Recent findings indicate that foreign intelligence services are increasingly responsible for a growing number of attacks on German businesses. In a revealing study released on August 26, conducted by the Digital Association Bitkom in collaboration with the Federal Office for the Protection of the Constitution, it was reported that 37% of companies affected by data theft, industrial espionage, or sabotage could attribute at least one incident to a foreign intelligence agency. This marks a significant increase from just 28% in 2025 and a mere 7% in 2023. For the first time, foreign intelligence agencies have emerged as the second-largest identified group of perpetrators, following organized crime, which accounted for 62% of affected companies that reported at least one attack linked to criminal organizations.
Sinan Selen, the president of the Federal Office for the Protection of the Constitution, commented that foreign intelligence services have intensified their hybrid activities and are increasingly implicated in attacks on the German economy. Selen highlighted the security and defense sectors as particularly attractive targets for these foreign entities. Furthermore, the geographical attribution of these attacks has also shifted significantly. According to Bitkom's research, 52% of the companies affected could trace at least one attack back to China, an increase from 46% the previous year. Russia follows closely with 49%, up from 46% last year.
It is essential to note that the data regarding the geographical origin of these attacks does not necessarily imply that the respective states or their intelligence services are directly involved. The study differentiates between the regions from which attacks originated and the groups to which companies attribute the incidents. Following China and Russia, Eastern Europe outside the European Union and Russia accounted for 34% of attacks, while the United States contributed to 27% and other EU countries to 26%. Notably, 12% of companies traced attacks back to Germany, and there has been a notable rise in incidents traced to Iran, which rose from 4% in 2025 to 9% now.
Ralf Wintergerst, president of Bitkom, pointed out the increasing intertwining of state and criminal actors, stating that the lines between organized crime and intelligence services are often blurred in many countries. He explained that intelligence services might utilize criminal structures while criminal groups may serve state interests under certain conditions. The economic repercussions of data theft, industrial espionage, and sabotage remain substantial, with Bitkom estimating the damage to the German economy at a minimum of €211 billion. Due to heightened uncertainty regarding the detection of attacks, the association has provided a range, suggesting that damages could reach as high as €270.8 billion.
Last year, Bitkom reported a total damage figure of €289.2 billion, which includes operational losses, damage to IT and production systems, investigation and replacement costs, legal disputes, as well as revenue losses due to product counterfeiting and the loss of competitive advantages. Concurrently, the dark field of unreported incidents is growing; 96% of surveyed companies reported being affected by theft, industrial espionage, or sabotage or suspecting such incidents. However, only 67% could definitively confirm an attack, a decline from 87% the previous year, while the proportion of companies merely suspecting an attack surged from 10% to 29%.
Authorities are playing an increasingly vital role in the detection of these incidents. Among the companies that could identify perpetrators or origins, 50% received information from state entities, compared to 35% in 2025 and just 24% in 2024. A significant portion of the financial losses is now occurring in the digital realm, with cyberattacks accounting for 76% of the total damage identified. This figure has risen from 70% last year and 59% five years ago, with Bitkom estimating losses from cyberattacks between €160.4 billion and €205.8 billion.
Nearly two-thirds of companies reported an increase in cyberattacks over the past twelve months, and 69% expect this trend to continue in the upcoming year. Notably, ransomware remains the most damaging type of attack, affecting 25% of companies who reported that attackers encrypted their data and demanded ransom for its release, although this represents a decrease from 34% last year.
Simultaneously, artificial intelligence is becoming increasingly significant in cyberattacks, with 82% of companies believing attackers are leveraging AI more frequently. However, only 31% could definitively confirm such use, with another 51% suspecting it. This trend is particularly visible in automated calls and manipulated media, where the percentage of companies reporting damages from so-called robo calls rose from 3% to 14%, and incidents involving deepfakes doubled from 4% to 8%.
Companies recognize potential AI use in attacks through the automated adaptation of attacks, high-quality fake audio and video recordings, as well as increasingly convincing messages and emails. Wintergerst emphasized that artificial intelligence fundamentally alters the landscape of attacks, with powerful models capable of generating malware and further automating attacks. Simultaneously, companies can harness AI to detect attacks more swiftly.
The study surveyed 1,003 companies in Germany with at least ten employees and an annual revenue of at least one million euros, targeting executives responsible for economic protection, including managing directors and IT officials. The survey was conducted between calendar weeks 16 and 23 of 2026.
As reported by fokus-afrika.de.