New: EU CAPTCHA – GDPR-compliant bot protection. Try it free for 3 months!
Home>
Trending Topics Cybersicherheit – July 2026
SECURITY INSIGHTS | July 31, 2026
Myra's monthly security highlights provide IT executives and security professionals with the most relevant topics from the world of cybersecurity. Current trends, defense strategies, and reports on cyberattacks, attack campaigns, and more are presented here in a clear and concise format.


How aggressively cybercriminals are currently targeting public-sector organizations became clear in July. In Romania, an attacker deleted the country's entire land registry database following a failed extortion attempt, effectively paralyzing the national real estate market. At the same time, recorded security incidents in the state administration of Saxony-Anhalt doubled, and the EU imposed sanctions on a Russian network of intelligence services and cybercriminals. Meanwhile, the German federal government is drawing consequences from the persistently high threat level: a cross-agency cybersecurity program now establishes uniform minimum standards for all federal ministries for the first time.
At the same time, risks and governance questions surrounding artificial intelligence continue to occupy the cybersecurity industry. During test runs, advanced AI models from Anthropic and OpenAI autonomously penetrated the systems of other companies — prompting Germany's Federal Office for Information Security (BSI) to issue a warning: vendors must assign their AI agents clearly defined roles and limited permissions. The BSI's new audit framework "A5" — a standard for trustworthy AI systems — illustrates what this can look like in practice. The European Commission, meanwhile, is preparing emergency measures against the possible blocking of security-relevant AI by third-party states.
The debate around such restrictions once again raises the overarching strategic question of securing digital sovereignty. The study "State of Digital Sovereignty 2026: Uncharted Waters," presented at the Myra event "Bots & Brews," shows that 39.7 percent of surveyed companies are actively adopting European software solutions — nearly double the figure from the previous year (20.4 percent).
IT Security Trends
Europe strengthens AI security: EU Commission unveils action plan against AI restrictions
After the U.S. government temporarily blocked non-U.S. nationals' access to AI models from the provider Anthropic, the EU Commission is responding with an action plan for greater AI security. By the end of the year, contingency measures are to be developed for the event that a third country restricts access to AI with security-relevant cyber capabilities. Plans include EU-wide capacities for evaluating AI models as well as a secure testing platform operated by the EU cybersecurity agency ENISA.
Saxony-Anhalt: Cyberattacks on the state administration double
The number of recorded IT security incidents in the state administration of Saxony-Anhalt more than doubled in the first half of 2026 compared with the same period the previous year — from 14 to 30 incidents. These included 16 phishing attacks, two DDoS attacks, two system intrusions, and nine cases of theft or loss of IT hardware. According to the ministry, DDoS attacks occur more frequently during vacation periods and are increasingly aimed at municipalities as well.
Training budgets rise: German companies invest more in security awareness
Amid the ongoing skills shortage, companies increasingly view cybersecurity training as a strategic investment. According to the ISC2 study "Security Training Trends 2026," 66 percent of German respondents increased their budgets for security training over the past twelve months. The main drivers are AI-supported attacks and the growing need for cloud security expertise.
Cybercrime
Romania: Attacker deletes the country's entire land registry database
Romania's entire land registry database has fallen victim to a cyberattack. Using valid credentials, the attacker gained access to the cadastral authority ANCPI, explored the internal systems, and — after a failed extortion attempt — destroyed all data along with the backups. The incident became public in mid-July. The stolen data was subsequently offered for sale in an online forum. As a result of the attack, Romania's real estate market largely ground to a halt: notaries were unable to certify transactions, and official apps and websites were offline.
EU sanctions Russia over serious cyberattacks and sabotage
The European Council accuses Russia of using a complex network of intelligence services, cybercriminals, hacktivists, and companies to carry out devastating cyber operations, and is responding with sanctions. At the center is "Center 16" of Russia's domestic intelligence service, the FSB, which is said to direct well-known groups such as Turla. The affected countries include Germany, France, Poland, and Finland. In Poland, the unit is alleged to have carried out acts of sabotage against heating plants and rail networks. In Germany, the attacks were primarily aimed at government institutions.
Stadler: Attackers extort millions from the train manufacturer
Swiss rail vehicle manufacturer Stadler became the target of a cyberattack in mid-July. The attacker group Everest gained access to a supplier's technical data via a data-exchange platform and demanded around 10 million Swiss francs in ransom. Stadler refused to pay, declared itself "not extortable," and filed a criminal complaint. According to the company, its own production systems were not affected, and the stolen data is not security-relevant.
Password spraying: 81 million login attempts against Microsoft 365
Within two weeks in June 2026, experts recorded around 81 million login attempts against Microsoft 365 environments; 78 accounts across 64 organizations were compromised in the process. The attackers used credentials from earlier data leaks and bypassed multi-factor authentication (MFA) via an outdated login method. Environments in which MFA was only partially enabled — for individual applications or user groups, for example — were particularly affected. The incident underscores that a second factor only provides reliable protection when it applies to all access paths without exception.
Ernst & Young: Data leak via a third-party support ticketing system
The auditing firm Ernst & Young (EY) is notifying clients of a data leak stemming from an attack on a third-party IT service management platform. Between March 28 and April 12, 2026, an unauthorized third party downloaded documents containing personal and financial data used to prepare tax returns. The anomaly was not discovered until April 23.
Transport for London: Five and a half years in prison for attackers from the "Scattered Spider" group
Two young men were each sentenced to five years and six months in prison for the cyberattack on London's transit operator Transport for London (TfL) in late summer 2024. They belonged to the well-known "Scattered Spider" group. It is only the second conviction under the UK's Computer Misuse Act. The damage to TfL amounts to around 34 million euros. As a result of the attack, all 27,000 TfL employees had to reset their passwords on site, and 148 systems went down.
Cyberattack on the City of Leipzig's IT service provider stopped without system outage
The Leipzig-based IT service provider Lecos, which supplies software solutions and computing capacity for municipalities, was the target of a cyberattack. According to the city administration, the attack was detected and stopped without any IT systems going down. Sensitive data did not fall into the attackers' hands, according to the information provided. The State Criminal Police Office of Saxony is investigating.
Best Practice, Defense & Mitigation
CyberGovSecure: Federal government adopts uniform cybersecurity rules for public agencies
With "CyberGovSecure," the German federal government has adopted a comprehensive program to enhance cybersecurity in public agencies. For the first time, uniform rules apply to all ministries: a new steering group chaired by the Federal Ministry for Digital Affairs sets the direction and works closely with the Federal Office for Information Security (BSI). Concrete measures include uniform device protection, regular vulnerability assessments, and mandatory multi-factor authentication. Additional positions and funding have been requested for implementation. An annual report is to disclose the progress made.
BSI presents "A5" assessment framework for trustworthy AI systems
With the "AI Audit and Assurance Assessment Architecture" (A5), the BSI has published a standardized, modular assessment framework for AI systems as a community draft for the first time. The criteria catalog evaluates AI systems on aspects including robustness, explainability, bias avoidance, and cybersecurity. Methodologically, A5 is modeled on the C5 cloud catalog and the ISAE 3000 assurance standard. A5 addresses the evidence requirements of the EU AI Act and the Cyber Resilience Act. The draft is open for comment until August 31, 2026.
USA: Government launches "Gold Eagle" clearinghouse for coordinated cyber defense
With "Gold Eagle," the U.S. government has launched the first operational program stemming from its AI executive order. The clearinghouse is intended to provide government agencies, critical infrastructure operators, and private companies with a shared platform for the coordinated handling of cyber vulnerabilities. Designed as a "force multiplier," it aims to eliminate duplicate scanning efforts and forward validated vulnerabilities in a targeted manner. Alongside the White House, the U.S. Department of the Treasury, the Department of Homeland Security with CISA, and the Pentagon are involved.
Things to know
Myra study "Uncharted Waters": German companies pivot toward European software
According to the Myra study "State of Digital Sovereignty 2026: Uncharted Waters," only 4.6 percent of German IT decision-makers now categorically rule out European software — down from 47.7 percent the previous year. By contrast, 39.7 percent are currently adopting European solutions, putting Germany narrowly ahead of France and the Nordic countries. The biggest obstacles cited are high migration costs and a lack of awareness of the European alternatives available.
Bundesdruckerei's "Möve" project: an AI safety inspection for public administration
With the project "Möve" (Evaluating Models for Public Administration), the government-owned Bundesdruckerei has created an AI model comparison tailored specifically to the needs of public agencies. Unlike international rankings, Möve evaluates more than 50 large language models against criteria such as performance, security, sustainability, transparency, precise handling of the German language, and compatibility with democratic values. The goal is to help agencies select reliable models and to protect citizens from flawed algorithmic decisions.
Autonomous AI attacks: BSI calls for greater control over AI
Anthropic, the company behind Claude, has acknowledged that its AI models unintentionally accessed the computer systems of three companies during security tests — made possible by a miscommunication with the testing partner that granted the models direct internet access. The incident follows a similar case involving an OpenAI model and is widely regarded by experts as a warning sign of the risks posed by autonomous AI agents. In response, Germany's Federal Office for Information Security (BSI) is calling for AI systems to be secured through clearly defined roles, restricted permissions, and mandatory review mechanisms.
BND and domestic intelligence service set to become "super agencies" with zero-days
A 648-page draft bill from the Federal Ministry of the Interior to overhaul intelligence-service law envisions a massive digital upgrade of the agencies. The domestic and foreign intelligence services would be allowed to act independently in the cyber-operational domain — for example, through active interventions in ongoing attacks and the use of zero-day vulnerabilities. Critics warn that this could relegate the BSI to the role of a mere supplier for the intelligence services. They also see the planned powers as a serious encroachment on digital civil liberties.
Stefan Bordel
Senior Editor
Stefan Bordel has been working as Editor and Technical Writer at Myra Security since 2020. He is responsible for the strategic development and editorial management of all content formats – from website content and specialist publications to whitepapers, social media communication, and technical documentation. In this role, he combines solid expertise from IT journalism with in-depth technical understanding in the field of cybersecurity. As a long-time Linux enthusiast, he closely follows developments in the IT industry both professionally and personally.