A sweeping new survey of German businesses reveals a dramatic escalation in state-sponsored cyber-attacks — and serves as a warning to Western countries that the same forces are almost certainly targeting them too. According to research by Bitkom, Germany's leading digital industry association, roughly four in ten German companies hit by cyber-attacks in the past year attribute at least one incident to a foreign intelligence service. China was cited most frequently, accounting for more than half of all incidents, with Russia close behind. Iran has now emerged as a significant third source.

How quickly has the threat from foreign intelligence services grown?

The scale of the shift is stark. The share of companies attributing attacks to foreign intelligence services has risen from just 7 per cent in 2023, to 28 per cent in 2025, to roughly 40 per cent today — nearly a six-fold increase in three years. Bitkom's survey covered 1,003 German companies across sectors, making it one of the most comprehensive snapshots of the corporate cyber-threat landscape in Europe.

Foreign intelligence services are now the second-most commonly blamed source of attacks on German companies, behind only organized crime. Germany's security and defense industries are identified as particularly attractive targets, given the volume of sensitive technology, procurement intelligence, and strategic information they hold.

The economic cost of cyber-attacks on Germany

The financial damage is immense. Bitkom estimates that cyber-attacks cost German businesses between $186 billion and $240 billion over the past year alone. That figure encompasses business interruptions, forensic investigation costs, recovery and remediation, legal disputes, extortion payments, lost revenue, and eroded competitive advantage. It does not capture the harder-to-quantify cost of stolen intellectual property — technology and trade secrets that may benefit foreign competitors for years.

Where does organized crime end and state espionage begin?

One of the most significant findings concerns the increasingly blurred line between criminal hackers and state intelligence operations. Bitkom President Ralf Wintergerst put it plainly: "The lines between organized crime and intelligence services are blurred in many countries. Intelligence services utilize criminal structures, and conversely, criminals are given free rein as long as they choose their targets in accordance with political directives."

This convergence makes attribution harder and defensive strategy more complex. An attack that looks like ransomware may simultaneously serve an intelligence-gathering purpose. An intrusion carried out by a criminal group may be tolerated or directed by a state actor operating in the background.

Germany's domestic intelligence chief sounds the alarm

Sinan Selen, president of Germany's domestic intelligence agency, the Bundesamt für Verfassungsschutz (BfV), was direct about the trend: "Foreign intelligence services have intensified their hybrid activities and are increasingly responsible for attacks on the German economy."

The use of the word "hybrid" is deliberate. State-sponsored cyber operations against corporations do not occur in isolation — they are part of a broader pattern of hybrid warfare that includes disinformation, infrastructure probing, and economic coercion.

Why this is a warning for the US, UK, and all Western allies

Germany is not a unique target. It is a canary. The same foreign intelligence services — Chinese, Russian, and Iranian — are actively targeting allied economies. There is no reason to assume the penetration rates among US or UK companies are lower; they may well be higher, given the volume of defense, financial, and technology assets those countries hold.

The Bitkom data provides the kind of rigorous, survey-based evidence that is often lacking in cyber-threat discussions dominated by anecdote and vendor-driven reports. The finding that 40 per cent of attacked companies now trace incidents to foreign intelligence agencies suggests that state-sponsored cyber operations have moved from exceptional to routine — and that corporate security strategies built around criminal threat models are no longer fit for purpose.