Aug 31, 2026 · 6 min read
German Firms Trace 37% of Attacks to Foreign Spies
Bitkom’s Wirtschaftsschutz 2026 survey, presented with Germany’s domestic intelligence service on 26 August 2026, puts a number on how far state actors have moved into ordinary corporate networks.
Three years ago, 7 percent of German companies that suffered data theft, industrial espionage or sabotage could point to a foreign intelligence service. This year the figure is 37 percent. Nothing about corporate Germany changed that fast; what changed is who is doing the attacking, and how well companies can now recognise it.
The survey was presented in Berlin by the industry association Bitkom together with the Bundesamt für Verfassungsschutz, and it ranks foreign services as the second most commonly named category of attacker, behind organised crime.
Key Takeaways
- Bitkom’s Wirtschaftsschutz 2026 survey of 1,003 German companies found 37 percent of affected firms blamed a foreign intelligence service, up from 28 percent in 2025 and 7 percent in 2023.
- Among affected companies, 52 percent traced an attack to China and 49 percent to Russia; Iran rose from 4 to 9 percent.
- Bitkom valued the annual damage from data theft, industrial espionage and sabotage at 211 to 270.8 billion euros, with cyberattacks accounting for 76 percent.
- Companies able to confirm an attack fell from 87 to 67 percent, while those suspecting one without proof rose from 10 to 29 percent.
- Espionage against digital communication was reported by 54 percent of affected companies, against 25 percent for ransomware.
What Did the Bitkom Study Actually Find?
It found that state directed attacks on German business went from niche to mainstream in three years. Bitkom polled 1,003 companies with at least ten employees by telephone between April and June 2026, and 96 percent said they were hit by, or suspect they were hit by, data theft, industrial espionage or sabotage.
Among affected firms, Bitkom recorded 62 percent naming organised crime, 37 percent a foreign intelligence service and 35 percent private individuals. Robocalls generated with AI jumped from 3 percent of incidents to 14 percent.
Why Did Confirmed Attacks Fall While the Damage Rose?
Because the attacks that announce themselves are being replaced by the ones that do not. Confirmed incidents dropped from 87 to 67 percent while unproven suspicion tripled, from 10 to 29 percent. Bitkom president Ralf Wintergerst summarised it in a line carried by the Bundesamt für Verfassungsschutz: the dark field is growing.
Most coverage read the drop in confirmed attacks as good news. Read the two figures together and the opposite case is stronger. Ransomware, which tells you it happened by encrypting your files, fell from 34 percent to 25 percent. Espionage against digital communication, which tells you nothing at all, sits at 54 percent.
Criminal groups need you to notice so they can be paid. A state collector needs you not to notice, for years.
Which Countries Are Named, and for What?
China and Russia are named at almost identical rates, but for different purposes. Of the companies that could attribute an attack, 52 percent pointed to China, 49 percent to Russia, 34 percent to non EU eastern Europe and 9 percent to Iran.
The split in intent matters more than the split in volume. As The Record reported on 27 August 2026, Chinese activity is described overwhelmingly as economic espionage aimed at technological advantage, while Russian activity skews towards sabotage and disinformation. One wants your files copied. The other wants your operations interrupted.
BfV president Sinan Selen framed the trend as foreign services having intensified their hybrid activities, and Wintergerst added the uncomfortable corollary: the line between organised crime and intelligence services is blurred.
Why Does State Espionage Land in the Inbox?
Because the mailbox is both the cheapest door into a company and one of the things worth stealing once inside. The ENISA Threat Landscape 2025 puts phishing at 60 percent of observed intrusion vectors across the EU, far ahead of anything else. Bitkom’s 54 percent for espionage against digital communication describes the other end of the same operation.
Two August 2026 cases show the full arc. US prosecutors charged 17 people tied to Iran’s Mabna Institute over a spearphishing campaign built on nothing more exotic than convincing credential harvesting pages. Days earlier the group tracked as Jewelbug walked out of a government webmail system with roughly 2,300 messages. Neither needed a zero day.
A German engineering firm’s mailbox is not merely a route to the file server. It holds supplier terms, unfiled patent drafts, and the name of everyone the company deals with. For an economic espionage programme the mail archive is often the objective, not the staging ground. That is why the 54 percent deserves more attention than the ransomware line it now dwarfs.
What This Means for Journalists, NGOs and Researchers
Anyone who reports on, contracts with, or studies these companies inherits their threat model without inheriting their security budget. A reporter covering German industrial policy corresponds with the same people a state collector wants, from a personal account, with no security operations centre behind it. The intermediary is the softer target.
Six days before the study, the BfV opened a helpline for people who fled Russia, China and Iran and now face surveillance inside Germany, naming journalists and dissidents among the intended callers. Two announcements from one agency in a week, one about corporate networks and one about exiled reporters, describe the same actors working two target lists. The tradecraft carries over: SilkParasite staged its spyware from an ordinary Google Drive folder and delivered the link by mail, which works identically on a procurement manager and a freelancer.
For a researcher the policy reading is sharper. A survey in which 29 percent of respondents suspect an incident they cannot prove has a large, growing, non random hole in it, and estimates built on self reported incidents understate state activity specifically, because state activity is the kind least likely to be detected. Treat 211 billion euros as a floor.
What Should a High Risk Reader Do Now?
Start with the account that takes unsolicited attachments from strangers, since that is the one being aimed at. These measures sit on top of the baseline in Germany’s annual BSI State of IT Security report, published in English.
- Move to phishing resistant authentication. Hardware keys or passkeys defeat the credential harvesting page these operations rely on. App based codes do not.
- Turn on your provider’s high risk account mode. Google Advanced Protection and Apple Lockdown Mode restrict the delivery paths these campaigns use.
- Audit third party access to your mailbox and revoke OAuth grants you no longer recognise. A persistent token survives a password change.
- Check forwarding rules monthly. A silent rule copying mail to an external address is standard persistence and leaves almost no other trace.
What to Watch Next
Watch whether the dark field keeps growing. If confirmed incidents fall again next year while the damage range climbs, the survey has stopped measuring attacks and started measuring detection. Watch the German response too, since legislators have already cleared the country’s intelligence services to hack and sabotage foreign infrastructure, a move justified in part by the escalation this survey documents. Escalation on both sides leaves the smallest actors, freelancers and civil society groups among them, carrying the risk with none of the budget.