You’d realise if you were being manipulated, wouldn’t you?
Nowadays, many successful attacks do not begin with malicious code, but with a credible enquiry. They arrive during peak office hours, are extremely polite and sometimes even wear a high-visibility vest.
Find out here why this is the case, what you can do about it, and why we at Deutsche Telekom are dedicating a whole day to this issue on 26 November.
In Brief
- Security is everyone’s business. It is the result of the many small decisions we make every day in our working lives, often without realising it.
- In an increasingly digital and automated world, responsibility still lies with people.
- After all, security is more than just technology or processes: it thrives on vigilance, responsibility and cooperation.
And it doesn’t stop at company boundaries #SecurityIs4Sharing
It’s Friday, 2.47 pm...
A Teams message from IT Support: there’s a problem with logging in; they need to verify the account briefly – it’ll only take a minute. The tone is friendly. The profile picture is correct. They even mention the name of the colleague from the last ticket. A brief hesitation. But let’s be honest: at 2.47 pm on a Friday, nobody wants to take a login problem into the weekend. Click: at that very moment, the first stage of the attack has succeeded. Technical safeguards alone cannot prevent such situations. No system has been hacked. No vulnerability has been exploited. Not a single line of code has been written.
Forget the image of the hacker in a hoodie, typing green strings of code across the screen at three in the morning. Companies have invested heavily in technology in recent years. Networks are secured, identities are professionally managed, and end devices are better protected than ever. Yet attacks still succeed. Not because the technology fails, but because the attackers have long since shifted their focus elsewhere: to something that isn’t in any system plan. To our trust. To our decisions. To our information. Let’s take a closer look.
Spelling mistakes as a warning sign are a thing of the past.
What actually happened at 2.47 pm? The uncomfortable truth is that everything we’ve been taught about phishing over the years wouldn’t have helped in this situation. The poor grammar? Gone. The poorly translated email about a surprise inheritance worth millions? A thing of the past. Its successor has studied your organisational structure on LinkedIn, knows the names of your line managers and writes flawless German – in a matter of seconds, thanks to generative AI – and, if required, in eight other languages and in the tone typical of your industry.
Phishing has become industrialised. What used to require linguistic talent, research and patience is now handled by language models working at full capacity. The barrier to entry for a convincing attack has never been lower. Attackers have long since moved beyond email. Your working day takes place in Teams, via text message, on video calls, and through QR codes on event invitations – so that’s exactly where the attack takes place too. What matters here is not just the channel, but the trust we place in it.
The most surprising thing about all this is that people do not fall for phishing because they are inattentive. They fall for it because the attack looks like work. Someone who approves two hundred invoices a day won’t notice invoice number 201 – precisely because it looks just like the two hundred before it. Attackers do not exploit gaps in knowledge; they exploit routine.
"Phishing is therefore no longer just an email problem. It is a matter of trust."
Julia Wollschläger, Group Security Officer der DTAG
Our Security Day
Our Security Day
On 26 November, here at Deutsche Telekom, we are making a conscious effort to integrate security into our employees’ day-to-day working lives. Because security concerns us all. It is not created solely by systems, but by the small decisions each and every one of us makes in our day-to-day work – often without even realising it. One thing is particularly important to us in this regard: security does not end at the company’s boundaries. Attackers have long been sharing their knowledge with one another – in a very collegial manner, incidentally. It’s high time that the defenders did the same. #SecurityIs4Sharing – join in!
How does it work?
It doesn’t have to be a major event. A team meeting featuring a real-life phishing example. An internal challenge. An open discussion on what information must never leave the company. What matters isn’t the scale of the event, but that security is given a permanent place: in the calendar and in people’s minds.
Share your actions, ideas and experiences at #SecurityIs4Sharing. The more organisations dedicate a day to security, the harder we make it for those waiting for a moment of carelessness. Please feel free to contact us: TagderSicherheit@telekom.de
The man with the ladder
A change of scene. A man in a high-visibility vest stands in front of the office block, a ladder under his arm, a toolbox in his hand, looking slightly annoyed. The universal expression that says, ‘I’ve got three more appointments today’. How many doors do you think will be held open for him? Probably more than we’d care to admit. And sometimes just one is enough. For example, the door to the server room. With a friendly ‘No problem!’. Welcome to social engineering. The discipline in which the most successful attackers aren’t the best hackers, but the best psychologists. Why spend weeks cracking a firewall when a confident demeanour and the phrase “I’m here to check the air conditioning” grant the same access?
The tools of the trade for these attackers are surprisingly unspectacular, and have hardly changed in decades: authority. Time pressure. Helpfulness. Curiosity. Routine. Fear. Six triggers built into every human being, with no option to ‘uninstall’ them. It’s not the principle that’s new. It’s the precision.
Because the same AI that polishes phishing emails can now clone voices. That call from the finance director who needs a bank transfer “immediately, just this once”? It sounds exactly like the finance director. The familiar name in the sender field no longer guarantees authenticity, nor does the familiar voice, and even the face on a video call can be synthetic. Behind this lies a fallacy that lurks in many security concepts: social engineering doesn’t attack people at all; it attacks decisions. To be more precise: decisions made under time pressure, with incomplete information and within relationships of trust. In other words, pretty much exactly the sort of decisions that make up a normal working day. People trust procedures more than they trust technology: anything that looks like an established business process is rarely questioned. The consequence is a new principle: trust is essential; verification is indispensable. No, asking for clarification is not mistrust.
Even pilots go through their checklist before every take-off, even though they know how to fly. Calling back on a familiar number, or briefly checking via a second channel – that’s not paranoia. That’s professionalism.
The colleague who never asks for clarification
Final scene. Tuesday, 5.12 pm. The draft contract needs to be summarised by tomorrow, my mind’s a blank, and it’s nearly time to finish for the day. Luckily, there’s that one colleague who never gets tired: I copy the contract into the AI tool, say, “Please summarise this for me”, and thirty seconds later, the result is there. The end of the working day is saved. AI is the most helpful colleague you’ve ever had. It never complains, has no meetings and always delivers. It has just one weakness: it never asks, ‘Are you sure you should be showing me this?’ This is where many discussions go off track. The question isn’t whether AI is dangerous. AI amplifies, accelerates and scales up many already known risks relating to confidentiality, data protection, intellectual property and compliance. Every use begins with the same simple action: someone enters information. And it is precisely at this moment that it is decided whether AI is a productivity miracle or a security incident waiting to happen.
The actual risk here is more subtle than one might think. It is the context. A single prompt seems harmless: a paragraph from a contract here, a turnover figure there, a snippet of source code over there. Each tiny piece on its own seems inconsequential. Taken together, however, they paint a surprisingly complete picture of how your company operates, plans and negotiates. Protecting information is therefore always about protecting context. The crucial question for organisations is therefore no longer ‘Are our employees allowed to use AI?’. Everyday practice has long since provided the answer to this. It is: ‘What information are we permitted to process, in which tool, and under what conditions?’
Blanket bans alone do not solve the problem. People use AI because it helps them work more productively and quickly. Clear guidelines are therefore crucial: approved tools, a mindful approach to classified information, and unambiguous rules regarding which tasks and decisions AI is permitted to take on. One fundamental principle still applies: responsibility cannot be delegated to an AI. However, this does not mean that every single step must be decided or authorised by a human. AI systems can act independently and make decisions within clearly defined limits.
What is crucial is that we, as humans, consciously set these limits: What objectives is the AI permitted to pursue? Which data and systems is it permitted to access? Which actions is it permitted to carry out independently? What level of risk do we accept – and when must it stop, escalate the matter or involve a human? The more autonomously an AI acts and the greater the potential impact of its decisions, the more important clear lines of responsibility, transparent decision-making and effective control mechanisms become. Responsibility remains with humans – even when not every single decision is made by a human.
Three attacks, one pattern
Did you notice? In none of the three stories was the technology breached. The firewall worked. So did the multi-factor authentication. The same target was attacked three times in three different ways: in the case of phishing, it was trust; in the case of social engineering, it was the decision; and in the case of AI, it was the information.
Attacks target identities, end devices, IT infrastructure, applications, and production and operational technology. That is why securing them technically is essential. However, even the best protective measures cannot prevent every risky decision made in day-to-day work. Many attacks therefore strike precisely where people assess information, trust requests or act under time pressure: between checking their inbox, opening the door and the end-of-day prompt.
The good news is: that is precisely where we can make a real difference. Verifying unusual enquiries via a second channel. Deliberately slowing things down when making critical decisions. Classifying information before it goes into an AI tool. Sounds unspectacular? It is. And that is exactly why it works.
However, behaviour like this does not arise from compulsory annual training alone. What matters most are the moments when we see the consequences our actions can have – and immediately learn what we can do differently next time. It is precisely these kinds of learning moments that we need to create: concrete, closely linked to our day-to-day work, and ideally before a mistake turns into a genuine security incident.
Because right now, somewhere, someone is clicking ‘Verify’ again at 2.47 pm.
Let’s work together to ensure that this routine becomes a brief moment of awareness.
Author: Julia Wollschläger
Julia Wollschläger is Group Security Officer at DTAG. In this role, she is responsible, amongst other things, for physical and personnel security, business continuity, and crisis and emergency management for the Group. Together with national and international security teams, she strengthens the Group’s resilience in the face of current and future security challenges and drives forward the development of an integrated, risk-based security approach. In addition, she is involved in coordinating the DAX30 CISO/CERT working group, thereby promoting cross-sector dialogue on security issues.