Cybersecurity in Flux: Our Experiences and Lessons Learned from a Direct Attack

August 25, 2026 – Reading time: 2 minutes

Our world is changing rapidly. Cyberattacks carried out by organized groups using highly automated artificial intelligence are part of a grim new reality.

We experienced this firsthand towards the end of July when a Chinese hacker group succeeded in accessing one of our employees’ data. We reported the attack to the authorities. After we refused to comply with the group’s demands, the attack was made public.

This attack brought home to us just how important a coordinated set of cybersecurity measures is. Thanks to our ISO 27001 certification, we were able to contain the damage and continue our day-to-day operations without interruption. We have learned from this attack, especially, how important it is to maintain established routines. The following three points in particular helped ensure that we were not left defenseless against the attack:

  • Segmentation of access rights: Strict access rights management prevented the data breach from becoming widespread. Truly sensitive data is kept separate.
  • Pre-planned measures backed by a dedicated team: Thanks to the workflows and teams established through ISO 27001, we were able to respond within a few hours. Rapid responses are crucial. The biggest wastes of time in such situations are unclear responsibilities and a lack of processes for immediate action.
  • Monitoring routines: Thanks to effective monitoring routines, we were able to quickly determine that the attack – or unauthorized access – had not spread and to rule out any hidden continuation.

Fact is: It can happen to anyone. We must get used to the increasing frequency of such incidents. This also requires an organized approach to incident-related communication. After all, the goal of such hacker groups is to destroy trust and business relationships by widely disseminating their claims. We counter this intent by engaging in even closer dialogue with our clients and strengthening our security-related communication channels.

We are already in close contact with the relevant contacts about this incident and will continue to be available to address our clients’ questions and concerns.