Foreign Spies Linked to 37% of Cyberattacks on German Companies

Foreign intelligence services were linked to 37% of attacks on German companies as businesses struggled to confirm intrusions and identify attackers.

Aug 27, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Germany’s businesses are losing billions to cyberattacks and espionage, and are becoming less certain about who is behind them, creating a security problem that companies cannot always see coming.

Bitkom estimates that data theft, industrial espionage, and sabotage cost German businesses around €211 billion to €270.8 billion ($246 billion to $315.7 billion), depending on the methodology.

At the same time, 37% of companies affected by these incidents said they could attribute at least one attack to a foreign intelligence service, up sharply from 28% last year.

Among surveyed companies, 67% said they had definitely experienced an incident, while another 29% suspected they had been targeted but could not confirm it.

That makes attribution harder as state-linked actors, organized crime groups and AI-assisted attack methods increasingly overlap.

The numbers behind Germany’s hacking problem

Bitkom found that 96% of German companies had either experienced or suspected data theft, industrial espionage or sabotage in the past 12 months, only slightly below the 97% recorded a year earlier.

But beneath that figure is a more worrying change. The share of companies that could confirm a successful attack fell from 87% to 67%, while those that suspected an attack but could not prove it jumped from 10% to 29%.

At the same time, only 43% considered themselves very well prepared for cyberattacks, down from 50% in the previous study.

There is one notable decline: ransomware, which remained the most common source of cyberattack-related damage, affected 25% of companies, down from 34% a year earlier.

Who is behind attacks on German companies?

Organized crime remains the largest identified source of attacks, sitting at 62%. Foreign intelligence services ranked second at 37%, up from 28% a year earlier, indicating that state-linked activity accounted for a growing share of attacks companies were able to attribute.

While China and Russia remain the leading identified foreign sources, Iran is the newer development worth watching.

The share of affected companies that traced at least one attack to Iran more than doubled, from 4% to 9%, making Iran a newly relevant actor in Bitkom’s assessment of economic crime.

Advertisement

Iran remains far behind China and Russia. But its rapid increase is significant, as that indicates that the increase suggests Iran is becoming more visible among the foreign sources German companies associate with cyber incidents.

AI is showing up in attackers’ hacking arsenal

Bitkom’s findings revealed that AI is increasingly used, although only 31% of companies were certain that AI was being used to attack them, while 51% had suspicion.

Evidence pointed to robocalls and deepfakes. The clearest evidence so far remains relatively small compared with traditional attacks, but it is increasing.

Why Germany’s hacking incident is a lesson for others

Germany’s experience shows that the hardest cyber problem for businesses may not be stopping every attack. It is knowing that an attack happened, determining who was behind it, and limiting the damage before the intrusion becomes something larger.

The lesson also goes beyond Germany’s immediate threat list. The goal is to adopt a robust perimeter defense across all attack surfaces. That in itself means companies must understand their attack surfaces to begin with.

Bitkom’s findings also point to the value of cooperation between companies and government agencies. Half of the companies that managed to identify an attacker or country of origin said authorities helped them do so, compared with 35% a year earlier. 

For businesses facing increasingly blurred lines between cybercrime, espionage and AI-assisted attacks, no single organization may have the full picture. Sharing indicators and evidence can help defenders connect activity that would otherwise look like isolated incidents.

Other News: A cyberattack on medical device maker Boston Scientific disrupted its IT systems and global order fulfillment operations

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.