Decoding the world of cybersecurity

German cyber losses reach up to €205.8bn

Cyberattacks accounted for 76% of losses from data theft, industrial espionage, and sabotage in Germany, as more affected businesses associated incidents with foreign intelligence services.

German cyber losses reach up to €205.8bn
Summary
  • Bitkom estimates cyberattacks accounted for €160.4bn to €205.8bn of German losses from data theft, espionage, and sabotage.
  • Thirty-seven per cent of affected respondents associated at least one attack with a foreign intelligence service, up sharply from 2023.
  • Detection, configuration, and identity weaknesses were cited more often than technical vulnerabilities as reasons attacks caused damage.

Cyberattacks accounted for three-quarters of Germany’s estimated losses from data theft, industrial espionage, and sabotage over the past year, while a growing share of affected businesses said they associated attacks with foreign intelligence services.

A new survey from Bitkom puts overall losses from those activities at between €211 billion and €270.8 billion. Cyberattacks accounted for 76% of the total, equivalent to an estimated €160.4 billion to €205.8 billion.

The German digital industry association said 37% of businesses affected by data theft, industrial espionage, or sabotage associated at least one attack with a foreign intelligence service during the previous 12 months. That compares with 28% a year earlier and 7% in 2023. Organised crime remained the most commonly identified actor category.

The figures do not amount to independent attribution of individual cyber operations. They are based on the assessments of surveyed companies, supported in some cases by government information, internal or external investigations, technical indicators, and log analysis. Bitkom said half of companies that were able to identify an attacker or origin had received relevant information from public authorities.

The survey also points to a widening gap between suspected and demonstrably confirmed incidents. Although 96% of respondents said they had experienced or suspected data theft, espionage, or sabotage, the proportion able to say with certainty that a successful attack had taken place fell, while the proportion that suspected an attack but could not conclusively establish one rose.

That uncertainty is consequential in an environment where espionage, criminal intrusion, and disruptive activity increasingly overlap. A company can incur recovery costs, lose sensitive material, or pass disruption into its supply chain without obtaining the evidence needed to make a confident attribution. For management teams, insurers, regulators, and state agencies, incomplete visibility complicates both loss assessment and the construction of a reliable national threat picture.

Bitkom’s findings also give relatively little support to the idea that damage is dominated by exotic technical exploits. Among businesses that suffered cyber-related harm, insufficient incident detection was the most commonly cited contributing weakness, followed by misconfigured IT systems and inadequate identity and access management. Technical vulnerabilities and ageing hardware or software also featured prominently.

Those results put operational discipline alongside technology investment. A business that cannot reliably detect malicious activity, maintain secure configuration, or control access may struggle to establish what happened even after disruption becomes visible. That becomes particularly important when the suspected attacker is a state-linked actor whose objective may be long-term access, intelligence collection, or strategic disruption rather than immediate monetisation.

Cybersecurity spending has not risen in proportion to the reported threat. Bitkom said the share of IT budgets devoted to security remained at 18% on average, unchanged from the previous year. At the same time, 63% of respondents said cyberattacks had increased over the past 12 months, and 69% expected further growth during the coming year.

The survey covered 1,003 German companies with at least ten employees and annual revenue of at least €1 million. Bitkom introduced a loss range this year because more respondents could no longer say conclusively whether an attack had taken place, adding another measure of uncertainty to an already substantial estimate of the economic cost.

×