Breaking news

Temu Faces €200 Million Fine Over EU Risk Assessment Shortcomings

Regulatory Repercussions For Risk Management Lapses

Temu was fined €200 million by the European Commission for failing to implement adequate risk assessment measures under the Digital Services Act (DSA). The penalty targets the company’s handling of illegal and unsafe products sold through its platform and reflects growing regulatory scrutiny of large online marketplaces operating in the European Union.

Inadequate Risk Assessment Framework

According to the Commission, Temu relied on general e-commerce industry data rather than platform-specific evidence when assessing risks linked to illegal or dangerous products. Regulators said the company failed to properly identify, analyze and evaluate systemic risks facing EU consumers. The investigation focused on risks associated with products including electronic chargers, baby toys and jewellery sold through the platform.

Alarming Safety Concerns

A mystery shopping exercise conducted during the investigation identified multiple safety violations involving products purchased through Temu. Several electronic chargers reportedly failed EU safety standards, with some overheating or catching fire during testing. Authorities also identified choking hazards and dangerous chemicals in baby toys, while some jewellery products were found to contain misleading labels or fail to comply with EU product regulations.

Design Flaws And Systemic Shortcomings

The probe extended beyond isolated product failures to examine the overall efficacy of Temu’s systems. The Commission highlighted that the platform’s use of recommendation systems and influencer-led promotion programs may inadvertently propagate the circulation of illegal products. Such systemic deficiencies represent a serious breach of obligations under the DSA.

Mandated Action And Future Compliance

Temu has until August 28, 2026, to submit an action plan outlining how it intends to strengthen risk assessment procedures and improve seller and product verification systems. The Commission said the company must introduce more advanced and evidence-based compliance measures to meet regulatory requirements. Temu described the fine as disproportionate and said improvements had already been implemented following the original 2024 assessment. European regulators indicated that additional sanctions remain possible if further violations or compliance failures are identified.

Google Warns Of Vishing Campaign Targeting Financial Firms

Cybercriminals are increasingly relying on a simple tactic to breach major financial institutions: convincing employees to hand over their own login credentials.

In a new report, Google said several hacking groups have been targeting large financial and investment firms in the United States through voice phishing, or “vishing”, before stealing sensitive corporate data and using it to extort victims.

Employees Are The Primary Target

According to Google’s researchers, attackers contact employees on their personal mobile phones while posing as colleagues or IT support staff. Victims are then directed to fake websites, where they are tricked into entering login credentials and multi-factor authentication codes.

Google tracks the groups under the names Falcon, Helix, Pink and Redact, although researchers believe they may be linked to a broader threat cluster known as UNC6671.

Some of the groups operate leak websites, where they threaten to publish stolen data unless companies agree to pay a ransom.

Financial Sector In The Spotlight

While previous attacks targeted industries including manufacturing, healthcare, insurance, technology and hospitality, Google said the hackers have increasingly shifted their focus to financial institutions and law firms.

Researchers believe organisations involved in mergers, acquisitions and capital markets are particularly attractive targets because of the highly confidential information they hold.

Google estimated that one cryptocurrency wallet linked to the operation received around $10 million in bitcoin during the first few months of the year. Ransom demands typically range from $750,000 to $3 million.

The report highlights that despite rapid advances in AI-driven cyberattacks, traditional social engineering techniques remain among the most effective ways for attackers to gain access to corporate networks.

The Future Forbes Realty Global Properties
Uol
Aretilaw firm
eCredo

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter