Study reveals 37% of German firms link hacks to spies
Bitkom's 2026 study finds China, Russia and Iran driving a fivefold rise since 2023
More than one in three German companies hit by a cyberattack in the past year now believe a foreign intelligence service was behind it, a figure that has climbed fivefold since 2023.
That's the headline finding from Bitkom's Wirtschaftsschutz 2026 study, presented Wednesday alongside Germany's domestic intelligence agency, the Verfassungsschutz.
In 2023, just 7% of affected companies pointed to a state intelligence service. That share rose to 28% last year and now sits at 37%, according to the Bitkom-commissioned research, which surveyed more than 1,000 companies.
Organised crime remains the more common culprit overall, implicated in 62% of attacks, but Bitkom President Ralf Wintergerst says the distinction is increasingly meaningless in practice.
For those companies capable of identifying the source of an attack on a per-country basis, 52% of them cited China and 49% Russia, with 9% citing Iran, which represents a smaller threat, yet, according to researchers, a rising one.
The governments of all three countries deny having cyberattack units operating outside their territory. Wintergerst describes the blurring line between state and criminal organisations, adding that intelligence organisations are increasingly dependent on criminal organisations, and vice versa.
Classical ransomware is falling out of favour for the sake of artificial intelligence-based attacks, according to the research, with robocalls and deepfakes being disproportionately harmful compared to the prevalence of attacks they carry out. 80% of companies anticipate increased use of artificial intelligence by the attackers.
Defensive confidence has dropped along with it, with only 43% of companies feeling adequately protected against attacks, down from 50% from last year, even though fewer companies believe that an attack could be an existential threat to them, down from 59% last year.
Bitkom put total annual damage from data theft, espionage and sabotage at €211 billion. Security spending hasn't moved in response, holding steady at 18% of the average company's IT budget.
-
OpenAI, Anthropic and Google join forces on AI safety efforts
-
Meta to deploy custom Arke and Astrid AI chips in 2027: Everything to know
-
Dreamforce 2026: Salesforce unveils Koa AI model and Google Cloud partnership
-
EU Kids Act: New social media rules for under-15s
-
China’s spy chief reveals growing fears over AI’s impact on communist party rule
-
Anthropic's new Claude tool targets financial advisors to streamline compliance and client research
-
Elon Musk’s bold AI safety idea: 'Let rivals test each other’s models'
-
Former Google DeepMind researcher warns autonomous AI could wipe out humanity amid industry-wide safety alarm