A Bitkom survey of 1,003 German companies found that nearly 40% of organizations affected by data theft, industrial espionage, or sabotage attributed at least one incident to a foreign intelligence service, up from 28% a year earlier and 7% in 2023. China was the most frequently cited source, followed by Russia; roughly one in 10 affected firms linked incidents to Iran. Ransomware remained the most commonly reported attack type, while estimated annual losses from cyberattacks remained in the hundreds of billions of euros.
Federal Office for the Protection of the Constitution President Sinan Selen warned that AI is worsening the threat environment, citing a China-linked operation assessed as entirely AI-generated. He urged stronger patching, resilience, and preventive cooperation, and said expanded intelligence powers would not create a systemic risk of zero-day vulnerabilities being withheld from Germany’s Federal Office for Information Security. Survey respondents also reported an increase in ransomware payments.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Nearly four in 10 affected companies attributed at least one incident involving data theft, industrial espionage, or sabotage to a foreign intelligence service, compared with 28% in the prior-year survey. China was the most frequently cited foreign source, followed by Russia and Iran.
Bitkom surveyed 1,003 German companies with more than 10 employees and estimated directly quantifiable cyberattack damage at €211 billion to €270.8 billion. The survey found ransomware remained a dominant threat, with 20% of respondents reporting that they had paid a ransom at least once.
Bitkom reported that 7% of affected German companies attributed at least one cyber incident to a foreign intelligence service in 2023.
Selen said proposed expanded intelligence authorities should support intervention against attacks and attacker infrastructure, but rejected claims that the BfV would systematically withhold vulnerabilities from the BSI. He stated that protecting society and the economy is incompatible with knowingly leaving vulnerabilities unaddressed.
BfV President Sinan Selen said the agency had identified an attack campaign from China that was entirely AI-generated. He warned that AI, deepfakes, and robocalls are accelerating the cyber threat environment and called for faster patching and multilayered defenses.
Lidl disclosed a data breach after attackers accessed customer information held by one of its IT service providers.
Hackers targeted Unimed, an external billing provider used by medical centers across Germany. Several German university hospitals said patient information was stolen in the breach.
The Dresden State Art Collections suffered a targeted cyberattack that disrupted substantial portions of its digital infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.