87% of German companies were attacked last year, and Russia has caught up with China

Bitkom puts the damage at €289.2bn and, for the first time, folds the domestic intelligence service’s own attribution into the survey.


Hand on screen of code to illustrate cyberattacks in Europe

Cyberattacks in Europe are rising

Image Credits Credit: Kai Stachowiak

Some 87% of German companies were hit by data theft, espionage, or sabotage in the past twelve months, up from 81% a year earlier, according to the industry association Bitkom, which puts the resulting damage at €289.2bn.

What is new in this year’s report is not the trend but the method, because Bitkom has combined its company survey with assessments from Germany’s domestic intelligence service, in a country where public sector defences have been under sustained pressure.

That combination matters because attribution is the thing companies cannot do for themselves. A firm knows it was breached and rarely knows by whom, so pairing survey responses with state intelligence on active campaigns produces a picture neither source generates alone.

The attribution finding is the one worth pausing on. Russia and China are each blamed for 46% of externally attributed incidents, with Russia climbing from 39% the previous year to draw level with China.

Russia overtaking its own prior figure by seven points in a single year is a substantial move in a dataset this size. It also fits a broader European pattern of Russian activity shifting from espionage towards disruption, which Dutch authorities have documented while seizing 800 servers tied to Russian hacking operations.

Of the total damage figure, roughly €202.4bn is attributed directly to cyberattacks, with the remainder covering analogue theft and sabotage. The overall number is up from €267bn the year before.

Those figures deserve to be read as estimates rather than accounts. They are built from self-reported survey responses about losses that firms often cannot measure precisely, and they include indirect costs such as reputational damage that no company books.

The methodology is at least transparent. Bitkom Research surveyed companies with at least ten employees and €1mn in annual revenue by telephone, which is a reasonable population and a reasonable instrument for a question this hard to quantify.

Rising percentages of this kind also carry a measurement problem worth naming. Better detection produces more reported incidents, so some of the increase from 81% to 87% may reflect companies noticing what was already happening rather than more of it happening.

Nearly 59% of companies said they feel economically threatened by cyber incidents, which is the finding with the clearest business consequence.

That is a majority of German firms describing an existential risk rather than an IT problem, and it changes what boards are willing to spend.

Malware, ransomware, and phishing remain the dominant vectors, with phishing typically providing the initial access. The persistence of that list is its own commentary, since none of these are novel techniques and all of them still work.

German industry is an unusually attractive target for a specific reason. The Mittelstand contains thousands of mid-sized companies holding world-leading engineering intellectual property with security budgets sized for their revenue rather than for the value of what they know.

Germany has been reinforcing its response, expanding intelligence service capabilities as the threat from foreign powers has grown, and NATO has been signing cyber partnerships with Microsoft, Palo Alto, and ESET in parallel. The awkwardness in that arrangement is familiar, given that European institutions are strengthening defences partly by deepening dependence on American vendors.

That tension runs through the whole discussion, because Europe’s cloud dependency is a political risk as much as a technical one, and separate Bitkom research has found the overwhelming majority of German companies believe their reliance on US cloud providers runs too deep.

The intelligence-sharing element is the part other European countries may copy. Most national industry bodies survey their members on breaches, and few pair the results with what the security services already know about who is running the campaigns.

What the report does not resolve is what any individual company should do differently. The attribution is better than it was, the damage is larger than it was, and the attack methods are the same ones the sector has been describing for a decade.

Get the TNW newsletter

Get the most important tech news in your inbox each week.