Security1 distinct publisher3 min readPublished
German firms' own attribution of attacks to state services has moved from 7% to nearly 40% in two years. That puts nation-state tradecraft on the risk register of any mid-sized manufacturer with a supplier list.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Attribution is the soft joint in this data. Bitkom asked 1,003 companies who attacked them and reported the answers, and the published account does not describe how any respondent reached the judgment that a foreign intelligence service was involved [1][19]. Bitkom's own president supplies the reason to hold the figure loosely: intelligence services use criminal infrastructure, and criminal crews are left alone where their targets suit political direction [12]. Some of what sits in the organized crime column belongs in the state column, and some state attributions are inference drawn from tradecraft that criminals also use [13].
The shape of the curve is more useful than the top line. The step happened last year. Seven per cent to 28% is a fourfold move; 28% to nearly 40% is about 1.4x, or twelve points [2][3][2]. Across both years the multiple is 5.7x [1]. Read that as one reclassification event followed by a year of confirmation rather than a rate that quadruples again.
Base sizes matter, because percentages of subsets get quoted as percentages of everything. More than two thirds of 1,003 firms reported a successful attack in the past 12 months, so at least 669 companies [1][7][4]. Nearly 40% of that group is roughly 270 [5]. The bases are not identical, since the espionage question was put to firms hit by data theft, industrial espionage or sabotage [2], so 270 is an order of magnitude, not a count.
Ransomware, at one in four firms, tends to report itself the day it happens [9], while collection rarely does. The same respondents listed communications interception and corporate data theft among what they saw [14], and those are found in log retention windows or not at all. That is the practical difference between the two threat models sitting in the same survey: one is a restore-time problem, the other is a dwell-time problem, and only the second one is affected by how long you keep egress records.
Three named German incidents from this year sit in the reporting around the survey. Lidl disclosed a breach in July after attackers reached customer data held by one of its IT service providers [16]. In April, external billing provider Unimed was targeted, and several university hospitals later said patient information had been stolen [17]. In January the Dresden State Art Collections lost large parts of its digital infrastructure to a targeted attack [18]. Two of the three reached the victim through somebody else's estate [6], which is also where Bitkom puts the knock-on damage: production stoppages at business partners, reputational damage to customers [15].
On the money, Bitkom's range is $186bn to $240bn for the year [8]. Midpoint $213bn, spread $54bn, about a quarter of the midpoint [3]. That is a directional figure for a ministry, and one unlikely to hold its shape once a budget committee starts asking where the number came from.
Ranked by verification strength, evidence, and original report placement.
Bitkom's findings are based on a survey of 1,003 German companies with at least 10 employees.
Nearly four in 10 German companies hit by data theft, industrial espionage or sabotage over the past year attributed at least one incident to a foreign intelligence service.
That figure is up from 28% last year and just 7% in 2023.
Foreign intelligence services are now the second-most commonly blamed attackers of German companies, behind only organized crime.
China was the most frequently cited foreign source of attacks: more than half of companies that experienced an incident said they traced at least one attack to China, with Russia ranking second.
Roughly one in 10 affected companies linked an incident to Iran.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A vCenter bug patched on July 29 is already a ransomware chain, not a ticket1 distinct publisher
product
Nine PBS is suing its dead vendor's landlord, and the colo contract holds the keys3 distinct publishers
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
security
KISA's Rhysida decrypter works, and at least four people found the bug that makes it possible1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One named survey, one publisher, no method disclosure
The quantitative core is a disclosed, reasonably large sample (1,003 German firms with 10+ employees) with named spokespeople from Bitkom and the domestic intelligence agency, which lifts it above anonymous vendor telemetry. But the cluster contains a single publisher reporting a single association study, the attribution shares are self-reported by respondents with no stated method, and the cost range is an association estimate rather than an audited loss figure.
Broad self-reported incidence, three concretely named cases
Real-world incidence is documented at two levels: survey-scale prevalence (more than two-thirds of firms reporting a successful attack, one in four hit by ransomware) and three specifically named German incidents this year, two of which arrived through an external service provider. That is more than an isolated anecdote but still rests on one survey plus three cases, none independently detailed here.
Real trend, but self-attribution carries the headline
The direction of travel is plausibly real and the reporting is restrained in tone, yet the most striking number - a 5.7x jump in state attribution in two years - is respondent belief with no stated attribution method, and the piece does not consider that rising awareness, briefings and press coverage could inflate self-attribution independently of actual state activity. The $186bn-$240bn cost range is presented without derivation. Modestly overstated relative to what the supplied evidence can bear.
Industry association plus intelligence agency, both served by threat salience
The data owner is a digital industry association whose members sell and buy security capability, and the study was presented alongside the president of Germany's domestic intelligence agency, who used the platform to stress intensified hybrid activity and the exposure of the defense industry. Both parties benefit from elevated threat salience - budget, mandate and policy attention - and no independent counterparty is quoted in the piece.
Directionally credible, single-source and self-reported
Confidence is moderate: the sample and spokespeople are named and the concrete incidents are checkable, but the cluster has one publisher, one underlying study, unverified respondent attribution and interested sponsors. The trend is credible enough to act on for planning; the precise shares and cost range should not be treated as settled.