Current threat landscape
How attackers operate today, what role AI tools play – and what protects effectively.
Facts and figures
The threat is real – for small companies too.
119
new vulnerabilities per day (BSI, 7/2024–6/2025)
80 %
of the 950 recorded ransomware attacks hit SMEs (BSI/BKA)
202,4 Mrd. €
damage from cyberattacks in Germany (Bitkom 2025)
71 %
of employees use unapproved AI tools (Microsoft)
Attack vectors
How attackers get in today.
// 01
Phishing – now with AI
AI produces flawless, personalised messages. Spelling mistakes are no longer a reliable warning sign.
// 02
Ransomware with data theft
Data is encrypted and also exfiltrated – with the threat of publication.
// 03
Stolen credentials
A single stolen password is enough if multi-factor sign-in is not enabled.
// 04
Unpatched systems
Firewalls, VPN gateways and internet-facing servers are scanned automatically for known vulnerabilities.
// 05
CEO fraud and deepfakes
Faked voices or videos of executives trigger payments or the release of data.
// 06
Via suppliers and software
Attacks increasingly run through supplier access or compromised software updates.
Shadow AI
Data leaks through AI tools in everyday work.
The biggest AI risk often comes not from attackers but from well-meant use: texts, customer data or source code are “quickly” pasted into a public AI service – and thereby leave the company. A well-known example: in 2023, Samsung employees entered source code and meeting notes into ChatGPT several times within a few weeks.
- Confidential input ends up with external providers and, depending on the service and settings, is stored or reused there.
- Private accounts and free versions are not covered by company rules or a data processing agreement.
- Prompt injection: hidden instructions in web pages, e-mails or documents make AI assistants reveal data or perform actions. The BSI explicitly warns about this.
- AI agents and extensions with access to mailboxes, calendars or files enlarge the attack surface.

Protection
What actually helps.
Most attacks can be made considerably harder with a few consistently implemented measures.
Sources
- BSI – Die Lage der IT-Sicherheit in Deutschland 2025
- Bitkom – Studie Wirtschaftsschutz 2025 (Vorstellung beim BfV)
- Microsoft – Studie zu Schatten-KI (November 2025)
- BSI – Einfluss von KI auf die Cyberbedrohungslandschaft
- t3n – Samsung-Ingenieure schicken vertrauliche Daten an ChatGPT (2023)
Last updated: September 2026. Figures are taken from the publications listed.