Some 87% of German companies were hit by data theft, espionage, or sabotage in the past twelve months, up from 81% a year earlier, according to the industry association Bitkom, which puts the resulting damage at €289.2bn.
What is new in this year’s report is not the trend but the method, because Bitkom has combined its company survey with assessments from Germany’s domestic intelligence service, in a country where public sector defences have been under sustained pressure.
That combination matters because attribution is the thing companies cannot do for themselves. A firm knows it was breached and rarely knows by whom, so pairing survey responses with state intelligence on active campaigns produces a picture neither source generates alone.
The attribution finding is the one worth pausing on. Russia and China are each blamed for 46% of externally attributed incidents, with Russia climbing from 39% the previous year to draw level with China.
Russia overtaking its own prior figure by seven points in a single year is a substantial move in a dataset this size. It also fits a broader European pattern of Russian activity shifting from espionage towards disruption, which Dutch authorities have documented while seizing 800 servers tied to Russian hacking operations.











