. For risk and compliance teams, freelancer fintech accounts must be monitored as part of broader fraud networks, not just individual users.
INCIDENT DETAILS -
TYPE
Money Laundering, Fraud, Account Takeover
MOTIVATION
Financial gain, Money laundering
IMPACT
Financial Loss: €2.5 billion (2024 EEA credit transfer fraud)Data Compromised: French personal data, Freelancer account credentialsSystems Affected: Fintech platforms (Revolut, Wise, N26), Payment rails (SEPA)Operational Impact: Exploitation of instant payment rails, Fraudulent cross-border transfersBrand Reputation Impact: Potential erosion of trust in fintech platformsIdentity Theft Risk: High (PII harvested and exploited)Payment Information Risk: High (fraudulent transactions)
DATA BREACH
Type Of Data Compromised: Personal Identifiable Information (PII), Account credentialsSensitivity Of Data: High (used for fraud and money laundering)Personally Identifiable Information: Yes (French personal data)
JANUARY 2023
729Before Incident
Cyber Attack
01 Jan 2023N26
N26, Revolut and Wise: Cybercriminals Exploit French Fintech Accounts to Move Stolen Money Before Detection

Fraud Networks Exploit Fintech Platforms in France to Launder Stolen Funds

671After Incident
CRITICAL-58
N26REVWIS1776889641
Fraud Networks Exploit Fintech Platforms in France to Launder Stolen Funds Organized fraud networks in France are deploying a sophisticated scheme to launder stolen money through fake business accounts on freelancer fintech platforms like Revolut, Wise, and N26. These platforms, designed for fast account openings and seamless transactions, have become prime targets due to their business-grade payment infrastructure, including SEPA transfers and invoicing. The operation, tracked as "Bastardaseller" part of the larger ASGARD fraud network specializes in creating and selling verified European business accounts on dark web marketplaces for $200 to $1,000 each. These accounts, known as mule accounts, enable fraudsters to move funds rapidly via instant payment rails, often before detection. In France, nearly 1 in 5 sign-up users was identified as a mule account, with the true scale likely higher. The scheme operates in three phases: 1. Phishing for PII – Fraudsters run phishing campaigns, such as fake mortgage consultation services, to collect victims' personal data. 2. Account Registration – Stolen PII is used to open accounts, with operators masking their location using SIM modem farms to generate French IP addresses and phone numbers. 3. Operational Handover – Once KYC is completed, control shifts to the fraud network via mobile apps, with subnet continuity linking the new login to the original sign-up infrastructure. According to the EBA-ECB Joint Report on Payment Fraud, credit transfer fraud losses in the European Economic Area reached $2.5 billion in 2023, a 25% increase from the previous year, with mule accounts as the primary driver. Detection remains challenging, as the fraud only becomes visible when analyzing the full account lifecycle rather than isolated transactions. Fintech platforms are urged to monitor MVNO IP addresses, sign-up velocity patterns, and device downgrades between KYC and operational phases to disrupt these networks. The attack underscores the growing threat of structured fraud operations exploiting digital financial services.
INCIDENT DETAILS -
TYPE
Fraud, Money Laundering
MOTIVATION
Financial gain, Money laundering
IMPACT
Financial Loss: $2.5 billion (credit transfer fraud losses in EEA, 2023)Data Compromised: Personally Identifiable Information (PII)Systems Affected: Fintech platforms (Revolut, Wise, N26)Operational Impact: Increased fraud detection challenges, exploitation of payment railsBrand Reputation Impact: Potential reputational damage to fintech platformsIdentity Theft Risk: High (stolen PII used for account creation)Payment Information Risk: High (SEPA transfers, instant payments)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Sensitivity Of Data: High (used for account creation and fraud)Personally Identifiable Information: Yes (stolen via phishing)
JANUARY 2022
770Before Incident
Cyber Attack
01 Jan 2022N26
N26: Stolen Money Routed Through French Fintech Accounts In New Cybercriminal Scheme

Cybercriminals Exploit French Fintech Platforms to Launder Stolen Funds Across Europe

712After Incident
CRITICAL-58
N261776853591
Cybercriminals Exploit French Fintech Platforms to Launder Stolen Funds Across Europe A sophisticated cybercrime operation is leveraging freelancer-focused fintech platforms in France to create verified mule accounts, facilitating the movement of stolen money across Europe. Research from Group-IB reveals that services like Revolut, Wise, and N26 popular for their fast onboarding and business-grade tools have become prime targets for fraud networks due to their ease of use and cross-border transfer capabilities. Criminals exploit the hybrid nature of these accounts, which combine personal identity verification with business-like functionality, allowing them to appear legitimate while rapidly transferring illicit funds. Verified mule accounts are sold on dark web markets for $300 to $700 each, often with escrow guarantees and replacement policies, underscoring the professionalization of the scheme. The operation follows a multi-stage process, beginning with phishing attacks that harvest victims’ personal data. One tactic involved fake mortgage advice sites, tricking users into submitting sensitive information later used to open fintech accounts. Once established, these accounts serve as conduits for stolen funds, complicating recovery efforts due to instant payment rails. The financial impact is severe: credit transfer fraud losses in the European Economic Area (EEA) reached €2.5 billion in 2024 a 24% increase from the previous year with end users bearing 85% of the costs. Group-IB’s findings highlight the scale of the problem, estimating that nearly 1 in 7 business account sign-ups in France may be fraudulent. The scheme is linked to organized cybercrime groups, including the ASGARD Network, with one actor, @astarta_seller1, actively advertising verified European accounts on underground forums. French entrepreneur accounts are particularly prized, commanding premium prices and indicating a targeted, high-volume operation. Many mule accounts likely remain undetected, posing an ongoing threat to financial security.
INCIDENT DETAILS -
TYPE
Financial Fraud, Money Laundering, Phishing
MOTIVATION
Financial gain, money laundering
IMPACT
Financial Loss: €2.5 billion in credit transfer fraud losses in the EEA (2024)Data Compromised: Personal data, personally identifiable informationSystems Affected: Fintech platforms (Revolut, Wise, N26)Operational Impact: Fraudulent account creation, illicit fund transfersBrand Reputation Impact: Potential reputational damage to fintech platformsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Personal data, personally identifiable informationSensitivity Of Data: HighPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for N26 ?
?
What was N26's A.I Rankiteo Cyber Score in May 2026 ?
?
What was N26's A.I Rankiteo Cyber Score in April 2026 ?
?
What was N26's A.I Rankiteo Cyber Score in March 2026 ?
?
What was N26's A.I Rankiteo Cyber Score in February 2026 ?
?
What was N26's A.I Rankiteo Cyber Score in January 2026 ?
?
What was N26's A.I Rankiteo Cyber Score in December 2025 ?
?
What was N26's A.I Rankiteo Cyber Score in November 2025 ?
?
What was N26's A.I Rankiteo Cyber Score in October 2025 ?
?
What was N26's A.I Rankiteo Cyber Score in September 2025 ?
?
What was N26's A.I Rankiteo Cyber Score in August 2025 ?
?
What was N26's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on N26's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with N26 ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view N26's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?