EBU Single Rulebook Q&A 4 November 2025 2025_7613 Classification of phishing-attacks as a reportable major ICT-related incident

Also known as

European Union · · · 06-02-2026

Can individual phishing incidents that target the customers of a financial entity in their “private sphere” be subsumed under “compromises the security of the network and information systems” pursuant to Article 3 No. 8 of Regulation (EU) 2022/2554 and can they therefore constitute a major ICT-related incident that must be reported pursuant to Article 19 (1) of Regulation (EU) 2022/2554?

Read the full text

This document is published by eba.europa.eu.

Moonlit adds the citation network, article-level links and cross-references, which are available to search for free.