Backups are no protection: How ransomware attacks really work and why recovery alone is not enough 

In many medium-sized businesses, there is a supposedly reassuring assumption: should a ransomware incident occur, you simply restore from backups and business carries on as normal. For a long time, this notion was not entirely unfounded. Until around 2022, ransomware was, at its core, essentially an encryption problem. Attackers would lock files, demand a ransom, and anyone with clean, up-to-date backups could weather the incident relatively unscathed. 

But those days are over. Modern ransomware attacks are multi-stage operations in which encryption is often merely the final, visible step in a much longer process. Anyone who continues to base their security strategy solely on recovery is defending against a threat that hardly exists in this form anymore. A look at the individual phases reveals how an attack actually unfolds today and why backup has become one of several building blocks rather than the sole lifeline. 

This is how a modern ransomware attack really unfolds 

A ransomware attack rarely begins with a loud bang. The initial entry is usually inconspicuous, for example via exploited software vulnerabilities, compromised login credentials or a well-crafted phishing email. According to the Verizon Data Breach Investigations Report 2026, the exploitation of vulnerabilities has now become the leading entry vector, accounting for 31 per cent of all security breaches – a significant increase from 20 per cent the previous year. By comparison, the misuse of stolen login credentials has declined slightly. This shift points to an approach that prioritises speed and scalability rather than conspicuous malware campaigns. 

Initial access is not usually followed by immediate encryption. Instead, attackers move inconspicuously through the network for weeks, expanding their privileges and gaining an overview of the infrastructure. Various expert analyses estimate the average time between initial access and actual encryption at around five to eleven days, though in many documented cases it is significantly longer. This is the phase where the crucial steps take place: 

  • Lateral movement: Attackers explore the network and identify valuable systems. 
  • Targeted search for backups: Network drives, NAS systems and even cloud synchronisations are tracked down so that they can be specifically encrypted or deleted at a later stage. 
  • Data exfiltration: Before any encryption even begins, sensitive data is copied and transferred to the attackers’ own infrastructure. 
  • Preparation for encryption: Only once backups have been compromised and data secured is the actual ransomware deployed. 

It is only at the end of this chain that victims perceive what they recognise as ‘the attack’: encrypted systems and a ransom demand. For your defences, this means one thing above all: there is a window of opportunity lasting days, or in some cases weeks, during which an attack could be detected and stopped before anything is encrypted at all. It is precisely this window that is scarcely utilised by traditional security approaches designed purely for recovery. 

Double Extortion: Why recovery does not solve the real problem 

The reason why a functioning backup is no longer sufficient today lies in what is known as ‘double extortion’. In this now dominant tactic, attackers not only encrypt your systems, but also specifically steal data beforehand and threaten to publish it. According to the BSI Situation Report 2025, around 72 per cent of all ransomware attacks now follow this pattern. 

The consequences for those affected are severe: even if you have flawless, up-to-date backups and can restore operations within hours, you have not escaped the actual extortion. Your stolen customer, staff or contract data remains in the attackers’ possession, and no recovery strategy can prevent its publication on the dark web. Added to this are potential reporting obligations to regulatory authorities and those affected, as well as the reputational damage, which often weighs more heavily than the actual operational downtime. 

Even paying the demanded ransom is not a reliable solution. A study by HYCU and ActualTech Media shows that, whilst around 60 per cent of companies that comply with the initial ransom demand do initially regain access to their data, almost a third have to make a further payment before recovery is even possible, and 8 per cent remain unable to access their data even after payment. And even if a decryption key is provided, the technical restoration of the systems often takes several weeks in practice. 

Why backups are still systematically targeted 

The fact that backups are a key target for attackers is no coincidence, but rather an integral part of modern ransomware campaigns. As described, professionally organised groups often spend weeks undetected within the network. During this time, they specifically search for accessible backups and destroy or encrypt them before the actual attack begins. In such a scenario, a backup that is accessible via the normal network no longer offers reliable protection. 

Another, frequently underestimated problem is a lack of testing. Whilst many companies formally have a backup strategy in place, they have never actually carried out a full recovery under real-world conditions. In an emergency, it then becomes apparent that backups are incomplete, out of date or simply non-functional. A backup that has never been restored is, in the worst case, merely a hope, not a safeguard. 

The Federal Office for Information Security (BSI) therefore takes a nuanced view of backups: they remain one of the most important preventive measures for restoring data availability in an emergency, but they explicitly do not protect against the theft and publication of data. According to the BSI, the following are particularly important: 

  • separate storage, isolated from the production network (offline or air-gap backups) 
  • regular, documented recovery tests 
  • clear responsibilities and a well-rehearsed contingency plan 

The real key: detecting attacks before encryption takes place 

In light of this development, the most effective lever in defence is shifting noticeably: away from a purely reactive approach after encryption has taken place, towards early detection during the preparatory phase, which often lasts for days. If an attacker is detected whilst they are still moving laterally within the network or exfiltrating data, the actual damage can often be prevented before it even occurs. 

This is precisely where approaches such as Extended Detection and Response (XDR) and Managed Detection and Response (MDR) come into play. XDR collects and correlates telemetry data from endpoints, firewalls, cloud services, email and identity systems, thereby revealing suspicious patterns that individual security tools would overlook. MDR supplements this data set with a Security Operations Centre (SOC) staffed around the clock, which not only analyses incidents but also intervenes actively where necessary. For companies without their own SOC – that is, the majority of small and medium-sized enterprises – this approach is often the most practical way to stop attacks at an early stage, before data is exfiltrated or systems are encrypted. 

This shift is now no longer merely a recommendation but is enshrined in regulation for a growing proportion of German SMEs. With the NIS-2 Implementation Act, documented protective measures – including provisions to maintain operations in accordance with Section 30 of the Federal Information Security Act (BSIG) – have become mandatory for around 29,500 German companies. 

What an effective security strategy actually requires 

The key insight can be summarised simply: a backup is a necessary but not a sufficient measure. It ensures the availability of data, but it prevents neither the initial breach nor the theft of sensitive information, nor the resulting reputational damage. A robust security strategy therefore covers the entire lifecycle of an attack, from prevention through early detection to recovery, and is based on several interlinked layers, including: 

  • consistent patch and vulnerability management 
  • multi-factor authentication for all access points 
  • network segmentation to contain lateral movement 
  • end-to-end detection of suspicious activity (EDR, XDR, MDR) 
  • isolated, regularly tested backups 
  • a documented and practised contingency plan 

The threat landscape in Germany alone demonstrates the necessity of this combination: the BSI Situation Report 2025 recorded 950 registered ransomware attacks, 80 per cent of which targeted small and medium-sized enterprises. Trend Micro’s Cyber Risk Report 2026 counted 433 confirmed ransomware incidents in Germany in 2025, placing the country among the three most severely affected nations worldwide, behind the US and Canada. 

Anyone who continues to rely solely on their backup in this environment is defending against yesterday’s attack. The more effective approach begins much earlier, with the detection of an attacker, long before the first file is encrypted. 

Early detection with NovaMDR™ 

This is precisely where NovaMDR™ comes in. Rather than relying on recovery after a successful attack, the service continuously monitors the IT environment and highlights suspicious activity whilst an attacker is still moving within the network, expanding their privileges or gathering initial data – in other words, during the critical window of days or weeks that determines the outcome of an attack. 

What NovaMDR™ offers SMEs 

  • 24/7 monitoring by a Security Operations Centre, without you having to set up your own internal SOC team 
  • Detection of suspicious patterns across endpoints, the network and other systems, rather than isolated individual alerts 
  • Active intervention in the event of an incident to stop lateral movement and data exfiltration at an early stage 
  • An approach specifically tailored to the resources and structures of SMEs in the DACH region 

Backup and MDR as a complement, not an alternative 

NovaMDR™ does not replace a backup strategy, but fills the gap left by recovery strategies alone. Whilst well-tested, isolated backups ensure the availability of data, early detection ensures that, in the best-case scenario, data theft and encryption do not occur in the first place. For companies that are already obliged to implement documented protective measures under NIS-2 and Section 30 of the BSIG, this approach can also be directly integrated into the required audit trail. 

Conclusion 

Ransomware is therefore no longer a one-off encryption incident, but a multi-stage operation that often begins days or weeks before the actual attack and specifically targets backups as well. Double extortion further ensures that even a complete recovery does not eliminate the risk of extortion as long as stolen data remains in circulation. 

A backup therefore remains indispensable, but is no longer sufficient as a stand-alone strategy. It is crucial to detect attackers during the preparation phase, before data is stolen and systems are encrypted. It is precisely this shift from mere recovery to early detection that medium-sized enterprises should be making now. 

Phishing 2.0: Why staff training is no longer enough to combat AI-powered attacks 

One click, one incorrect bank transfer, one compromised account: phishing has been one of the biggest risks to your business for years. What is new, however, is the speed and sophistication with which attackers operate today. Artificial intelligence has turned a familiar problem into a threat that renders many of your established protective measures ineffective. If, as a security manager, you are still relying on annual awareness training covering traditional warning signs, you are protecting your business against a threat landscape that is a thing of the past. 

The figures speak for themselves 

Recent analyses by Dashlane show just how significant this leap really is: AI-generated phishing emails now have a success rate of 54 per cent, compared with just 12 per cent for traditional, manually created campaigns. Since the launch of ChatGPT at the end of 2022, global phishing volumes have risen by 4,151 per cent, and business email compromise now accounts for 73 per cent of all reported cyber incidents.  

Attackers are no longer limiting themselves to traditional email: smishing, vishing and deepfake attacks via video are also becoming noticeably more prevalent. This is particularly problematic for your existing awareness programme: AI-generated messages are increasingly free of typos and stylistic inconsistencies – precisely the characteristics on which traditional training courses base their detection guidelines.

Social Engineering 2.0: How AI is changing attackers 

According to estimates, social engineering is behind up to 98 per cent of all cyberattacks. The actual vulnerability is therefore rarely the technology, but rather the people with whom you and your colleagues work on a daily basis. Generative AI is now changing the way in which this vulnerability can be exploited – both more precisely and more convincingly. Attackers analyse publicly available information about their targets and adapt their messages in real time to the victims’ behaviour, for example if they initially hesitate.  

Among the established forms of attack that are taking on a new dimension thanks to AI are, in particular, classic mass phishing, personalised spear-phishing, the compromise of business email accounts by exploiting real-world power dynamics, and pretexting, in which attackers invent convincing pretexts to gain targeted access to sensitive information. According to estimates, AI-assisted attackers can work around 40 per cent faster whilst simultaneously generating significantly more convincing content – a gain in efficiency that benefits criminals alone.  

Deepfakes and voice cloning take attacks to a new level 

The threat becomes even more serious when AI no longer just forges text, but also voices and images. Just a few seconds of audio material is enough to convincingly clone an executive’s voice and persuade your staff to make bank transfers over the phone. A case from Hong Kong illustrates just how real this threat already is: an employee took part in a video conference in which supposedly familiar colleagues were present. 

In fact, they were all AI-generated deepfakes, which persuaded him to make a bank transfer of around 25 million US dollars. 

This development is not an isolated incident, but part of an industry-wide trend: identity-based attacks are set to be the dominant form of threat by 2026, as generative AI enables hyper-personalised phishing, automated attacks on login credentials on an industrial scale, and deepfake attacks that are virtually impossible for humans to recognise as fakes. At the same time, the barrier to entry for attackers is continuing to fall: AI now allows even less technically savvy criminals to carry out operations that were previously the preserve of state-sponsored actors. So do ask yourself: would you be able to recognise a video call from your senior management as genuine beyond any doubt today?  

A record-breaking wave of attacks MEs – in most cases

Recent real-world incidents show that this trend is not slowing down but accelerating. In March 2026, the coffee chain Starbucks reported a serious data breach. Attackers had gained unnoticed access to the internal human resources management system via fake login portals, without using any traditional malware. At the same time, the Bergisch Chamber of Industry and Commerce warned of mass mailings of fake emails in which fraudsters posed as Chamber staff and, under the pretext of a data check, requested updates to bank details – complete with forged logos, portrait photos and signatures to maximise credibility. 

For the remainder of 2026, you should expect a further increase and refinement of such attacks, as AI automation reduces preparation time whilst the personalisation of messages increases at the same time.

Why traditional awareness training is reaching its limits

This highlights why many existing training programmes in your organisation may be falling on deaf ears. Three technical developments make modern attacks particularly dangerous: AI analyses publicly available profiles, LinkedIn data and previous data breaches, and uses this to compose messages that are precisely tailored to the target’s role, tone of voice and current projects. A few seconds of audio material are used to create a deceptively real voice, turning a purported call from senior management into a tool for CEO fraud. And fake video calls featuring deceptively realistic-looking line managers put your staff under pressure in real time, for example to authorise urgent bank transfers.  

The result: typos, awkward forms of address or inappropriate corporate wording – in other words, precisely those warning signs on which traditional training programmes are based – simply no longer exist in this form. Whilst awareness remains an important component of your security strategy, it can no longer be the sole line of defence. 

A culture of caution rather than isolated identifying features

One detail that may come as a surprise at first glance: a total of 197 different ERP systems were identified in the sample. This is If attacks can no longer be reliably identified by external characteristics, you must also shift the focus of your prevention measures. Instead of concentrating exclusively on obvious signs of phishing, it is advisable to establish a fundamental culture of caution throughout the organisation.  

It is crucial that every incoming communication is scrutinised critically:  

  • Why would this message come from this particular person?  
  • Did you actually sign up for this webinar?  
  • Doesn’t this offer sound too good to be true?  

Encourage your teams to make a habit of asking precisely these kinds of questions. The focus should be more on the contextual content of a message than on its outward form. To ensure that such a culture really takes hold in your day-to-day working life, you need regular and compulsory training sessions. One-off compulsory sessions are not enough.

The technical foundation: authentication and simulation

However, awareness and culture alone are not enough if the technical infrastructure in your organisation is not up to scratch. As the task of detecting fake messages can no longer be left solely to humans, a key lever lies in the technical protection of your own domains: correctly implemented SPF, DKIM and, above all, a consistently enforced DMARC make it considerably more difficult for attackers to misuse your brand for phishing. Combined with clear approval processes for payments and a modernised awareness programme, this creates a significantly more robust level of protection.  

In addition, regular phishing simulations have become an integral part of modern security strategies. If you use Microsoft 365, you can, for example, utilise the integrated attack simulation training provided by Microsoft 365 Defender. In addition, specialised solutions such as SoSafe’s phishing demo or KnowBe4’s free Phishing Security Test have become established on the market. Such simulations show you, under realistic conditions, how your staff actually react to suspicious messages, thereby providing the data needed to refine your training content in a targeted manner, rather than adopting a one-size-fits-all approach. 

How Managed Detection and Response provides additional protection 

However, even the best combination of awareness, organisational culture and technical prevention cannot prevent every attack, precisely because AI-powered attacks have become so targeted and varied that a single successful click within your organisation remains a possibility at any time.  

This is where Managed Detection and Response (MDR) comes in: through continuous monitoring of the network, endpoints and access patterns, it can detect suspicious activities following a successful phishing or social engineering attack – such as unusual login attempts, conspicuous data access or suspicious account activity – before any significant damage occurs. MDR thus complements your preventative measures with an effective second line of defence that kicks in precisely when prevention alone has not been sufficient. 

Conclusion

AI has transformed phishing from a mass phenomenon with recognisable vulnerabilities into a highly personalised threat that is now almost impossible to detect. If you want to protect your business effectively, a fundamental rethink is essential: practical, recurring training sessions rather than one-off compulsory events; a company-wide culture of vigilance; consistently implemented technical safeguards such as DMARC and phishing-resistant authentication; and continuous monitoring that responds as soon as something does slip through. Only by combining these elements can the growing threat posed by AI-powered social engineering be effectively contained. 

SMEs choose SMEs: What a new study on the German IT market reveals

A recent study by the University of Potsdam shows that almost half of all small and medium-sized enterprises (SMEs) in Germany rely on solutions from the SME IT sector for their ERP software. What lies behind this, what does it mean for you as a decision-maker, and why is this topic more relevant than ever?

Who actually supports whom?

German SMEs are regarded as the backbone of the economy. That may sound like a cliché, but if you take a closer look at the figures, it quickly becomes clear that this is simply the reality. And within this backbone, there is a relationship that hardly anyone speaks about openly: that between SME users and the SME IT sector.

The Bundesverband IT-Mittelstand e.V. (BITMi) raised precisely this question and commissioned the Chair of Business Informatics at the University of Potsdam to provide an empirical answer. The results have been available since May 2026, and it is worth taking a closer look.

What the study examined

The research team led by Prof. Dr.-Ing. Norbert Gronau analysed a sample of around 2,500 companies. The methodological approach: using ERP systems as a proxy. The reasoning behind this is as simple as it is compelling.

ERP (Enterprise Resource Planning) software is the most widely used standard business software of all. It integrates accounting, stock management, CRM, production and more into a central platform. And because ERP providers typically offer a whole ecosystem of complementary solutions, the choice of ERP system provides a reliable indication of whether a company tends to rely on solutions designed for large corporations or on software tailored for SMEs.

For the study, two groups were clearly defined: the SME user base comprises companies with fewer than 1,000 employees. The SME IT sector on the supplier side consists of software companies with fewer than 500 employees, characterised by close customer relationships and specialisation.

The sample covered a total of over 4.6 million jobs, 72.5% of which were in SMEs. This provides a solid basis for reliable conclusions.

The key finding: almost one in two chooses SME IT providers

Among the 1,662 SME ERP user companies in the sample, 44.3% rely on solutions from SME IT providers, whilst 55.7% use corporate ERP systems such as SAP or Microsoft Dynamics. At first glance, this may appear to be a clear majority in favour of the large providers. But when you consider the marketing budgets, sales organisations and brand awareness that these large corporations bring to bear, holding on to almost half the market is a truly extraordinary achievement.

Particularly noteworthy is the reach of these SME solutions: they are used across all company sizes, and even among large enterprises, the share remains at over 20%. SME software is therefore no longer a niche topic for small businesses.

SMEs buy from SMEs – in most cases

An interesting finding from the study concerns selection behaviour by company size. There is a clear trend: users prefer IT providers from their own size category. Micro-enterprises are more likely than average to opt for software from smaller providers, whilst large enterprises tend to favour products from major corporations.

Looking at the percentages, the shift is clearly visible:

  • Micro-enterprises (< 10 employees): 48.8% use SME ERP
  • Small enterprises (< 50 employees): 52.9%
  • Lower-tier SMEs (< 250 employees): 46.6%
  • SMEs (< 500 employees): 37.8%
  • Upper-tier SMEs (< 1,000 employees): 28.9%
  • Large enterprises: 22.5%

What is striking is that even among upper-tier SMEs and large enterprises, SME ERP solutions are by no means insignificant. This speaks to the quality and performance of these providers.

Relevant across all sectors, not just in mechanical engineering for your IT team

Another key finding of the study: SME IT providers are by no means insignificant in any major sector. Whether in chemicals, electrical engineering, food, retail, property or IT services themselves, they hold significant market shares across the board.

As expected, they are particularly well represented in traditional SME sectors such as the service sector, metalworking and retail in general. Only in the automotive industry, where corporate group structures dominate, is their share somewhat lower. But even there, they are present.

This shows that SME IT companies do not have a specific home sector; they are generalists with deep specialisation.

Diversity as a strength: 197 different ERP systems in use in the supply chain

One detail that may come as a surprise at first glance: a total of 197 different ERP systems were identified in the sample. This is not a sign of fragmentation or chaos. It is a sign of diversity and competition.

On the supplier side, most of these systems come from small and medium-sized enterprises:

  • Small enterprises (< 50 employees): 56 different systems (28.4% of all suppliers)
  • Lower mid-market (< 250 employees): 63 systems (32.0%)

Together, these two size categories already account for 60% of all ERP providers on the market. Large corporations with more than 1,000 employees, on the other hand, make up only 13.2% of providers, but naturally account for a significant proportion of installations due to their widespread use.

What this means for you as a decision-maker

If you are currently considering a new software infrastructure for your company, or if your ERP system is getting on in years, this study sends a clear message: the market for medium-sized IT providers is capable, diverse and trustworthy. Opting for a large corporation’s solution is not automatically the safest choice, and choosing a medium-sized provider is not a compromise.

At the same time, you should bear in mind a question that the study does not explicitly answer, but which is directly related to it.

And then there is the issue of security

Software decisions are IT decisions. And today, IT decisions are always security decisions as well.

So whether you opt for a corporate-level solution or a medium-sized ERP platform: any system integrated into your business processes is also a potential point of attack. Ransomware, data breaches, compromised supply chains – these are no longer abstract scenarios. They affect companies of all sizes, across all sectors, on a daily basis.

Medium-sized companies in particular face a specific challenge here:

IT resources are limited, yet the threat landscape is complex. For most, operating their own Security Operations Centre (SOC) is simply not cost-effective.

This is precisely where Managed Detection and Response (MDR) comes in. Instead of building up in-house capacity – which is rarely cost-effective to operate in the long term – a specialist provider takes over the continuous monitoring, detection and response to threats. With NovaMDR™, we offer exactly that: an MDR solution consistently tailored to the needs of SMEs, without the complexity of large corporations, but with full SOC support. SMEs protecting SMEs, if you like. The same logic demonstrated by the BITMi study for ERP software therefore also applies to cybersecurity.

Conclusion: SME IT is not a stopgap solution; it is a conscious choice

The University of Potsdam study highlights what many in the field have long known: SME IT is structurally deeply embedded in the fabric of the German economy. Almost one in two SMEs relies on its solutions, across all sectors and company sizes, with a tendency towards loyalty.

This is no coincidence. It is the result of customer focus, specialisation and an understanding of what really drives SMEs. IT providers who think in terms of SMEs – rather than corporate structures – are able to connect with their customers’ language, requirements and pace.

For you and your business, this means: when making your next software decision, be sure to consider SME providers as well. Not out of solidarity, but because the figures show that it pays off.


Gronau, N. (2026). Wie stark trägt der IT-Mittelstand den deutschen Mittelstand? Untersuchung für den Bundesverband IT-Mittelstand e.V. (BITMi). Universität Potsdam, Lehrstuhl für Wirtschaftsinformatik. 

The WhatsApp Spyware Crisis: Why a fake update is the cleverest hack of 2026

In early April 2026, WhatsApp officially alerted approximately 200 high-value individuals – including corporate executives, journalists, and government officials—that they had been targeted by a highly sophisticated spyware campaign. The method was deceptively simple: attackers used counterfeit versions of the app to trick targets into installing a “critical security update” outside of official stores. For Small and Medium-sized Enterprises (SME), this isn’t just a tech headline; it’s a direct warning that the most responsible behavior of your staff—maintaining device security—is now being weaponized by hackers to bypass enterprise defenses.

The irony of security: A trap for the conscientious

Imagine this scenario: An employee wants to ensure their work mobile is protected and sees a professional-looking notification for a WhatsApp update. Nothing unusual at first glance. Out of habit and a sense of duty, they click ‘Install’ to keep the device up to date. In that single second, your corporate perimeter is breached. The irony in 2026 is brutal: it’s precisely the attempt to ensure security that opens the door to the spy. A compromised phone no longer just means the loss of private data; it’s basically a cloned master key to your financial systems and customer databases.

Shadow IT: The invisible crack in your defences

In Germany, business flexibility and success are based on hybrid working and BYOD (Bring Your Own Device). But when employees use the same device for private chats and sensitive company emails, this security boundary disappears. Such incidents reveal the hallmark of modern attacks: hackers no longer try to ‘break through’ your firewall; they simply ask your employees for the ‘key’ through psychological manipulation. For many German SMEs, this invisible breach turns into an irreversible act of industrial espionage through an unconscious tap.

Why your current security is just an alarm, not a security guard

Many company managers believe that basic antivirus software is sufficient. But there is a crucial difference: traditional software is like an alarm system. It makes a noise, but if no one reacts at 3:00 am, the thief gets away anyway. Furthermore, if your employee manually clicks ‘Allow access’, the software assumes it’s a legitimate human decision and remains silent. In a typical SME, IT resources are limited. Without continuous monitoring, an attack at the weekend gives hackers a 48-hour head start to steal your data.

Why you should choose NovaMDR™

Professional response as your competitive advantage

As purely technical defences have reached their limits, you need a dynamic solution that combines technology with human intelligence. This is where Managed Detection and Response (MDR) comes into play. Our MDR service creates an intelligent shield through bespoke behavioral modeling. We do not believe in ‘one-size-fits-all’ solutions. Instead, our platform learns your company’s unique ‘digital DNA.’ If an employee’s device shows atypical data flows (even if the software has a ‘legitimate signature’), our system raises the alarm immediately.

The final line of defence with local experts

Important: Cyberattacks don’t stick to office hours, and your team needs breaks. If an employee triggers a high-risk alert outside working hours, you shouldn’t have to wade through English manuals or wait for a response from an overseas call center. Our local German-speaking experts intervene in real time. We don’t just send you a simple message; we act as your 24/7 security service, blocking the threat before it spreads. The service integrates seamlessly into your existing architecture and guarantees security without slowing down productivity.

Your Legal Shield and the Executive Bottom Line

As an entrepreneur or executive, you face not only technical risks but also personal liability. Under the GDPR and the stricter NIS2 guidelines of 2026, directors can be held personally accountable for security failures. The audit logs provided by MDR are more than just a defence: they offer you legal proof of your duty of care. This compliance-compliant approach demonstrates to regulatory authorities that you have implemented ‘state-of-the-art’ measures to fulfill your management responsibilities.

Leave security to the professionals so you can focus on your business

Last week’s WhatsApp attacks show that hackers have mastered the art of human manipulation. For German SMEs, future security is not about “preventing every click”, but about “responding professionally as soon as a click occurs.” With MDR, you take the burden of 24/7 vigilance off your employees’ shoulders. In an era of increasing digital uncertainty, professional real-time protection is not an expense. It’s your most stable business investment.

What is Infostealer Malware? 

Infostealers are a type of malicious software (malware) designed to infiltrate computer systems and steal sensitive information. They collect various types of data that are used by cybercriminals to gain access to restricted data, such as 

  • Login credentials 
  • Bank/Card information 
  • Personal data (home address, security number, phone number, etc.) 
  • Browser history data and cookies information 
  • Crypto wallets and keys 
  • Device-specific details (OS name, version, IP, installed software, etc.) 

Infostealers are the most frequent type of attack in 2025 

In 2024, infostealer malware infected approximately 4.3 million devices, compromising around 3.9 billion credentials, including passwords and other sensitive data. 

  1. Malware-as-a-Service on the rise 

Underground forums represent a great source for potential hackers with minimal technical expertise to purchase this type of service (malware-as-a-service). 

  1. The rise in cryptocurrency adoption 

As the acceptance of cryptocurrency expands globally, hackers stand to gain significant returns on investment by obtaining wallet/key information. 

  1. Remote workforce & more online accounts than ever 

People manage more online accounts and digital assets than ever before, and with more employees working from home on potentially less secure networks, it creates the perfect storm conditions for hackers to exploit. 

How do Infostealers get in? 

1. The classic bait and switch with phishing attackers distributing malicious payloads through deceptive communications. 

These often take the form of malicious document attachments that exploit application vulnerabilities when opened. They also employ links directing users to credential harvesting sites or malware downloads disguised as legitimate resources.  

2. Compromised Websites  

Hackers can unknowingly distribute malware on regular websites. Some attacks automatically download malicious files when you simply visit an infected site. 

Harmful ads placed on legitimate websites can redirect visitors to dangerous content. Software downloads may contain hidden malware alongside the intended program. 

3. Social Engineering  

Criminals may pretend to be technical support staff to convince victims to grant them remote access to computers. Deceptive messages on social media platforms exploit existing relationships to spread malicious links. Public QR codes can also lead individuals to risky websites. 

4. Trojan Horse in Supply Chain  

Attackers often target the software development and distribution process, which may alter legitimate software updates to include malicious code. Many applications’ development libraries and components are also susceptible to compromise. 

Most popular Infostealer variants 

RedLine Stealer 

RedLine Stealer was frequently cited as one of the most dominant infostealers throughout 2023 and 2024. One report indicated it was responsible for 43% of observed infostealer infections in 2024. It targets credentials, cookies, credit card details, FTP clients, cryptocurrency wallets, and specific files.

LummaC2 Infostealer 

LumnaC2 saw a significant surge in detections in late 2024. Reports indicate massive increases in detections (e.g., a 369% increase from H2 vs. H1 2024, according to ESET), and it’s often listed among the top 3 most prevalent stealers. It targets crypto wallets, browser data (profiles, cookies, credentials), 2FA extensions, and system information. 

Rise Pro  

Rise Pro is one of the most significant stealers, according to some reports (e.g., Kaspersky data places it second only to RedLine for 2024 infections). 

Racoon Stealer 

While its main developer was arrested, leading to a temporary dip, updated versions emerged, and it remains a frequently mentioned threat, particularly noted in some regional reports (like LACNIC for Latin America/Caribbean) and historical data. It steals a wide range of credentials and crypto wallets. 

What IT Managers Can Do Today to Protect Against Infostealers 

  • Start by disabling browser-based password storage across all endpoints and enforce the use of enterprise-grade password managers. This helps eliminate one of the most common data sources targeted by infostealers. 
  • Ensure that MFA is phishing-resistant by using hardware tokens or app-based push notifications rather than SMS codes. 
  • Next, segment your high-risk and legacy systems. Machines running outdated operating systems or OT equipment that can’t support modern EDR agents should be isolated using firewall rules and VLAN segmentation to prevent lateral movement. 
  • Secure endpoint and browser configurations by removing unnecessary software and plugins. Block installation of unsigned apps or browser extensions not vetted by your team. This reduces the potential attack surface significantly. 
  • Proactively monitor early signs of infostealer activity. Watch for unusual outbound connections, reuse of credentials from unknown IPs, or browser processes behaving abnormally. 
     

Traditional antivirus and firewall solutions aren’t built to detect credential theft as it happens. That’s where Managed Detection and Response (MDR) comes in. 

With solutions like NovaMDR, small and medium-sized businesses can gain:

  • We conduct 24/7 behavioral monitoring of endpoints, networks, and cloud activity to detect abnormal data exfiltration in real-time. 
  • We ensure expert validation of threats to prevent false positives from overshadowing genuine alerts. 
  • We detect credential theft by spotting anomalies such as logins from new geographies, cookie harvesting behaviors, and password dumping tools. 
  • We deliver immediate response capabilities such as isolating infected endpoints, halting suspicious processes, or triggering password resets. 

Ready to stop infostealers before they ruin your business? Check out NovaMDR

Advanced Persistent Threats: Protecting German Manufacturing with Managed Detection and Response

Advanced Persistent Threats, or APTs, are attacks that breach networks to gain access to valuable data. To put into scope the challenges Germany and others are facing, look no further than the growth in the APT protection market.

The Advanced Persistent Threat Protection market will reach $14.6 billion by 2025, with a CAGR of 16.1% from 2020 to 2025.

The market of cybersecurity solutions designed to address APT attacks is growing because the threat continues to expand across all industrial sectors and countries. Ransomware, Denial-of-Service (DoS) attacks, and intellectual property theft are attack vectors used by APTs.

ForeNova, a global provider of managed detection and response (MDR) services, understands the growing problem of APTs targeting high-value industries in Germany. These APTs focus on value data, including intellectual property theft.

German manufacturing firms look to MDR providers like ForeNova for help with 24/7 monitoring, automated incident response, and greater observability of APT threats.

Interested in learning more about ForeNova’s NovaMDR platform offering?

Click here to schedule a demo with the ForeNova engineering team today!

Impact of APTs on the Manufacturing Sector in Germany?

Bitkom announced a projected cost of 206 billion euros ($224 billion) for IT theft, data breaches, espionage, and sabotage in Germany during 2023. This report marks the third year in a row exceeding 200 billion euros, according to a survey of over 1,000 companies.

State-sponsored cyberattacks against high-value German manufacturing is second only to industrial espionage. Both attack vectors continue to increase in complexity and sophistication.

Buried within attack vectors resides complex automated kill chains leveraging adversarial AI tools. These kill chains combine several simulated attacks, including:

  • Distributed Denial of Service against edge architectures, including web portals, Zero-trust, and SASE-based instances.
  • Advanced email attacks against manufacturing site managers, production teams, and operations groups are very common.

Manufacturing in Germany continues to rise in ransomware attacks from email phishing with the endgame of extorting manufacturing firms, shutting down critical production systems, or redirecting global supply orders to the wrong suppliers.

The kill chain also contains social engineering attacks, physical intrusions, and constant threat of insider threats.

Rise in Insider Threats Within Manufacturing

Manufacturing firms face a dual challenge: Network users can exfiltrate crucial data, risking operational disruptions and production slowdowns while companies investigate these attacks.

Dealing with State-Sponsored APT Group

State-sponsored attacks bring an additional dimension to attack surfaces. China, Russia, North Korea, Vietnam, Nigeria, South Africa, and other nation-states all contribute to the APT nightmare globally.

ATP groups funded by nation-states present several challenges for cybersecurity teams across all industries. Most of these groups are well-funded, have access to state-sponsored cybersecurity research material and tools, and a resource pool of talent within these countries’ military forces.

MuddyWater: APT34

This Iranian group targets energy and defense industries, which is widely known.

Fancy Bear (APT 28)

Established in 2004, this Russian-based APT group targets manufacturing and critical infrastructure in the United States and Germany.

Chinese hacker group APT 27

This APT group has targeted German companies in sectors such as pharmaceuticals and technology and successfully stolen valuable intellectual property assets.

APT31: Judgment Panda

Chinese state-sponsored APT group conducts cyber espionage for national interests, employing sophisticated spear-phishing, malware, and zero-day vulnerabilities to target governments, businesses, and political entities globally.

Judgment Panda targets U.S, German, and Hong Kong political figures, critical infrastructure, and industrial manufacturing.

Which Manufacturing Industries in Germany Remain the Highest Value Targets for Hackers?

Previously, APT groups focused their cyberattack efforts on stealing money, committing financial fraud through email phishing, and leveraging ransomware to extort money from their victims.

APT groups that focus on efforts in the German manufacturing sectors do so with the ideas that operational disruptions, stealing intellectual property, and/or committing cyber attacks are far more profitable.

Manufacturers facing unplanned production outages face financial losses of between $900 and $17000 per minute. These same cyberattacks also cause a downstream problem with the supply chain supporting the manufacturing processes.

Hackers targeting high-value manufacturing may choose to embed malware into user devices, host-based application platforms, and robotic control units. These malware files go unnoticed because most devices and hosts receive infrequent software updates.

These well-placed malware files were more than likely introduced through an email phishing campaign.

Automotive

Like other German manufacturing firms, the German automotive industry continues to experience various cyberattacks against its employees, supply chain partners, and networks.

The Volkswagen data breach exposed the information of 800,000 EV customers. In addition to this security breach, Volkswagen also faced intellectual property theft. In 2015, hackers compromised nearly 19,000 documents related to Volkswagen’s research and development projects. However, the company did not report the event until 2024.

Chemical

Two former employees of Lanxess, a chemical factory, stole intellectual property, including trade secrets and information on constructing next-generation nuclear reactors.

The buyers of these trade secrets included a Chinese company that planned to use the stolen information to develop a competing product against Lanxess.

Machinery

Nation-state hackers and hacktivists globally target manufacturing businesses like VARTA.

In February 2024, hackers breached VARTA AG’s systems, disrupting global battery production and impacting its supply chain. Two weeks later, VARTA revealed the real threats and announced a temporary shutdown of IT systems and output for security reasons.

Pharmaceutical

APT 27, a Chinese hacker group known for attacking Western government agencies, also targeted BfV, a German pharmaceutical and technology Company.

“Besides stealing trade secrets and intellectual property, the hackers tried to penetrate customers’ and service providers’ networks to infiltrate several companies simultaneously.”

Researchers also found a new extortion group, Morpheus, active since December 12, 2024, claiming to have compromised Arrotex Pharmaceuticals (Australia) and PUS GmbH (Germany) through data theft.

The Role of Managed Detection and Response (MDR)

MDR providers like ForeNova are critical in preventing APT groups from becoming successful. ForeNova’s expertise in proactive monitoring, observability, automated incident response, and threat modeling helps protect clients from a wide range of cyberattacks.

NovaMDR, ForeNova’s groundbreaking service, ingests log data from endpoint devices, Microsoft M365, and other sources. Leveraging the AI and ML functions, NovaMDR processes the data in real time and helps detect attacks quickly. This quick reaction capability, combined with the log data processing and automated incident response, helps contain even the early signs of a ransomware attack.

NovaMDR’s ability to handle these early signs of action also reduces the human resource cost of incident response. Organizations that leverage firms like ForeNova can reallocate human capital resources to other parts of the organization.

Benefits of Implementing MDR in Manufacturing

Leveraging NovaMDR for manufacturing creates many positive engagement models. Automotive manufacturers seeking to comply with TISAX can leverage NovaMDR to help monitor critical cybersecurity controls protecting the various supply chain connections and applications required under this compliance mandate.

Chemical manufacturing firms in Germany could also use NovaMDR to monitor intrusion prevention tools, firewalls, and email systems that target Internet-of-things (IoT) devices that control chemical compound distribution systems, environmental controls, and flow control systems.

German machinery firms migrating to industrial 5.0 robotics and automation controls could benefit from having ForeNova monitor these devices. Hackers using ransomware malware attempt to gain control of the computer control units for these automated tools, which can shut down operations entirely. NovaMDR’s ability to process log data in real time and leverage automated incidents can protect machinery’s production line systems from cyberattacks.

Like her German manufacturing firms, pharmaceutical firms continue transforming their research platforms globally by promoting great interconnection and collaboration. This transformation comes with an inherent risk. Organizations working together to find a cure for AIDS and COVID-19 become subject to intellectual property theft from insiders. Contractors, disgruntled employees, or even competitors could be among these insiders.

NovaMDR’s ability to process M365 logs helps determine if someone is attempting to copy valuable data to a USB or using email to send files outbound.

Why ForeNova?

Germany has some of the world’s most advanced manufacturing techniques. However, over two-thirds of German companies have been affected by a security breach, as attackers, some suspected of being foreign spy agencies, seek to steal trade secrets.

ForeNova’s expertise in identifying early signs of a persistent threat through email, endpoint, or network channels helps lower the risk for their German manufacturing clients.

Combining the firm’s knowledge of global APT hacker groups, leveraging their artificial intelligence (AI) and machine learning (ML) defensive capabilities, and compliance reporting support, ForeNova continues to become a strategy service partner to help protect their clients in stopping ATP attacks and intellectual data theft.

Immer up to date!

Abonnieren Sie unseren Newsletter und erhalten Sie wertvolle Branchen-Insights, Produkt-Updates und aktuelle Analysen von ForeNova direkt in Ihr Postfach.

Wir verwenden Brevo als unsere Marketing-Plattform. Indem Sie das Formular absenden, erklären Sie sich einverstanden, dass die von Ihnen angegebenen persönlichen Informationen an Brevo zur Bearbeitung übertragen werden, gemäß den Datenschutzrichtlinien von Brevo.