Summary
- Bitkom says 37% of affected German companies linked at least one incident to a foreign intelligence service, up from 7% in 2023.
- Data theft, espionage, and sabotage are estimated to have caused between €211bn and €270.8bn of damage, with cyberattacks accounting for 76%.
- Detection, configuration, and identity controls appeared more frequently among causes of cyber damage than inadequate staff security awareness.
Foreign intelligence services are appearing far more frequently in cyber incidents affecting German companies, while the financial damage attributed to data theft, industrial espionage, and sabotage remains above €200 billion a year. A new study from Bitkom found that 37% of affected businesses could attribute at least one incident during the previous 12 months to a foreign intelligence service, compared with 28% a year earlier and 7% in 2023.
The German digital industry association surveyed 1,003 companies with at least ten employees and annual revenue of €1 million or more. Across the sample, 96% said they had been affected by, or suspected they had experienced, data theft, espionage, or sabotage, although the findings also expose growing uncertainty about what organisations can prove has happened inside their systems.
Only 67% could identify an attack with certainty, down from 87% a year earlier, while the proportion that suspected an incident but could not establish it conclusively rose from 10% to 29%. Bitkom has therefore expressed the economic damage as a range, estimating total losses at between €211 billion and €270.8 billion.
Organised crime remains the most commonly identified attacker group, cited by 62% of affected businesses able to make an attribution, but foreign intelligence services now follow at 37%. Among companies able to trace geographical origins, China and Russia appeared most frequently, while the proportion linking incidents to Iran rose from 4% to 9%.
Cyber damage is converging with geopolitical risk
Cyberattacks accounted for 76% of the estimated overall damage, up from 70% last year and 59% five years ago. Bitkom puts cyber-related losses between €160.4 billion and €205.8 billion, covering business interruption, investigations, replacement measures, litigation, extortion, lost sales, and competitive harm.
Attribution remains an imperfect measure because state intelligence services and organised criminal groups can overlap operationally, while companies often see only the intrusion rather than the organisation directing it. Germany has already been adjusting its security architecture to a more active threat environment, including changes to intelligence law covering AI analysis and narrowly defined cyber intervention.
Some of the more useful findings concern weaknesses inside the organisations being attacked. Among companies that suffered damage from a cyber incident, 59% cited inadequate detection as a contributing factor, followed by misconfigured IT systems at 57% and insufficient identity and access management at 55%.
Technical vulnerabilities were cited by 50%, outdated hardware or software by 43%, and compromise through external providers or suppliers by 8%. By comparison, 18% attributed damage to inadequate employee security awareness, complicating the tendency to frame corporate cyber resilience principally around staff behaviour and phishing training.
AI changes attack volume more than security fundamentals
Ransomware remained the attack type most likely to have caused damage, reported by 25% of businesses, although that proportion was down from 34% a year earlier. Bitkom also recorded growth from a much smaller base in techniques associated with artificial intelligence, including automated robocalls and deepfake-related incidents.
Some 82% of companies believe attackers are making greater use of AI, although only 31% said they were certain and another 51% suspected it. Respondents pointed to more personalised messages, higher attack frequency, improved forged audio and video, and automated adaptation of attempted compromises.
Those capabilities can increase the speed and credibility of attacks, but the study suggests that conventional security operations continue to determine much of the resulting damage. Detection, configuration, and identity management all rank above employee awareness among reported contributing factors.
That operational gap is appearing while security spending has stopped rising as a proportion of IT budgets. German companies continue to devote an average of 18% of IT expenditure to security, unchanged from the previous year, while Bitkom and Germany’s Federal Office for Information Security recommend 20%.
Confidence has weakened at the same time, with the proportion of organisations describing themselves as very well prepared for cyberattacks falling from 50% to 43%. The study also found that incidents can propagate into other businesses through production outages, customers, and suppliers, giving corporate weaknesses a wider economic effect.
Bitkom’s methodology cannot independently establish the actor behind every incident reported by respondents, and the rise in suspected breaches is itself evidence of uncertainty. Even so, the combination of more companies identifying foreign intelligence involvement and fewer considering themselves well prepared leaves German industry facing geopolitical and operational cyber risks through many of the same systems.












