Weekly Backlog Week 34/2026
Katrin Peter 8 Minuten Lesezeit

Weekly Backlog Week 34/2026

40 minutes. That’s apparently how long it took for a compromised access to turn into a supply chain attack affecting thousands of organizations. Meanwhile, in Europe, we’re still debating how much digital sovereignty is actually embedded in an infrastructure that can hardly function without US tech.

🧠Editorial:

40 minutes. That’s apparently how long it took for a compromised access to turn into a supply chain attack affecting thousands of organizations. Meanwhile, in Europe, we’re still debating how much digital sovereignty is actually embedded in an infrastructure that can hardly function without US tech.

At first glance, these seem like two different stories. But they’re not. Ultimately, it’s about dependencies—on platforms, manufacturers, supply chains, and decisions made outside one’s own sphere of influence.

Or put another way: Who really has control when it matters?

That’s exactly what this week is about. Enjoy reading—and perhaps afterward, reviewing your own Plan B.

📰 Tech-News:

Cyberattack on France’s Tax Administration: Data from 678,000 Affected Stolen

France’s cybercrime authorities are investigating an attack on a state-run information system of the tax administration. Cybercriminals managed to steal data from 678,000 individuals and companies. Officials from the tax authority describe the incident as more complex than previous cyberattacks.

The investigation is being led by the French Office anti-cybercriminalité (OFAC). According to the Paris prosecutor’s office, there is also an investigation into the suspicion of involvement in a criminal organization to prepare a crime.

The exact technical details of the attack are not yet known. According to Le Monde, the attackers’ access was blocked during a routine check at the end of June. However, the data breach was not noticed at that time.

The potential scope only became known later: a post appeared in a digital underground forum claiming the theft. The alleged perpetrator stated there that they had accessed an internal tool of the French tax authority via a VPN.

For individuals, full names, family quotient information, taxable income, and withholding tax rates are among the data affected. Access credentials to the tax administration’s website were reportedly not stolen.

Those affected are to be informed this week and warned of possible identity theft and fraud attempts. For companies, the stolen information includes tax numbers, business addresses, and the address of the authorized company representative. The financial authority considers this data to be less sensitive.

This incident is not the only major IT security case in France this year. In June, attacks on the French government messenger Tchap were reported, affecting around 73,000 users. In February, attackers accessed a national bank account database and retrieved information on 1.2 million accounts.

🔗https://www.heise.de/news/Frankreich-untersucht-Diebstahl-von-Steuerdaten-von-678-000-Betroffenen-11416188.html

Digital Sovereignty Needs an Exit Plan

Digital sovereignty is increasingly being implemented practically in Europe. France requires its ministries to have concrete plans to reduce non-European IT dependencies, the EU Parliament has introduced Qwant as the default search engine, and the Austrian Ministry of Economic Affairs operates its own Nextcloud environment for around 1,200 employees.

Karl Fröhlich takes these developments as an opportunity in a recent article for speicherguide.de to focus the debate on digital sovereignty on a crucial point: exit capability.

His argument is noteworthy. A European provider, a German data center, or a contract with a European subsidiary does not automatically make an IT infrastructure sovereign. What matters is who can access the data, which laws providers and subcontractors are subject to, who controls the keys—and whether a company can actually transfer its data and applications to another platform.

Thus, Fröhlich clearly separates data residency from data sovereignty and digital sovereignty. The storage location initially only answers the question of where data resides. Sovereignty, on the other hand, is demonstrated by whether an organization can switch providers, fully export its data, and continue operations independently.

This is particularly relevant for cloud exit. Although the EU Data Act has strengthened switching rights for data processing services since September 2025, a legal right alone does not migrate databases, replace proprietary interfaces, or create alternative infrastructure. An exit must therefore be considered already in the architecture design.

This includes open or clearly defined export formats, documented interfaces, independent backups, controllable keys, existing know-how, and above all, tested restore and migration processes. For large data volumes, very practical questions arise: How long does a full export take? What costs are incurred? And on which infrastructure will the data continue to run?

Thus, Fröhlich hits an important point in the sovereignty debate: dependency cannot be reduced solely through procurement policy. It must become technically manageable.

🔗https://www.speicherguide.de/datensouveraenitaet/digitale-souveraenitaet-braucht-exit-faehigkeit-27050.html

SAP: Europe’s Tech Champion Makes Us More Dependent on the USA

SAP is one of the few European technology companies of global significance. All the more remarkable is with whom the company is building its technological future.

SAP is consistently pushing its customers towards the cloud. Existing customers who commit to transitioning the majority of their current system landscape to SAP Cloud ERP gain access to selected AI scenarios. At the same time, SAP is expanding strategic partnerships with Amazon Web Services, Microsoft, Google Cloud, NVIDIA, and Anthropic.

And now Palantir is also joining.

In May, SAP expanded its strategic partnership with the US company. Palantir AIP is already available as a “SAP Endorsed App,” with another SAP solution extension expected in the third quarter of 2026.

One must consider the significance of this development: SAP systems encompass finance, procurement, human resources, supply chains, and other business-critical processes. As Europe’s most important software company increasingly leads its customers into the cloud and aligns its technological strategy closely with American hyperscalers, AI providers, and Palantir, SAP’s dependencies increasingly become those of its customers.

While Europe invests billions and debates how we can become more technologically sovereign, our largest software company is creating facts in the opposite direction.

The recent news about a CVSS 10.0-rated vulnerability in SAP Commerce Cloud, which according to Golem is already being exploited for attacks, almost seems like a footnote.

Because the much larger question is long-term in nature: How sovereign can a European company be when one of its most important European technology providers increasingly ties its own future to US big tech?

SAP, due to its market position, would have the opportunity to be a central component of a sovereign European technology infrastructure.

Instead, SAP itself risks becoming a multiplier of our technological dependency.

🔗https://news.sap.com/germany/2026/05/sap-stellt-das-autonome-unternehmen-vor/?utm_source=chatgpt.com & https://news.sap.com/germany/2026/05/sap-und-palantir-erweitern-partnerschaft-mit-ki-gestuetzten-tools-fuer-die-datenmigration-zur-beschleunigung-der-cloud-erp-transformation-fuer-autonome-unternehmen/ &https://www.golem.de/news/schadcode-im-anmarsch-sap-systeme-werden-ueber-kritische-luecke-attackiert-2608-211987.html

After More Than 60 Years: ebm-papst to Be Fully Sold to US Company

Christian Höffner brought to my attention an article from heise describing a remarkable ownership change in German industry.

The fan and cooling specialist ebm-papst is to be sold to the US company Madison Air. The company from Mulfingen in Baden-Württemberg employs more than 13,000 people worldwide and recently generated annual sales of around 2.2 billion euros.

Founded in 1963, ebm-papst develops fans and motors for numerous industrial applications, including data center cooling—a sector whose significance is growing due to the expansion of AI infrastructure and the associated cooling needs.

According to information about the planned deal, the previous owner families intend to transfer their shares entirely to Madison Air. The purchase price is around 4.8 billion euros.

Madison Air itself operates in the air, ventilation, and cooling technology sector and was already a customer of ebm-papst. The acquisition aims to expand access to the US market and the joint activities of both companies.

For ebm-papst, the planned ownership change comes during a phase of further investments. The company is expanding its capacities at its headquarters in Mulfingen. Due to high demand for fans, particularly for data centers, additional jobs are to be created in production.

Internationally, investments have also been made recently. In Oradea, Romania, ebm-papst opened a new site for production, research, development, and service. The investment volume amounts to around 30 million euros.

The planned sale to Madison Air is not yet complete. The transaction is subject to the necessary regulatory approvals.

Thus, a German family business founded in 1963 with 35 employees could fully come under the control of a US owner after more than six decades.

🔗https://www.heise.de/news/Deutscher-Kuehlungsspezialist-ebm-papst-leitet-Verkauf-an-US-Firma-ein-11417131.html

Federal Cartel Office Forces Apple to Fairer Tracking Requests

Apple must change its rules for tracking requests on iPhones and iPads. The Federal Cartel Office has concluded a competition law proceeding against the company. Apple has made legally binding commitments to adjust its consent dialogues.

The focus is on the App Tracking Transparency Framework (ATTF) introduced in 2021. Third parties must obtain additional consent to use user data across devices for personalized advertising.

The Federal Cartel Office primarily criticized the different treatment of Apple and other app providers. The stricter requirements did not apply equally to Apple’s own offerings. For consent to personalized advertising, Apple used a separate dialogue. According to the Federal Cartel Office, the language, design, and options were such that users were more likely to consent.

In the future, requests for Apple services and third-party providers should be more aligned in terms of language, appearance, and content and be designed more neutrally. For third-party apps, Apple should also refrain from using the previously used warning hand and the term “tracking.”

App providers will also have more options. They should be able to explain to users in more detail the significance of personalized advertising for their business model. Additionally, Apple’s request should better integrate with the overall user experience.

Weitere Backlogs

Kontakt aufnehmen