Estimated reading time: 6 minutes
Bitkom has published a single headline damage figure for German industry every year for a decade. This year it published two.
The digital association put losses from data theft, industrial espionage, and sabotage at somewhere between €211bn and €270.8bn over the past twelve months. The reason for the corridor sits in the methodology note. Companies have stopped being able to tell whether they were attacked.
Firms that could confirm a successful attack with certainty fell to 67%, down from 87% a year ago. Firms that suspect an attack but cannot prove one rose from 10% to 29%. Bitkom built the lower end of its range from companies that can demonstrate a breach, and the upper end by adding the suspected cases that exceed the five-year average.

Why German Cyber Attack Losses Got A Range
Bitkom president Ralf Wintergerst attributes the widening dark field to attacker tradecraft. Intelligence services work more professionally and more covertly. Less capable attackers get new options from AI. The result is more incidents that companies sense but cannot document.
That matters well beyond Germany. Underwriters price cyber on loss data submitted by insureds. A market where detection confidence drops 20 points in a year is a market where the submitted numbers get softer, and where the gap between reported and actual loss widens without anyone being able to size it.
Cyber attacks now account for 76% of total damages, up from 70% last year and 59% five years ago. That share works out to between €160.4bn and €205.8bn.
Who German Companies Blame
Organized crime remains the largest perpetrator group at 62%, down from 68%. Foreign intelligence services sit second at 37%, up from 28% last year and 7% in 2023.
By origin, 52% of firms traced at least one attack to China and 49% to Russia. Eastern Europe outside the EU follows at 34%, the United States at 27%, other EU countries at 26% and Germany itself at 12%. Iran arrives as a new entrant at 9%, more than double last year’s 4%. China, Russia and Iran have all denied conducting cyber attacks abroad.
Read those figures as self-reported attribution rather than forensic attribution. Bitkom surveyed 1,003 companies with at least ten employees, and asked them where they believed attacks came from. Half of the firms that identified a perpetrator got help from German authorities, which strengthens the picture without turning it into evidence.
Wintergerst also notes the boundaries are porous. Intelligence services use criminal infrastructure, and criminals get latitude when their targets suit political direction.
What Actually Caused The Losses
The damage causes read like an underwriting questionnaire.
Companies that suffered losses point first to inadequate detection of security incidents, at 59%. Misconfigured IT systems follow at 57%, then weak identity and access management at 55%. Technical vulnerabilities come fourth at 50%, followed by outdated hardware or software at 43%.
Two figures cut against the prevailing narrative. Only 8% attribute compromise to an external service provider or supplier. And only 18% blame insufficient security awareness among staff. The failures are structural rather than human, which is consistent with what Verizon found this year.
One in five affected companies says the incident spread beyond its own walls, causing production outages at partners or reputational damage to clients. That is contingent business interruption described from the insured’s side, and it echoes the accumulation concerns Munich Re raised in earlier Cyber Insurance News reporting.
The Confidence Gap
Ransomware fell sharply. A quarter of all companies had data encrypted for extortion, down from 34% last year. Wintergerst credits preparation and wants the drop to become a trend rather than a blip.
AI-enabled methods moved the other way from a low base. Damaging automated robocalls jumped from 3% to 14%. Deepfakes doubled from 4% to 8%. Eight in ten companies assume attackers are increasing their use of AI, though only 31% are certain of it. The rest are guessing, which is the same measurement problem in miniature and a familiar one from this year’s AI incident response data.
The oddest number in the study is a pair. Companies rating themselves very well prepared fell from 50% to 43%. Companies that see a successful attack as a threat to their existence also fell, from 59% to 45%. Feeling less ready and less worried at the same time is what Wintergerst calls a deceptive sense of security, possibly a habituation effect.
Security spending sits still at 18% of the IT budget. Bitkom and the federal cyber agency both recommend 20%.
The Blind Spot Behind The Cyber Loss Data
One failure runs through the whole study. Inadequate detection is the leading cause of damage, named by 59% of firms that lost money. It is also the reason Bitkom could not publish a single number this year. The same blind spot lets an attack land, then hides what it cost.
That leaves the market in an awkward position. The losses are real. The submissions are honest. The figures underneath both are getting softer. Bitkom’s useful contribution was to print the uncertainty rather than round it away. Most loss studies do not.
FAQ – German Cyber Attack Losses
How large are German cyber attack losses in 2026?
Bitkom puts total damages from data theft, industrial espionage and sabotage at between €211bn and €270.8bn. Cyber attacks account for 76 percent of that, or roughly €160.4bn to €205.8bn. The association published a range this year rather than a single figure.
Why did Bitkom publish a range instead of a number?
Companies grew less able to confirm attacks. Firms certain of a successful attack fell from 87 to 67 percent, while those suspecting one without proof rose from 10 to 29 percent. The lower estimate counts proven cases, the upper adds suspected cases above the five-year average.
Which countries do German firms blame most?
China at 52 percent and Russia at 49 percent, followed by non-EU Eastern Europe at 34 percent and the United States at 27 percent. Iran entered at 9 percent. All three of China, Russia and Iran deny conducting cyber attacks abroad.
What caused the actual damage?
Inadequate detection of security incidents leads at 59 percent, followed by system misconfiguration at 57 percent and weak identity and access management at 55 percent. Only 8 percent cite an external provider or supplier, and 18 percent cite employee awareness.
Is ransomware still the main cyber threat in Germany?
It remains the most damaging single method, hitting 25 percent of all companies, but that is down sharply from 34 percent. AI-enabled methods rose from a low base, with damaging robocalls climbing from 3 to 14 percent and deepfakes doubling to 8 percent.
Related Cyber Insurance Posts
- Residential Proxy Risk: The Employee Earns Pennies, The Buyer Gets The Router
- Nobody Owns The Password. Passpack CEO Chris Skipworth Explains The Credential Gap Sitting Inside Your Next Renewal – Cyber Insurance News PODCAST
- Coalition Introduces Active Cyber Insurance in Germany(Opens in a new browser tab)
- BOXX Insurance Expands Cyber Insurance Protection(Opens in a new browser tab)
- 73% of Irish Workers Feel Blamed for Cybersecurity Breaches, Study Reveals(Opens in a new browser tab)