Last year, 87% of German businesses experienced attacks, and Russia has now matched China in this regard.

Last year, 87% of German businesses experienced attacks, and Russia has now matched China in this regard.

      According to the industry association Bitkom, approximately 87% of German companies experienced data theft, espionage, or sabotage in the past year, an increase from 81% the previous year, with the resulting damages estimated at €289.2 billion. This year’s report introduces a new methodology rather than a change in trend; Bitkom has merged its company survey with evaluations from Germany's domestic intelligence agency, in a landscape where public sector defenses have been under constant strain.

      This combination is crucial because companies find it difficult to attribute attacks on their own. While a business may recognize it has been breached, it often lacks knowledge of the perpetrators. By integrating survey data with state intelligence on current threats, a more comprehensive picture emerges that neither source could provide independently.

      The attribution findings are particularly noteworthy. Russia and China are each implicated in 46% of externally attributed incidents, with Russia increasing from 39% the previous year, now matching China’s rate. Russia's seven-point rise in just one year is significant in such a large dataset and aligns with a broader European trend showing a shift in Russian activities from espionage to disruption, as Dutch authorities have shown by seizing 800 servers linked to Russian hacking operations.

      Of the total damage, about €202.4 billion is directly linked to cyberattacks, while the remainder accounts for physical theft and sabotage. This overall figure has risen from €267 billion the previous year. It is essential to interpret these numbers as estimates rather than precise accounts; they are derived from self-reported data regarding losses that firms often cannot accurately quantify, and they also encompass indirect costs like reputational damage that companies typically don’t register.

      The methodology is at least clear; Bitkom Research conducted telephone surveys with companies that have at least ten employees and €1 million in annual revenue, representing a sensible demographic and method for addressing such difficult-to-quantify issues. However, rising percentages pose a measurement concern; improved detection may result in more incidents being reported, meaning some of the increase from 81% to 87% could simply indicate greater awareness rather than an actual rise in incidents.

      Almost 59% of companies indicated they feel economically threatened by cyber incidents, which is the finding that carries the most significant business implications. This represents a majority of German firms perceiving an existential risk, rather than merely an IT issue, which impacts how much boards are willing to allocate for prevention.

      Malware, ransomware, and phishing remain the primary attack vectors, with phishing often being the initial entry point. The continued relevance of these methods speaks volumes, as they are not new techniques yet still prove effective.

      German industry is particularly appealing to cybercriminals for a specific reason: the Mittelstand is made up of thousands of mid-sized firms that possess world-leading engineering intellectual property but have security budgets that reflect their revenue rather than the worth of that knowledge.

      To address the increasing threat from foreign powers, Germany has been bolstering its response and enhancing intelligence service capabilities, while NATO has been establishing cyber partnerships with Microsoft, Palo Alto, and ESET. However, there is a notable tension in this approach, as European institutions are reinforcing their defenses partly by relying more on American vendors.

      This dependency on U.S. cloud providers represents a political as well as technical risk, as further research from Bitkom indicates that a significant majority of German companies feel their reliance on these providers is excessive.

      The intelligence-sharing component of this report may serve as a model for other European nations, as most national industry organizations conduct surveys on breaches but few integrate their findings with the insights of security agencies regarding ongoing threats.

      What the report fails to clarify is what actions individual companies should take moving forward. While attribution has improved, the damage has escalated, and the methods of attack remain consistent with what the sector has reported over the past decade.

Other articles

Microsoft employees created their own compensation spreadsheet, which highlights two companies. Microsoft employees created their own compensation spreadsheet, which highlights two companies. Approximately 600 Microsoft employees contributed salary information to a crowdsourced spreadsheet, revealing base salaries ranging from $111,000 to $450,000 and an increasing disparity in equity. Last year, 87% of companies in Germany experienced attacks, and Russia has now matched China's level. Last year, 87% of companies in Germany experienced attacks, and Russia has now matched China's level. Bitkom estimates the cost of damage to German companies at €289.2 billion, attributing 46% of the attacks to both Russia and China. MindRank’s oral GLP-1 is the most advanced AI-native drug program to date. MindRank’s oral GLP-1 is the most advanced AI-native drug program to date. In July, MindRank, a Chinese AI drug development company, secured $52 million and announced that its oral GLP-1 candidate has progressed to Phase III with approximately $23 million invested in research and development. Metro 2039 lacks heroes. It exchanges hope for vengeance, and I fully support this new approach. Metro 2039 lacks heroes. It exchanges hope for vengeance, and I fully support this new approach. The new Renegade gameplay trailer for Metro 2039 takes us once again underground, featuring more intricate environments, additional survival tools, intense combat, and yet another unsettling hint of the Dark Ones. Amazon shifted part of its Canadian sourcing from the US to China in order to evade tariffs. Amazon shifted part of its Canadian sourcing from the US to China in order to evade tariffs. Internal documents indicate that Amazon anticipates a growth of over 40% in Canadian package volume by 2029, and that it has moved some sourcing to China. Amazon relocated a portion of its Canadian sourcing from the US to China to evade tariffs. Amazon relocated a portion of its Canadian sourcing from the US to China to evade tariffs. Internal documents reveal that Amazon anticipates a package volume increase in Canada of over 40% by 2029, and that it has moved some sourcing operations to China.

Last year, 87% of German businesses experienced attacks, and Russia has now matched China in this regard.

Bitkom estimates the losses for German companies to be €289.2 billion, with Russia and China each responsible for 46% of the reported attacks.