HackMyIP
← Back to News
2026-08-27 The Record

German Companies Blame Chinese and Russian Spies for Surge in Cyberattacks

APTThreat IntelData Breach

Foreign intelligence services—particularly those operating out of China and Russia—are ramping up cyber operations against German companies, according to a new Bitkom survey of 1,003 firms with at least ten employees. Nearly four in ten organizations hit by data theft, industrial espionage, or sabotage in the past year attributed at least one incident to a state-sponsored actor, a sharp jump from 28% in 2024 and just 7% in 2023. China was the most frequently cited origin, with more than half of affected companies tracing at least one attack to Chinese-linked actors. Russia ranked second, while Iran emerged as a notable third source, implicated in roughly one in ten incidents. Sinan Selen, president of Germany's domestic intelligence agency (BfV), warned at the study's presentation that "foreign intelligence services have intensified their hybrid activities and are increasingly responsible for attacks on the German economy," singling out the country's security and defense sector as a prime target.

The financial impact is staggering. Bitkom estimates cyberattacks cost German businesses between $186 billion and $240 billion over the past year, factoring in business interruptions, forensic investigations, recovery operations, legal disputes, extortion payments, lost revenue, and eroded competitive advantage. More than two-thirds of surveyed companies reported at least one successful cyberattack in the last twelve months. Ransomware remained the dominant attack vector, with one in four firms stating that attackers encrypted their data and demanded payment for restoration. Phishing, password-spraying attacks, distributed denial-of-service campaigns, malware infections, communications interception, and corporate data theft rounded out the threat landscape. Bitkom President Ralf Wintergerst noted that the boundary between organized cybercrime syndicates and state intelligence services is increasingly porous: "Intelligence services utilize criminal structures, and conversely, criminals are given free rein as long as they choose their targets in accordance with political directives."

For organizations operating in high-value sectors, the findings underscore the urgency of validating exposure across the attack surface. Security teams can use a port scanner to identify externally exposed services that APT groups frequently target for initial access, while a DNS leak test helps confirm that internal DNS queries aren't leaking to adversary-controlled resolvers during reconnaissance. Given the prevalence of phishing and credential-based attacks in this dataset, employees should also run any suspicious credentials through a password checker to detect exposure in known breaches. As state-sponsored campaigns continue blurring the line between espionage and organized crime, proactive threat intelligence and continuous attack surface monitoring are no longer optional for European enterprises.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →