German Cyber Attack Losses Now Come With A Range.

Estimated reading time: 6 minutes

Bitkom has published a single headline damage figure for German industry every year for a decade. This year it published two.

The digital association put losses from data theft, industrial espionage, and sabotage at somewhere between €211bn and €270.8bn over the past twelve months. The reason for the corridor sits in the methodology note. Companies have stopped being able to tell whether they were attacked.

Firms that could confirm a successful attack with certainty fell to 67%, down from 87% a year ago. Firms that suspect an attack but cannot prove one rose from 10% to 29%. Bitkom built the lower end of its range from companies that can demonstrate a breach, and the upper end by adding the suspected cases that exceed the five-year average.

German cyber attack losses graphic from Cyber Insurance News showing cyan digits dissolving into particles beside the Bitkom range of 211 to 270.8 billion euros

Why German Cyber Attack Losses Got A Range

Bitkom president Ralf Wintergerst attributes the widening dark field to attacker tradecraft. Intelligence services work more professionally and more covertly. Less capable attackers get new options from AI. The result is more incidents that companies sense but cannot document.

That matters well beyond Germany. Underwriters price cyber on loss data submitted by insureds. A market where detection confidence drops 20 points in a year is a market where the submitted numbers get softer, and where the gap between reported and actual loss widens without anyone being able to size it.

Cyber attacks now account for 76% of total damages, up from 70% last year and 59% five years ago. That share works out to between €160.4bn and €205.8bn.

Who German Companies Blame

Organized crime remains the largest perpetrator group at 62%, down from 68%. Foreign intelligence services sit second at 37%, up from 28% last year and 7% in 2023.

By origin, 52% of firms traced at least one attack to China and 49% to Russia. Eastern Europe outside the EU follows at 34%, the United States at 27%, other EU countries at 26% and Germany itself at 12%. Iran arrives as a new entrant at 9%, more than double last year’s 4%. China, Russia and Iran have all denied conducting cyber attacks abroad.

See also  Buy Coverage Now Before Cyber Insurance Premiums Increase: Gallagher

Read those figures as self-reported attribution rather than forensic attribution. Bitkom surveyed 1,003 companies with at least ten employees, and asked them where they believed attacks came from. Half of the firms that identified a perpetrator got help from German authorities, which strengthens the picture without turning it into evidence.

Wintergerst also notes the boundaries are porous. Intelligence services use criminal infrastructure, and criminals get latitude when their targets suit political direction.

What Actually Caused The Losses

The damage causes read like an underwriting questionnaire.

Companies that suffered losses point first to inadequate detection of security incidents, at 59%. Misconfigured IT systems follow at 57%, then weak identity and access management at 55%. Technical vulnerabilities come fourth at 50%, followed by outdated hardware or software at 43%.

Two figures cut against the prevailing narrative. Only 8% attribute compromise to an external service provider or supplier. And only 18% blame insufficient security awareness among staff. The failures are structural rather than human, which is consistent with what Verizon found this year.

One in five affected companies says the incident spread beyond its own walls, causing production outages at partners or reputational damage to clients. That is contingent business interruption described from the insured’s side, and it echoes the accumulation concerns Munich Re raised in earlier Cyber Insurance News reporting.

The Confidence Gap

Ransomware fell sharply. A quarter of all companies had data encrypted for extortion, down from 34% last year. Wintergerst credits preparation and wants the drop to become a trend rather than a blip.

AI-enabled methods moved the other way from a low base. Damaging automated robocalls jumped from 3% to 14%. Deepfakes doubled from 4% to 8%. Eight in ten companies assume attackers are increasing their use of AI, though only 31% are certain of it. The rest are guessing, which is the same measurement problem in miniature and a familiar one from this year’s AI incident response data.

See also  Roll Out of Lloyd's Cyber War Exclusion Dazes and Confuses Market 

The oddest number in the study is a pair. Companies rating themselves very well prepared fell from 50% to 43%. Companies that see a successful attack as a threat to their existence also fell, from 59% to 45%. Feeling less ready and less worried at the same time is what Wintergerst calls a deceptive sense of security, possibly a habituation effect.

Security spending sits still at 18% of the IT budget. Bitkom and the federal cyber agency both recommend 20%.

The Blind Spot Behind The Cyber Loss Data

One failure runs through the whole study. Inadequate detection is the leading cause of damage, named by 59% of firms that lost money. It is also the reason Bitkom could not publish a single number this year. The same blind spot lets an attack land, then hides what it cost.

That leaves the market in an awkward position. The losses are real. The submissions are honest. The figures underneath both are getting softer. Bitkom’s useful contribution was to print the uncertainty rather than round it away. Most loss studies do not.

FAQ – German Cyber Attack Losses

How large are German cyber attack losses in 2026?

Bitkom puts total damages from data theft, industrial espionage and sabotage at between €211bn and €270.8bn. Cyber attacks account for 76 percent of that, or roughly €160.4bn to €205.8bn. The association published a range this year rather than a single figure.

Why did Bitkom publish a range instead of a number?

Companies grew less able to confirm attacks. Firms certain of a successful attack fell from 87 to 67 percent, while those suspecting one without proof rose from 10 to 29 percent. The lower estimate counts proven cases, the upper adds suspected cases above the five-year average.

See also  China Releases Plan for Cyber Insurance Development

Which countries do German firms blame most?

China at 52 percent and Russia at 49 percent, followed by non-EU Eastern Europe at 34 percent and the United States at 27 percent. Iran entered at 9 percent. All three of China, Russia and Iran deny conducting cyber attacks abroad.

What caused the actual damage?

Inadequate detection of security incidents leads at 59 percent, followed by system misconfiguration at 57 percent and weak identity and access management at 55 percent. Only 8 percent cite an external provider or supplier, and 18 percent cite employee awareness.

Is ransomware still the main cyber threat in Germany?

It remains the most damaging single method, hitting 25 percent of all companies, but that is down sharply from 34 percent. AI-enabled methods rose from a low base, with damaging robocalls climbing from 3 to 14 percent and deepfakes doubling to 8 percent.

Leave a Comment

×