THREAT BRIEFING · 09.09.2026 DEENFRES

Practice & Implementation

Cyberattacks: The Biggest Waves Are Yet to Come

By Benedikt Langer · July 21, 2026 · 6 min read

Cyberattacks on German businesses are becoming more targeted. Cyber resilience means prioritizing: closing API attack surfaces, managing patch windows, and testing recovery – without panic narratives.

Key Takeaways

  • Up to 37 million customer records – primarily phone numbers and account details – are estimated to have been stolen by cybercriminals and offered for high sums on the dark web.
  • Large-scale data theft is thriving; for example, Hanover-based auto supplier and tire manufacturer Continental was also severely affected at the end of 2022.
  • T-Mobile’s US subsidiary claims on its corporate site that it aims to change wireless communication forever.
  • Yet, like many other telecom firms – and companies across all sectors – it is grappling with very real, immediate challenges: data crime.

Related:622 CVEs: Prioritize Instead of Panic Patching  /  NIS2 Patchwork: Four States Before the ECJ

“Changing wireless for good.” T-Mobile’s US subsidiary claims on its corporate site that it aims to change wireless communication forever. A bold – and very high – ambition. Especially since the company, like many other telecom firms and businesses across all industries, is currently battling concrete, very earthly problems: data crime. In early 2023, T-Mobile in the US was hacked. Up to 37 million customer records – primarily phone numbers and account details – are estimated to have been stolen by cybercriminals and offered for high sums on the dark web.

APIs: Smart but unfortunately vulnerable interfaces

What is cyber resilience? The ability of an organization to anticipate attacks, limit damage, and restore operations in a targeted manner. Prioritized patches, hardened APIs, and tested recovery plans matter – not a flood of generic tools.

This is no isolated incident, and certainly not the last of its kind. Large-scale data theft is thriving; for example, Hanover-based auto supplier and tire manufacturer Continental was also severely affected at the end of 2022. Frank von Seth, CEO of cyan digital security, sees the cause of the attack – as in the T-Mobile case – often in misconfigured APIs. These “Application Programming Interfaces” are the gateways between different applications and systems, essentially the lifelines of digitalization. They enable data exchange between programs, companies, customers, or machines – think “Internet of Things.” Frank von Seth notes: “Cybercriminals have significantly professionalized in recent years and know these entry points like APIs all too well. When misconfigured, they simplify illegal third-party access to data.”

More openness means more attack surfaces

The problem is this: without greater openness between systems, there can be no progress in data sharing. Yet at the same time, the risks posed by these open structures grow exponentially – especially for companies with vast customer touchpoints, such as those in the telecommunications industry. Theoretically, there are two ways to respond: first, the path of complete isolation. But this “North Korea model” would mean maximum economic and technological regression – and is therefore not a serious option for German SMEs or corporations. That leaves only option two: even greater openness, paired with heightened risk awareness and far stronger IT resilience than before. This means, on the one hand, becoming more resistant to attacks. And on the other, behaving as effectively as possible in the event of likely attacks and minimizing the damage.

Frank von Seth anticipates a clear increase in cyberattacks. Business is no longer the domain of a few hackers: “For mass-market attacks, ready-made tools are already available on the dark web – tools you can buy as easily as a Netflix subscription. Anyone can become a criminal and send ransomware or run phishing campaigns.”

It can happen to anyone

Companies need to rethink their approach. Today, it can happen to anyone – regardless of industry, size, or scale. Frank von Seth: “Fundamentally, the question is no longer whether digital resilience must protect against hackers, but when. Too many still lack this awareness. IT security is still seen as cumbersome, as an obstacle to business processes. Yet the opposite is true: not only because scalable solutions already exist.”

In too many cases, companies resist implementing far-reaching IT security systems on cost grounds. Yet this not only opens the door to hackers – it also magnifies the economic damage once an attack succeeds and companies must deal with the aftermath.”

Many companies also focus too narrowly on protecting their own operations when erecting defenses against cyber attackers. The risks posed by partners, customers, or suppliers – whose own systems are equally vulnerable and with which corporate IT regularly exchanges data – are all too often overlooked.

 

Source: Freepik, evening_tao

Fact: According to ISC2, more than 3.4 million cybersecurity professionals are currently missing worldwide.

Fact: AV-TEST reports that over 450,000 new malware variants are discovered daily.

Key Facts

Dwell time: On average, attackers remain undetected in corporate networks for 204 days.

SMEs in the crosshairs: 43 percent of all cyberattacks target small and medium-sized enterprises.

Frequently Asked Questions

Each question is locked. Click to unlock the answer.

What are the most common cyber threats to businesses?

According to the BSI situation report, ransomware, phishing, DDoS attacks, and supply-chain compromises are the most prevalent threats. For German companies, regulatory risks (GDPR, NIS2) are additional factors.

How much should a company invest in cybersecurity?

Industry experts recommend allocating 10 to 15 percent of the IT budget to cybersecurity. German companies currently average 14 percent, according to Bitkom. What matters most is the absolute amount – and the strategic distribution across prevention, detection, and response.

Does every company need a CISO?

Not every company needs a full-time CISO, but every company does need clear accountability for IT security at the executive level. SMEs can engage an external CISO (virtual CISO). With NIS2, management responsibility becomes legally mandated.

Editor’s Reading Picks

Reading Tip622 CVEs: Prioritize, Don’t Panic-PatchReading TipNIS2 Patchwork: Four States Head to the ECJReading TipCI/CD Leaked the AsyncAPI Botnet Loader

More from the MBF Media Network

cloudmagazinThe Copilot Shift: First, the People Had to Come On BoardMyBusinessFutureFaster Back-office Operations: How Banks Are Finally Gaining Control Over Document-heavy ProcessesDigital ChiefsKimi Halts Subscriptions: 7 Checks for Your AI Capital Expenditure

Image source: AI-generated (July 2026)

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH