Cybercrime has now become part of everyday life for German businesses. According to the Bitkom study ‘Economic Security 2025’, nine out of ten companies were affected by attacks last year. The total damage caused by theft, sabotage and industrial espionage amounted to around 289 billion euros. 70 per cent of this was directly attributable to cyberattacks.
However, cybercriminals by no means rely solely on highly complex technical attacks. Often, a successful attack begins with a fake email, a stolen password or a message that appears to be trustworthy. At the same time, the methods are evolving: attackers exploit security vulnerabilities, compromise service providers and are increasingly using AI to make their attacks faster and more convincing.
Which attack methods should companies keep a close eye on in particular?
Phishing and social engineering: targeting people
A message from Microsoft, an urgent request from senior management or a purported communication from the HR department: in phishing attacks, attackers attempt to trick their victims into revealing login details, opening malicious attachments or clicking on manipulated links.
Phishing remains one of the main entry points for cyberattacks. The European cybersecurity agency ENISA examined a total of 4,875 incidents for its Threat Landscape Report 2025. Among the attacks analysed, phishing was by far the most common initial point of entry, accounting for 60 per cent.
Social engineering is no longer limited to traditional emails. Attackers also use text messages, instant messaging apps, telephone calls and social media. Using information from publicly available sources, they can also tailor their messages specifically to individual people and organisations.
Stolen login details: Gaining access to the company using someone else’s identity
Why go to the trouble of hacking into a system when you can simply log in with a valid password?
Usernames and passwords are particularly valuable to cybercriminals. They can fall into the hands of attackers through phishing, malware or previously disclosed data breaches, for example.
Verizon’s Data Breach Investigations Report 2026 shows just how relevant this method of attack remains: in 36 per cent of the data breaches investigated, the use of stolen login credentials played a part.
The situation becomes particularly problematic when employees use the same or similar passwords for multiple services. Companies should therefore implement technical measures such as multi-factor authentication. At the same time, employees must understand why handling login credentials responsibly and recognising suspicious login attempts are crucial.
Vulnerabilities: Cybercriminals are on the lookout for open doors
Whilst attackers in phishing campaigns specifically target individuals, they do not always require their cooperation. Security vulnerabilities in software, VPN access, servers and other systems connected to the internet are playing an increasingly significant role.
The Verizon DBIR 2026 highlights a particularly clear trend here: the exploitation of vulnerabilities played a part in 32 per cent of the data breaches examined. In the previous report, the figure was 18 per cent – meaning the proportion has almost doubled within a year.
For businesses, this means that updates and security patches must not be unnecessarily delayed. Structured patch and vulnerability management is one of the key components of an effective cybersecurity strategy.
Ransomware: When suddenly nothing works any more
Once access to the company network has been gained, ransomware can be one of the possible consequences. Cybercriminals encrypt data or systems and demand a ransom in exchange for unlocking them. Often, sensitive company data is stolen beforehand as well. Companies are then blackmailed not only with the downtime of their systems, but also with the publication of confidential information.
Ransomware remains one of the most far-reaching cyber threats. In its ‘Threat Landscape 2025’, ENISA identifies it as the threat with the greatest impact in the EU. Verizon’s ‘Data Breach Investigations Report 2026’ also highlights the scale of the problem: ransomware played a role in almost half of the data breaches investigated.
The potential consequences range from production and operational downtime, through data loss, to significant financial losses and damage to reputation.
Supply chain attacks: When the attack comes via third parties
Today, corporations are digitally interconnected with a wide range of service providers, software suppliers and business partners. It is precisely these interdependencies that attackers are increasingly exploiting.
Rather than attacking a well-protected company directly, they compromise, for example, an external service provider and use this to gain access to other organisations.
The Verizon DBIR 2025 highlights just how significant this risk has become: third parties were involved in 30 per cent of the data breaches examined – twice as often as in the previous year.
Cybersecurity therefore does not end at a company’s own boundaries. The security standards of service providers, software vendors and other partners should also form part of risk management.
AI is also changing cybercrime
Artificial intelligence does not just offer new opportunities to businesses. Cybercriminals can also use generative AI to prepare and scale up their attacks.
Phishing messages that appear deceptively genuine can be created in a matter of seconds and translated into numerous languages. Social engineering attacks, as well as manipulated voices, images and videos, can also be made more convincing with the help of AI.
This makes one skill even more important for staff: not simply trusting the professional appearance of a message or a supposedly familiar sender, but critically examining the content, context and any unusual features.
Cybersecurity requires technology – and staff who are aware of the issues
The latest figures show that there is no single ‘typical’ cyberattack. Attackers combine technical vulnerabilities with stolen login credentials, social engineering and malware. Consequently, defences must operate on multiple levels. Firewalls, multi-factor authentication, backups, patch management and other technical safeguards form the basis of effective cybersecurity. However, they cannot prevent every situation.
Employees make security-related decisions every day: Is this link trustworthy? Should I open this file? Is this urgent payment request really from my line manager? What should I do if I notice an unusual login attempt?
This is precisely where security awareness comes in. Regular training helps employees to recognise current attack methods, identify suspicious situations at an early stage and respond correctly in an emergency. For however technical cybercrime may seem, people remain a decisive factor for information security in many areas.
When it comes to delivering systematic and regular training, e-learning is the key format for most organisations. E-learning systems ensure the distribution, delivery and documentation of training courses for relevant target groups.