update page now

New: EU CAPTCHA – GDPR-compliant bot protection. Try it free for 3 months!

Trending Topics Cybersecurity – May 2026

SECURITY INSIGHTS | May 2, 2026

Myra's monthly security highlights provide IT executives and security professionals with the most relevant topics from the world of cybersecurity. Current trends, defense strategies, and reports on cyberattacks, attack campaigns, and more are presented here in a clear and concise format.

Trending Topics Cybersecurity
Trending Topics Cybersecurity

Artificial intelligence is fundamentally transforming the dynamics of attacks in cyberspace. BaFin President Mark Branson warned at the financial watchdog’s annual press conference that AI systems can automatically identify and exploit vulnerabilities in the IT infrastructures of banks and insurers. This requires a substantial acceleration of patch management processes: cycles that were traditionally measured in months will in future have to be completed within days or even hours.

The current cybercrime situation report by the German Federal Criminal Police Office (BKA) backs up this assessment with empirical data. In 2025, a total of 333,922 cybercrime offenses were recorded. Particularly noteworthy is a 25 percent increase in DDoS attacks, which the BKA primarily attributes to intensified hacktivism by pro-Russian groups. This development underscores the geopolitical dimension of the cyberthreat landscape.

At the same time, law enforcement agencies are reporting successful countermeasures: for example, the US Department of Justice has arrested the operator of the Kimwolf botnet and shut down 45 DDoS-for-hire platforms. The botnet was responsible for DDoS attacks with peak volumes of up to 31.4 Tbps. Despite this success, the speed at which attackers are able to build new infrastructures remains a key challenge for the long-term cybersecurity of critical infrastructures.

The top IT security topics in May:

IT Security Trends

Bitkom calls for risk-based EU framework for cloud sovereignty

The industry association Bitkom has published the English-language position paper “Assessing Cloud Sovereignty,” which refers to current initiatives by the EU and the German Federal Office for Information Security (BSI). In it, the association calls for risk-based, technology-neutral and EU-wide harmonized criteria for cloud sovereignty instead of blanket rules.

Swiss federal office plans to exclude US cloud providers from healthcare data project

As part of its planned initiative to digitalize healthcare data, the Swiss Federal Office of Public Health intends to exclude providers that fall under the US CLOUD Act from the outset. The specification for the “SwissHDS” platform requires exclusive applicability of Swiss law as well as independence from foreign legal jurisdictions – a requirement that would in effect rule out Microsoft, Google, AWS and similar providers. The Federal Office for Buildings and Logistics, which is responsible for procurement, also emphasized that highly sensitive healthcare data must be protected from access by foreign authorities.

BKA situation report 2025: Cybercrime in Germany hits record levels

According to the latest BKA cybercrime situation report, authorities recorded a total of 333,922 offenses in 2025, as well as 1,041 documented ransomware incidents (up 10 percent) – although the true scale is likely to be significantly higher. Around 90 percent of ransomware attacks targeted mid-market companies, and the median ransom demand rose by 65 percent. The number of DDoS attacks increased by 25 percent according to the BKA, mainly due to intensified hacktivism by pro-Russian groups.

Financial regulator BaFin warns: AI massively accelerates attacks on financial infrastructures

BaFin President Mark Branson warned at the authority’s annual press conference that AI systems can automatically identify and exploit vulnerabilities in the IT infrastructures of banks and insurers. Patch management cycles that were previously measured in months will in future have to be completed within days or even hours; BaFin announced additional resources and increased supervisory activities.

Myra Bot Management
Myra Bot Management

Cybercrime

Attack on billing service provider: Patient data from several university hospitals stolen

In a cyberattack on an external service provider, data belonging to an estimated 100,000 or more patients of several university hospitals was stolen. Among those affected are university hospitals in Freiburg, Heidelberg, Cologne, Mannheim, Tübingen and Ulm. The compromised service provider, Unimed, based in Saarland, offers billing and documentation services for hospitals. The attack actually took place in mid-April 2026. The affected hospitals subsequently stopped transmitting data to the service provider and promptly informed the relevant data protection authorities as well as the BSI.

Nitrogen ransomware hits Foxconn: 8 TB of data stolen from US plants

Contract manufacturer Foxconn has confirmed a ransomware attack on several of its North American plants, including sites in Mount Pleasant, Wisconsin, and Houston, Texas. The Nitrogen group, active since 2023, has claimed responsibility and says it has exfiltrated more than 11 million files (8 TB) – including confidential project documents from Apple, Nvidia, Intel and Google. Employees temporarily had to resort to pen and paper because systems and WLAN were completely down.

Eurovision in Vienna: Austrian police repel around 500 cyberattacks

During the Eurovision Song Contest in Vienna, Austrian police registered around 500 cyberattacks classified as serious. According to Federal Police Director Michael Takacs, not only the ESC website was targeted but also systems controlling access areas; all attacks were successfully repelled.

Attack on learning platform Canvas affects around 9,000 educational institutions worldwide

The threat group ShinyHunters claims to have gained access to data belonging to around 9,000 educational institutions worldwide in connection with the Canvas learning platform operated by Instructure and is threatening to leak the data. In a separate incident, the login pages of numerous schools and universities on the platform were also defaced. The attackers demanded a ransom for what they claim are around 280 million data records relating to teachers, students and school pupils.

Investigation into ransomware attack on Südwestfalen-IT closed

The public prosecutor’s office in Cologne has closed the case concerning the cyberattack on municipal IT service provider Südwestfalen-IT after around two and a half years due to the inability to identify any perpetrators. On the night of October 30, 2023, attackers encrypted server data. As a result, 22,000 workstations in local authorities were brought to a standstill, around 1.6 million citizens were affected and many town halls were forced to close. Administrative processes had to be handled manually or by fax for weeks. The Akira group claimed responsibility for the attack; its members remain unknown.

After attack on France’s identity authority: 15-year-old arrested

After roughly 19 million data records from the French authority for secure identity documents (ANTS) were offered for sale in an underground forum in April, the competent public prosecutor’s office has now reported an investigative success. A 15-year-old suspect has been arrested and faces a prison sentence of up to seven years and fines of up to 300,000 euros. The minor is alleged to have acted under the alias “breach3d” and personally offered the dataset for sale online.

Best Practice, Defense & Mitigation

German ministry presents roadmap for cybersecurity research through 2027

The Federal Ministry for Research, Technology and Space (BMFTR) aims to sharpen the focus of Germany’s security research and align it with changing geopolitical conditions. As part of a roadmap process, representatives from academia and industry are being involved; the resulting research program is scheduled to launch at the beginning of 2027. The key priorities include artificial intelligence, cryptographic methods, the resilience of government infrastructures and a faster transfer of research results into practical use.

Kimwolf botnet: Canadian operator arrested, 45 DDoS platforms taken down

The US Department of Justice has arrested 23‑year‑old Jacob Butler from Ottawa, Canada, who is alleged to have operated the Kimwolf botnet – a variant of AISURU that infected Android devices via exposed ADB services. Kimwolf is said to have issued more than 25,000 attack commands; the AISURU/Kimwolf botnets were behind record DDoS attacks of up to 31.4 Tbps. At the same time, 45 DDoS‑for‑hire platforms were taken offline.

Federal administration launches cross-ministerial CyberGovSecure program

With the national implementation of NIS‑2, the German Federal Office for Information Security (BSI) has assumed the role of overarching authority for IT security in the federal administration. The new CyberGovSecure program puts this CISO function into practice and consolidates policies, measures and budgets across ministerial boundaries. All federal agencies are involved and remain responsible for implementation within their own remit. A joint reporting framework is intended to make the status of measures and remaining gaps visible across the entire federal administration.

Things to know

10 years of GDPR: Implementation rate rises to 71 percent

A long-term study by the industry association Bitkom shows that 71 percent of companies have now largely implemented the GDPR – compared to just 7 percent when it came into force in 2018. At the same time, 81 percent report that business processes have become more complex, 69 percent see obstacles for AI training, and 63 percent fear that the compliance burden could drive AI developers out of the EU.

About the author

Stefan Bordel

Senior Editor

About the author

Stefan Bordel has been working as Editor and Technical Writer at Myra Security since 2020. He is responsible for the strategic development and editorial management of all content formats – from website content and specialist publications to whitepapers, social media communication, and technical documentation. In this role, he combines solid expertise from IT journalism with in-depth technical understanding in the field of cybersecurity. As a long-time Linux enthusiast, he closely follows developments in the IT industry both professionally and personally.

Similar Articles