{"id":7112,"date":"2026-07-21T21:06:43","date_gmt":"2026-07-21T21:06:43","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3214\/"},"modified":"2026-07-23T12:12:27","modified_gmt":"2026-07-23T12:12:27","slug":"cyberattacks-the-biggest-waves-are-yet-to-come","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/07\/21\/cyberattacks-the-biggest-waves-are-yet-to-come\/","title":{"rendered":"Cyberattacks: The Biggest Waves Are Yet to Come"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">4 min read<\/p>\n<p><strong>Cyberattacks on German businesses are becoming more targeted. Cyber resilience means prioritizing: closing API attack surfaces, managing patch windows, and testing recovery &#8211; without panic narratives.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;\">Up to 37 million customer records &#8211; primarily phone numbers and account details &#8211; are estimated to have been stolen by cybercriminals and offered for high sums on the dark web.<\/li>\n<li style=\"margin-bottom:12px;\">Large-scale data theft is thriving; for example, Hanover-based auto supplier and tire manufacturer Continental was also severely affected at the end of 2022.<\/li>\n<li style=\"margin-bottom:12px;\">T-Mobile\u2019s US subsidiary claims on its corporate site that it aims to change wireless communication forever.<\/li>\n<li style=\"margin-bottom:12px;\">Yet, like many other telecom firms &#8211; and companies across all sectors &#8211; it is grappling with very real, immediate challenges: data crime.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/17\/622-cves-prioritize-over-panic-patching\/\" style=\"color:#333;text-decoration:underline;\">622 CVEs: Prioritize Instead of Panic Patching<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/17\/nis2-patchwork-four-states-face-eu-court\/\" style=\"color:#333;text-decoration:underline;\">NIS2 Patchwork: Four States Before the ECJ<\/a><\/p>\n<p>\u201cChanging wireless for good.\u201d T-Mobile\u2019s US subsidiary claims on its corporate site that it aims to change wireless communication forever. A bold &#8211; and very high &#8211; ambition. Especially since the company, like many other telecom firms and businesses across all industries, is currently battling concrete, very earthly problems: data crime. In early 2023, T-Mobile in the US was hacked. Up to 37 million customer records &#8211; primarily phone numbers and account details &#8211; are estimated to have been stolen by cybercriminals and offered for high sums on the dark web.<\/p>\n<h2>APIs: Smart but unfortunately vulnerable interfaces<\/h2>\n<p><strong>What is cyber resilience?<\/strong> The ability of an organization to anticipate attacks, limit damage, and restore operations in a targeted manner. Prioritized patches, hardened APIs, and tested recovery plans matter &#8211; not a flood of generic tools.<\/p>\n<p>This is no isolated incident, and certainly not the last of its kind. Large-scale data theft is thriving; for example, Hanover-based auto supplier and tire manufacturer Continental was also severely affected at the end of 2022. Frank von Seth, CEO of <a href=\"https:\/\/www.cyansecurity.com\/\">cyan digital security<\/a>, sees the cause of the attack &#8211; as in the T-Mobile case &#8211; often in misconfigured APIs. These \u201cApplication Programming Interfaces\u201d are the gateways between different applications and systems, essentially the lifelines of digitalization. They enable data exchange between programs, companies, customers, or machines &#8211; think \u201cInternet of Things.\u201d Frank von Seth notes: \u201cCybercriminals have significantly professionalized in recent years and know these entry points like APIs all too well. When misconfigured, they simplify illegal third-party access to data.\u201d<\/p>\n<h2>More openness means more attack surfaces<\/h2>\n<p>The problem is this: without greater openness between systems, there can be no progress in data sharing. Yet at the same time, the risks posed by these open structures grow exponentially &#8211; especially for companies with vast customer touchpoints, such as those in the telecommunications industry. Theoretically, there are two ways to respond: first, the path of complete isolation. But this \u201cNorth Korea model\u201d would mean maximum economic and technological regression &#8211; and is therefore not a serious option for German SMEs or corporations. That leaves only option two: even greater openness, paired with heightened risk awareness and far stronger IT resilience than before. This means, on the one hand, becoming more resistant to attacks. And on the other, behaving as effectively as possible in the event of likely attacks and minimizing the damage.<\/p>\n<p>Frank von Seth anticipates a <a href=\"https:\/\/www.cloudmagazin.com\/2026\/07\/21\/copilot-adoption-eigenversuch\/\" target=\"_blank\" rel=\"noopener\">clear increase in cyberattacks<\/a>. Business is no longer the domain of a few hackers: \u201cFor mass-market attacks, ready-made tools are already available on the dark web &#8211; tools you can buy as easily as a Netflix subscription. Anyone can become a criminal and send ransomware or run phishing campaigns.\u201d<\/p>\n<h2>It can happen to anyone<\/h2>\n<p>Companies need to rethink their approach. Today, it can happen to anyone &#8211; regardless of industry, size, or scale. Frank von Seth: \u201cFundamentally, the question is no longer whether digital resilience must protect against hackers, but when. Too many still lack this awareness. IT security is still seen as cumbersome, as an obstacle to business processes. Yet the opposite is true: not only because scalable solutions already exist.\u201d<\/p>\n<p style=\"text-align: left;\">In too many cases, companies resist implementing far-reaching IT security systems on cost grounds. Yet this not only opens the door to hackers &#8211; it also magnifies the economic damage once an attack succeeds and companies must deal with the aftermath.\u201d<\/p>\n<p style=\"text-align: left;\">Many companies also focus too narrowly on protecting their own operations when erecting defenses against cyber attackers. The risks posed by partners, customers, or suppliers &#8211; whose own systems are equally vulnerable and with which corporate IT regularly exchanges data &#8211; are all too often overlooked.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: right;\"><em>Source: <a href=\"https:\/\/www.freepik.com\/free-photo\/large-buildings-with-dome-lights_960759.htm#query=telekommunikation&amp;position=31&amp;from_view=search&amp;track=robertav1_2_sidr\">Freepik, evening_tao<\/a><\/em><\/p>\n<p><strong>Fact:<\/strong> According to ISC2, more than 3.4 million cybersecurity professionals are currently missing worldwide.<\/p>\n<p><strong>Fact:<\/strong> AV-TEST reports that over 450,000 new malware variants are discovered daily.<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>Dwell time:<\/strong> On average, attackers remain undetected in corporate networks for 204 days.<\/p>\n<p><strong>SMEs in the crosshairs:<\/strong> 43 percent of all cyberattacks target small and medium-sized enterprises.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Each question is locked. Click to unlock the answer.<\/p>\n<details>\n<summary><strong>What are the most common cyber threats to businesses?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">According to the BSI situation report, ransomware, phishing, DDoS attacks, and supply-chain compromises are the most prevalent threats. For German companies, regulatory risks (GDPR, NIS2) are additional factors.<\/p>\n<\/details>\n<details>\n<summary><strong>How much should a company invest in cybersecurity?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Industry experts recommend allocating 10 to 15 percent of the IT budget to cybersecurity. German companies currently average 14 percent, according to Bitkom. What matters most is the absolute amount &#8211; and the strategic distribution across prevention, detection, and response.<\/p>\n<\/details>\n<details>\n<summary><strong>Does every company need a CISO?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Not every company needs a full-time CISO, but every company does need clear accountability for IT security at the executive level. SMEs can engage an external CISO (virtual CISO). With NIS2, management responsibility becomes legally mandated.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=de--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor\u2019s Reading Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/17\/622-cves-prioritize-over-panic-patching\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/cover-hero-15-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Reading Tip<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">622 CVEs: Prioritize, Don\u2019t Panic-Patch<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/17\/nis2-patchwork-four-states-face-eu-court\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/cover-hero-13-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Reading Tip<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">NIS2 Patchwork: Four States Head to the ECJ<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/17\/cicd-published-asyncapi-botnet-loader\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/cover-hero-12-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Reading Tip<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">CI\/CD Leaked the AsyncAPI Botnet Loader<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/07\/21\/copilot-adoption-eigenversuch\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-copilot-adoption-eigenversuch-20156955.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">The Copilot Shift: First, the People Had to Come On Board<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/bfsi-back-office-automatisierung-ibpm-banken-iron-mountain\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-bfsi-back-office-automatisierung-ibpm-ba-13429849-250x143.png\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Faster Back-office Operations: How Banks Are Finally Gaining Control Over Document-heavy Processes<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/kimi-stoppt-abos-7-checks-fuers-ki-capex\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-kimi-stoppt-abos-7-checks-fuers-ki-capex-34500327-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Kimi Halts Subscriptions: 7 Checks for Your AI Capital Expenditure<\/span><\/span><\/a><\/p>\n<p style=\"font-style:italic;text-align:right;font-size:0.85em;color:#888;margin-top:8px;\">Image source: AI-generated (July 2026)<\/p>\n<p><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"Cyberattacks on German businesses are becoming more targeted. Cyber resilience means prioritizing: closing API attack surfaces, managing patch windows, and testing recovery &#8211; without panic narratives. Key Takeaways Up to 37 million customer records &#8211; primarily phone numbers and account details &#8211; are estimated to have been stolen by cybercriminals and offered [&hellip;]","protected":false},"author":50,"featured_media":3218,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cyberattacks","_yoast_wpseo_title":"Cyberattacks: The Biggest Waves Are Yet to Come","_yoast_wpseo_metadesc":"Cyberattacks: Protect your business with proven cyber resilience strategies. Stay ahead of threats\u2014act now to secure your company\u2019s future.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3214"],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-7112","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":3214,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7112"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7112\/revisions"}],"predecessor-version":[{"id":22518,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7112\/revisions\/22518"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3218"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7112"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}