Cyberattacks: The Biggest Waves Are Yet to Come
Cyberattacks on German businesses are becoming more targeted. Cyber resilience means prioritizing: closing API attack surfaces, managing patch windows, and testing recovery – without panic narratives.
Key Takeaways
- Up to 37 million customer records – primarily phone numbers and account details – are estimated to have been stolen by cybercriminals and offered for high sums on the dark web.
- Large-scale data theft is thriving; for example, Hanover-based auto supplier and tire manufacturer Continental was also severely affected at the end of 2022.
- T-Mobile’s US subsidiary claims on its corporate site that it aims to change wireless communication forever.
- Yet, like many other telecom firms – and companies across all sectors – it is grappling with very real, immediate challenges: data crime.
Related:622 CVEs: Prioritize Instead of Panic Patching / NIS2 Patchwork: Four States Before the ECJ
“Changing wireless for good.” T-Mobile’s US subsidiary claims on its corporate site that it aims to change wireless communication forever. A bold – and very high – ambition. Especially since the company, like many other telecom firms and businesses across all industries, is currently battling concrete, very earthly problems: data crime. In early 2023, T-Mobile in the US was hacked. Up to 37 million customer records – primarily phone numbers and account details – are estimated to have been stolen by cybercriminals and offered for high sums on the dark web.
APIs: Smart but unfortunately vulnerable interfaces
What is cyber resilience? The ability of an organization to anticipate attacks, limit damage, and restore operations in a targeted manner. Prioritized patches, hardened APIs, and tested recovery plans matter – not a flood of generic tools.
This is no isolated incident, and certainly not the last of its kind. Large-scale data theft is thriving; for example, Hanover-based auto supplier and tire manufacturer Continental was also severely affected at the end of 2022. Frank von Seth, CEO of cyan digital security, sees the cause of the attack – as in the T-Mobile case – often in misconfigured APIs. These “Application Programming Interfaces” are the gateways between different applications and systems, essentially the lifelines of digitalization. They enable data exchange between programs, companies, customers, or machines – think “Internet of Things.” Frank von Seth notes: “Cybercriminals have significantly professionalized in recent years and know these entry points like APIs all too well. When misconfigured, they simplify illegal third-party access to data.”
More openness means more attack surfaces
The problem is this: without greater openness between systems, there can be no progress in data sharing. Yet at the same time, the risks posed by these open structures grow exponentially – especially for companies with vast customer touchpoints, such as those in the telecommunications industry. Theoretically, there are two ways to respond: first, the path of complete isolation. But this “North Korea model” would mean maximum economic and technological regression – and is therefore not a serious option for German SMEs or corporations. That leaves only option two: even greater openness, paired with heightened risk awareness and far stronger IT resilience than before. This means, on the one hand, becoming more resistant to attacks. And on the other, behaving as effectively as possible in the event of likely attacks and minimizing the damage.
Frank von Seth anticipates a clear increase in cyberattacks. Business is no longer the domain of a few hackers: “For mass-market attacks, ready-made tools are already available on the dark web – tools you can buy as easily as a Netflix subscription. Anyone can become a criminal and send ransomware or run phishing campaigns.”
It can happen to anyone
Companies need to rethink their approach. Today, it can happen to anyone – regardless of industry, size, or scale. Frank von Seth: “Fundamentally, the question is no longer whether digital resilience must protect against hackers, but when. Too many still lack this awareness. IT security is still seen as cumbersome, as an obstacle to business processes. Yet the opposite is true: not only because scalable solutions already exist.”
In too many cases, companies resist implementing far-reaching IT security systems on cost grounds. Yet this not only opens the door to hackers – it also magnifies the economic damage once an attack succeeds and companies must deal with the aftermath.”
Many companies also focus too narrowly on protecting their own operations when erecting defenses against cyber attackers. The risks posed by partners, customers, or suppliers – whose own systems are equally vulnerable and with which corporate IT regularly exchanges data – are all too often overlooked.
Source: Freepik, evening_tao
Fact: According to ISC2, more than 3.4 million cybersecurity professionals are currently missing worldwide.
Fact: AV-TEST reports that over 450,000 new malware variants are discovered daily.
Key Facts
Dwell time: On average, attackers remain undetected in corporate networks for 204 days.
SMEs in the crosshairs: 43 percent of all cyberattacks target small and medium-sized enterprises.
Frequently Asked Questions
Each question is locked. Click to unlock the answer.
What are the most common cyber threats to businesses?
According to the BSI situation report, ransomware, phishing, DDoS attacks, and supply-chain compromises are the most prevalent threats. For German companies, regulatory risks (GDPR, NIS2) are additional factors.
How much should a company invest in cybersecurity?
Industry experts recommend allocating 10 to 15 percent of the IT budget to cybersecurity. German companies currently average 14 percent, according to Bitkom. What matters most is the absolute amount – and the strategic distribution across prevention, detection, and response.
Does every company need a CISO?
Not every company needs a full-time CISO, but every company does need clear accountability for IT security at the executive level. SMEs can engage an external CISO (virtual CISO). With NIS2, management responsibility becomes legally mandated.
Editor’s Reading Picks
Reading Tip622 CVEs: Prioritize, Don’t Panic-PatchReading TipNIS2 Patchwork: Four States Head to the ECJReading TipCI/CD Leaked the AsyncAPI Botnet Loader
More from the MBF Media Network
cloudmagazinThe Copilot Shift: First, the People Had to Come On BoardMyBusinessFutureFaster Back-office Operations: How Banks Are Finally Gaining Control Over Document-heavy ProcessesDigital ChiefsKimi Halts Subscriptions: 7 Checks for Your AI Capital Expenditure
Image source: AI-generated (July 2026)





