

German businesses are reporting a sharp rise in cyberattacks they believe are connected to foreign intelligence services, according to a new study by digital industry association Bitkom. The findings point to a growing security challenge for companies as cybercrime increasingly overlaps with state-linked activity.
The study found that 37% of German companies affected by data theft, industrial espionage or sabotage said they had traced at least one attack in the previous 12 months to a foreign intelligence service. That compares with 28% a year earlier and just 7% in 2023.
Among companies that identified the origin of an attack, China and Russia were the most frequently named sources. Around 52% of affected businesses traced at least one incident to China, while 49% linked an attack to Russia. Iran was identified by 9% of companies, up from 4% the previous year, making it a growing concern for German businesses.
China, Russia and Iran denied conducting cyberattacks abroad. German officials have also warned about a worsening cyber and hybrid threat environment, with businesses increasingly facing attacks that combine digital intrusion with espionage, sabotage or other forms of disruption.
Despite the increase in suspected state-linked operations, organised crime remains the biggest source of attacks, according to the survey. Around 62% of affected companies attributed at least one incident to criminal groups.
Bitkom President Ralf Wintergerst said the distinction between criminal networks and intelligence services can sometimes be difficult to establish. According to him, intelligence agencies may use criminal structures, while criminals can also operate with targets that align with political objectives.
The financial consequences are significant. Bitkom estimates that data theft, industrial espionage and sabotage cost the German economy between €211 billion and €270.8 billion. Cyberattacks account for about 76% of the overall damage.
The study also highlighted changes in the way cyberattacks are carried out. Traditional attacks such as ransomware are becoming less dominant, while newer techniques involving automated calls and deepfakes are causing more damage.
Eight in 10 companies expect attackers to increase their use of AI, although many businesses said they could not definitively confirm when such tools had been involved. Damage linked to automated robocalls rose from 3% to 14%, while damage involving deepfakes increased from 4% to 8%.
Also Read: Pakistan Hackers Target India, Exploiting Border Tensions for Cyber Attacks
The research also found that only 43% of companies considered themselves very well prepared for cyberattacks, down from 50% a year earlier. Cybersecurity spending, meanwhile, remained at around 18% of overall IT budgets.
The survey covered 1,003 German companies with at least 10 employees, making the findings a significant indicator of the country's corporate cybersecurity landscape.
For German businesses, the message is becoming harder to ignore: cyber threats are no longer limited to conventional criminals, and the growing overlap between organised crime, foreign intelligence operations and emerging technologies is making digital security increasingly complex.