• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechThe Mobile Executive

Security Holes Found at Smartphone-Only Bank Backed by Peter Thiel

By
Reuters
Reuters
Down Arrow Button Icon
By
Reuters
Reuters
Down Arrow Button Icon
December 28, 2016, 12:23 PM ET
Photograph by Sean Gallup—Getty Images

German fintech company N26, which made its name mocking traditional banks, has found itself on the receiving end of criticism after a security researcher proved its smartphone apps exposed users to potential account hijacking.

N26, previously known as Number26, has expanded rapidly since it launched in early 2015 as a smartphone-only bank with no local branches, with the backing of major global investors including Silicon Valley’s Peter Thiel.

Vincent Haupert, a research fellow and PhD student in the computer science department of the University of Erlangen-Nuernberg, told the Chaos Communications Congress in Hamburg how he and two colleagues found N26 security defenses riddled with holes that could have been used to defraud thousands of users.

“They say you can open a bank account in just eight minutes,” Haupert said. “As it turns out, you can lose it even faster.”

In a statement, N26 thanked Haupert for alerting the company to “a theoretical security vulnerability” and advising it on fixes, which N26 said it completed this month.

N26 offers a range of online banking and other financial services to 200,000 customers in 17 European countries through a banking license granted earlier this year by German financial regulator Bafin.

Get Data Sheet, Fortune’s daily technology newsletter.

N26 executives have been the most outspoken among new fintech players in arguing traditional banks are failing to serve customers more directly by relying on antiquated local branch relationships instead of modern, phone-based services.

“I don’t see banks at all as my competitors. They just can’t move fast enough,” N26 Chief Executive Valentin Stalf told Reuters last year.

Haupert told the Chaos conference, Europe’s biggest annual gathering of hackers, how his team had found numerous ways to attack N26 banking apps to hijack individual customer accounts.

“With such a strategy, fintechs squander the trust that banks established over years,” he said.

For example, Haupert said he compared data from a leak of 68 million account credentials from online file sharing company Dropbox with information on N26 users he was able to request from the company’s own software feed to identify 33,000 N26 user credentials—without being thwarted by N26 anti-fraud systems.

From there, he said it would have been simple to send a phishing email to these N26 customers that could potentially have allowed him to break into their accounts.

“Don’t worry, we didn’t do this,” Haupert said. “My professor had legal concerns.”

Instead, Haupert disclosed his research findings to N26 on Sept. 25.

In response, N26 said in a statement it had made customer accounts more secure by reducing and encrypting data transfers, by blocking brute-force attacks in which hackers can quickly guess user credentials, and fixing voice-recognition security weaknesses in its app for the newest Apple (AAPL) mobile devices.

“At no time during these scenarios was personal data of our customers available to third parties,” the statement said. “No N26 customer was impacted by the demonstrated vulnerabilities.”

It added: “We have fully addressed and closed all vulnerabilities promptly and completely” and quoted Haupert as saying earlier this month that all vulnerabilities he had uncovered appeared to have been fixed.

Still, Haupert said regulators needed to take a closer look at the security of banks. “It was Bafin that granted a banking license to N26 only six months ago,” he said, adding that security weaknesses at that time were rampant.

A spokesman for the financial regulator declined to comment.

About the Author
By Reuters
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Mike Horton poses with his arms crossed.
NewslettersTerm Sheet
Exclusive: Hyfix raises $15 million to build a U.S. alternative to DJI’s drone dominance
By Lily Mae LazarusApril 15, 2026
11 minutes ago
A ULA Atlas V-551 rocket lifts off with 27 new Amazon Leo satellites from Cape Canaveral Space Force Station in Florida on December 14, 2025. (Photo: Manuel Mazzanti/NurPhoto/Getty Images)
NewslettersFortune Tech
Why Amazon bought Globalstar for $11.6 billion
By Andrew NuscaApril 15, 2026
40 minutes ago
Jeremy Renner
AIHealth
Exclusive: Jeremy Renner bets on the tech that could have saved his life faster: ‘There’s 150 people that are responsible for me not dying’
By Catherina GioinoApril 15, 2026
1 hour ago
The hidden menace behind Big Tech’s AI arms race: Meta, Amazon and others are spending billions on hardware that’s worthless in 3 years
AIFinance
The hidden menace behind Big Tech’s AI arms race: Meta, Amazon and others are spending billions on hardware that’s worthless in 3 years
By Shawn TullyApril 15, 2026
3 hours ago
The billionaire Anthropic cofounder who majored in literature says knowing how to ask the right questions beats knowing how to code
SuccessTech
The billionaire Anthropic cofounder who majored in literature says knowing how to ask the right questions beats knowing how to code
By Marco Quiroz-GutierrezApril 14, 2026
14 hours ago
TOKYO, JAPAN - FEBRUARY 3: Open AI CEO Sam Altman speaks during a talk session with SoftBank Group CEO Masayoshi Son at an event titled "Transforming Business through AI" in Tokyo, Japan, on February 03, 2025. SoftBank and OpenAI announced that they have agreed a partnership to set up a joint venture for artificial intelligence services in Japan today. (Photo by Tomohiro Oh
CybersecuritySam Altman
From Molotov cocktails to data center shutdowns, the AI backlash is turning revolutionary
By Eva RoytburgApril 14, 2026
15 hours ago

Most Popular

Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
Success
Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
By Fortune EditorsApril 13, 2026
2 days ago
Retirees are facing a $345,000 bill they never saw coming — and most aren't prepared
Commentary
Retirees are facing a $345,000 bill they never saw coming — and most aren't prepared
By Fortune EditorsApril 14, 2026
1 day ago
He was coding at 12 like Elon Musk and became one of Google’s youngest-ever CMOs—but now says Gen Z is better off ice skating than learning to code
Success
He was coding at 12 like Elon Musk and became one of Google’s youngest-ever CMOs—but now says Gen Z is better off ice skating than learning to code
By Fortune EditorsApril 14, 2026
1 day ago
Anthropic is facing a wave of user backlash over reports of performance issues with its Claude AI chatbot
AI
Anthropic is facing a wave of user backlash over reports of performance issues with its Claude AI chatbot
By Fortune EditorsApril 14, 2026
1 day ago
Current price of oil as of April 14, 2026
Personal Finance
Current price of oil as of April 14, 2026
By Fortune EditorsApril 14, 2026
22 hours ago
Current price of gold as of April 13, 2026
Personal Finance
Current price of gold as of April 13, 2026
By Fortune EditorsApril 13, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.