Cyber Risks 2026: The 10 Biggest Threats for German Companies
178.6 billion euros in damages from cybercrime in Germany – in 2024 alone. The BSI counts 309,000 new malware variants per day, DDoS attacks have doubled in the first half of the year, and 22 state-sponsored hacker groups operate actively on German soil. This article classifies the ten most dangerous threat scenarios for companies – with current figures from the BSI situation report, Bitkom study and ENISA Threat Landscape.
Key Takeaways
- 178.6 billion euros in cyber damages in Germany in 2024 – two-thirds of total economic crime losses. 81 percent of all companies affected (Bitkom Wirtschaftsschutz 2024).
- Cyber risk at number 1 of the Allianz Risk Barometer 2025 – the fourth year in a row, with a record gap of 7 percentage points to number 2 (Allianz).
- 309,000 new malware variants daily, up 26 percent on the previous year. 22 APT groups active in Germany (BSI Situation Report 2024).
- Germany was the most-attacked country globally for DDoS in Q1 2025 – ahead of Turkey and China (Cloudflare).
- ENISA Threat Landscape 2024: availability attacks (DDoS) in the number 1 spot for the first time, pushing ransomware to number 2.
The bigger picture: why 2026 is different
The threat landscape has shifted qualitatively over the past two years. Three trends are driving the escalation: AI-powered attack tools dramatically lower the entry barrier for attackers. Geopolitical conflicts put German companies in the crosshairs of state-sponsored groups. And the growing convergence of OT and IT systems opens attack surfaces that did not exist five years ago.
The Bitkom Wirtschaftsschutz 2024 study puts the total damage from theft, espionage and sabotage at 266.6 billion euros – a record, 43 billion more than in 2021. 178.6 billion euros of that is attributable to cybercrime. IT security spending rose 14 percent to more than 10 billion euros for the first time, but the gap between investment and damage keeps widening.
1. Ransomware: 950 reported attacks, 60 percent affected
The BKA documents 950 reported ransomware attacks on German companies and institutions – “two to three serious cases a day”. 72 percent of them use double extortion: data is both encrypted and published. The Bitkom study shows that 60 percent of German companies were affected over the past 12 months. Only 12.5 percent paid ransom – a drop that pushes attackers towards more aggressive methods.
ENISA moved ransomware from number 1 to number 2 in 2024 for the first time – not because ransomware is shrinking, but because DDoS is growing even faster.
2. DDoS attacks: Germany as the global top target
The BSI reports that DDoS attacks doubled in the first half of 2024. The share of high-volume attacks (above 10,000 Mbit/s) sat at 13 percent monthly – twice as high as the long-term average of 6.75 percent.
Cloudflare data for Q1 2025 confirms the trend: Germany was the most-attacked country globally for DDoS attacks, ahead of Turkey and China. Globally, DDoS attacks climbed to 20.5 million in a single quarter – a 358 percent increase year over year. ENISA now ranks availability attacks as the largest threat category for the first time.
3. State-sponsored attacks: 22 APT groups active in Germany
The BSI documents 22 different APT groups (Advanced Persistent Threats) operating on German soil between July 2023 and June 2024. Targets: companies, public authorities and political organizations.
A concrete case: APT29 (Russian foreign intelligence service SVR, “Cozy Bear”) sent spear-phishing emails in early 2024 disguised as invitations to a CDU dinner event – with a ROOTSAW dropper and WINELOADER payload. It was the first documented time that APT29 directly targeted a political party. APT28 (GRU, “Fancy Bear”) is running ongoing campaigns against defense companies and critical infrastructure. According to the Federal Office for the Protection of the Constitution, Germany’s consistent support for Ukraine makes the country a priority target.
4. Supply chain attacks: from 929 to 459,000 malicious packages
According to Sonatype, the number of malicious open-source packages has exploded from 929 (2020) to 459,070 (2024). More than 70 percent of organizations experienced at least one material supply chain attack in the past year.
The XZ Utils case (March 2024) shows the scale: an attacker invested years in social engineering to gain maintainer access to a core library. The backdoor (CVSS 10.0) targeted OpenSSH authentication and was only discovered by chance – a developer noticed an inexplicable 500-millisecond delay on SSH connections.
5. AI-powered attacks: phishing industrialized
AI has fundamentally lowered the entry barrier for phishing attacks. Industry data shows a 202 percent increase in phishing emails in the second half of 2024. AI helps attackers craft phishing emails up to 40 percent faster – with significantly better grammar and personalization than manually written messages.
Deepfake fraud is growing even faster: in Q1 2025 the industry already counted 179 deepfake incidents – more than in all of 2024 (150 cases). Financial losses from deepfake fraud exceeded 200 million USD in Q1 2025 alone.
6. Insider threats: 68 percent of all breaches involve a human factor
The Verizon Data Breach Investigations Report 2024 (30,458 incidents analyzed) shows that 68 percent of all breaches involve a non-malicious human factor – errors or social engineering victims. Stolen credentials have appeared in 31 percent of all breaches over the last ten years.
In healthcare, 70 percent of data protection breaches trace back to internal actors. Human errors (wrong email recipient, accidental cloud sharing) drive 28 percent of all breaches.
7. OT/IoT attacks: 900 million attacks and +114 percent
Nozomi Networks documents 900 million OT/IoT attacks in 2024 – an increase of 114 percent on the 420 million of the previous year. Germany ranks number 3 globally for IoT attacks (7 percent of all observed attacks), behind the US (54 percent) and Hong Kong (15 percent).
Particularly critical: the energy sector saw a 459 percent increase in IoT malware activity against electricity and oil/gas companies. The growing interconnection of OT systems with IT networks creates attack surfaces that classic network segmentation alone can no longer contain.
8. Malware evolution: 256 percent more 64-bit Windows exploits
The BSI registers 309,000 new malware variants per day – 26 percent more than in the previous year. Particularly notable: malware exploiting vulnerabilities in 64-bit Windows versions is up 256 percent. Android malware grew 48 percent, and 6 of the 10 most active botnets specifically target Android devices.
In parallel, 78 new security vulnerabilities were discovered per day – 14 percent more than in the previous year. CISA registered a total of 619 ICS-CERT vulnerabilities in industrial control systems in 2024.
“Cyber incidents rank at number 1 of the Allianz Risk Barometer for the fourth year in a row – with the biggest gap ever. Ten years ago, cyber risk was still at number 8.”
– Allianz Risk Barometer, January 2025, translated
9. Cloud misconfigurations and identity attacks
Cloud misconfigurations remain one of the most common causes of data breaches. Microsoft blocks 600 million identity attacks per day, including 7,000 password attacks per second. Only 41 percent of Entra enterprise users are protected by MFA – a gap that attackers systematically exploit.
Identity-based attacks make up the bulk of all compromises: stolen credentials were the cause of 22 percent of all data breaches in 2024 (Verizon DBIR). Adaptive MFA and passkeys are the most effective countermeasures.
10. Regulatory pressure: NIS2, DORA and CRA in parallel
2026 is the year in which three EU regulations apply in parallel: NIS2 (in force since December 2025, 29,500 companies), DORA (financial sector) and the Cyber Resilience Act (CRA, from 2027 for connected products). The compliance burden is a threat of its own for many companies – especially in the Mittelstand: skilled staff are missing, budgets are limited, and the reporting obligations (24 hours to the BSI, 72 hours to the data protection authority) require processes that many have not yet implemented.
ENISA Top 7 threat categories 2024
| # | Threat category | Change |
|---|---|---|
| 1 | Availability attacks (DDoS) | New at number 1 |
| 2 | Ransomware | Dropped from number 1 |
| 3 | Threats Against Data | Stable |
| 4 | Malware | Stable |
| 5 | Social Engineering | Stable |
| 6 | Information Manipulation | Stable |
| 7 | Supply Chain Attacks | Stable |
Conclusion: the threat is structural, not cyclical
The numbers don’t show cyclical swings but a structural shift. AI-powered attacks, geopolitical escalation and regulatory pressure create a triple burden that the security budgets and staff capacities of many companies cannot keep up with. The answer is not a single tool, but an integrated approach: prevention (Adaptive MFA, Zero Trust), detection (SIEM, ITDR), response (a tested incident response plan) and compliance (NIS2 reporting chains).
First step: match your own risk landscape against the ENISA Top 7. Which scenarios are most relevant for your organization? Where are the biggest gaps between threat and protective measure? This prioritization costs one workshop afternoon – and prevents budget from flowing into the wrong measures.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What are the biggest cyber threats to German companies in 2026?
According to the BSI situation report and ENISA, DDoS attacks (now number 1), ransomware (number 2) and supply chain attacks are the biggest threats. Complemented by 22 active APT groups in Germany and the industrialization of AI-powered phishing. Total damages in 2024 came to 178.6 billion euros (Bitkom).
How many cyber attacks are there daily in Germany?
The BSI registers 309,000 new malware variants per day. Microsoft blocks 600 million identity attacks globally per day. The BKA reports “two to three serious ransomware cases a day” being filed. The actual number is significantly higher, because many incidents are not reported.
Why is Germany a prime target for cyber attacks?
Three factors: Germany’s consistent support for Ukraine makes it a priority target for Russian APT groups (BfV assessment). The export-heavy economy with a lot of intellectual property attracts industrial espionage. And the high OT/IT convergence in industry (mechanical engineering, automotive, chemicals) offers a large attack surface. In Q1 2025, Germany was the most-attacked country worldwide for DDoS.
What does a cyber attack cost a German company?
According to the IBM Cost of a Data Breach Report 2024, an average of 4.9 million euros per incident – the highest figure in the study’s history. In 2025 the figure dropped to 3.87 million euros for the first time, among other things due to AI-based SOC tools that can shorten the breach lifecycle by up to 89 days.
How can companies protect themselves against the top threats?
An integrated approach: Adaptive MFA and Zero Trust for identity protection (addresses ransomware entry and credential theft). SIEM and ITDR for detection. A tested incident response plan with NIS2 reporting chains (24h BSI, 72h data protection authority). Supply chain security through SBOM and vendor assessments. And regular tabletop exercises, which are mandatory under NIS2.
Editor’s picks
- Cybersecurity trends 2026: seven developments
- Adaptive MFA 2026: how risk-based authentication replaces standard MFA
- Incident response plan 2026: NIS2 reporting duties and checklist
Further reading in the MBF Media network
- → cloudmagazin – Cloud, SaaS and IT infrastructure
- → Digital Chiefs – strategies for IT decision makers
- → MyBusinessFuture – digitalization in the Mittelstand
Cover image source: Pexels / Tima Miroshnichenko (px:5380664)