THREAT BRIEFING · 10.09.2026 DEENFRES

Strategy & Governance

Cyber Risks 2026: The 10 Biggest Threats for German Companies

By Benedikt Langer · March 24, 2026 · 11 min read

178.6 billion euros in damages from cybercrime in Germany – in 2024 alone. The BSI counts 309,000 new malware variants per day, DDoS attacks have doubled in the first half of the year, and 22 state-sponsored hacker groups operate actively on German soil. This article classifies the ten most dangerous threat scenarios for companies – with current figures from the BSI situation report, Bitkom study and ENISA Threat Landscape.

Key Takeaways

The bigger picture: why 2026 is different

The threat landscape has shifted qualitatively over the past two years. Three trends are driving the escalation: AI-powered attack tools dramatically lower the entry barrier for attackers. Geopolitical conflicts put German companies in the crosshairs of state-sponsored groups. And the growing convergence of OT and IT systems opens attack surfaces that did not exist five years ago.

The Bitkom Wirtschaftsschutz 2024 study puts the total damage from theft, espionage and sabotage at 266.6 billion euros – a record, 43 billion more than in 2021. 178.6 billion euros of that is attributable to cybercrime. IT security spending rose 14 percent to more than 10 billion euros for the first time, but the gap between investment and damage keeps widening.

EUR 178.6 bn
Damage from cybercrime in Germany in 2024 – a record
Source: Bitkom Wirtschaftsschutz, August 2024

1. Ransomware: 950 reported attacks, 60 percent affected

The BKA documents 950 reported ransomware attacks on German companies and institutions – “two to three serious cases a day”. 72 percent of them use double extortion: data is both encrypted and published. The Bitkom study shows that 60 percent of German companies were affected over the past 12 months. Only 12.5 percent paid ransom – a drop that pushes attackers towards more aggressive methods.

ENISA moved ransomware from number 1 to number 2 in 2024 for the first time – not because ransomware is shrinking, but because DDoS is growing even faster.

2. DDoS attacks: Germany as the global top target

The BSI reports that DDoS attacks doubled in the first half of 2024. The share of high-volume attacks (above 10,000 Mbit/s) sat at 13 percent monthly – twice as high as the long-term average of 6.75 percent.

Cloudflare data for Q1 2025 confirms the trend: Germany was the most-attacked country globally for DDoS attacks, ahead of Turkey and China. Globally, DDoS attacks climbed to 20.5 million in a single quarter – a 358 percent increase year over year. ENISA now ranks availability attacks as the largest threat category for the first time.

3. State-sponsored attacks: 22 APT groups active in Germany

The BSI documents 22 different APT groups (Advanced Persistent Threats) operating on German soil between July 2023 and June 2024. Targets: companies, public authorities and political organizations.

A concrete case: APT29 (Russian foreign intelligence service SVR, “Cozy Bear”) sent spear-phishing emails in early 2024 disguised as invitations to a CDU dinner event – with a ROOTSAW dropper and WINELOADER payload. It was the first documented time that APT29 directly targeted a political party. APT28 (GRU, “Fancy Bear”) is running ongoing campaigns against defense companies and critical infrastructure. According to the Federal Office for the Protection of the Constitution, Germany’s consistent support for Ukraine makes the country a priority target.

4. Supply chain attacks: from 929 to 459,000 malicious packages

According to Sonatype, the number of malicious open-source packages has exploded from 929 (2020) to 459,070 (2024). More than 70 percent of organizations experienced at least one material supply chain attack in the past year.

The XZ Utils case (March 2024) shows the scale: an attacker invested years in social engineering to gain maintainer access to a core library. The backdoor (CVSS 10.0) targeted OpenSSH authentication and was only discovered by chance – a developer noticed an inexplicable 500-millisecond delay on SSH connections.

5. AI-powered attacks: phishing industrialized

AI has fundamentally lowered the entry barrier for phishing attacks. Industry data shows a 202 percent increase in phishing emails in the second half of 2024. AI helps attackers craft phishing emails up to 40 percent faster – with significantly better grammar and personalization than manually written messages.

Deepfake fraud is growing even faster: in Q1 2025 the industry already counted 179 deepfake incidents – more than in all of 2024 (150 cases). Financial losses from deepfake fraud exceeded 200 million USD in Q1 2025 alone.

6. Insider threats: 68 percent of all breaches involve a human factor

The Verizon Data Breach Investigations Report 2024 (30,458 incidents analyzed) shows that 68 percent of all breaches involve a non-malicious human factor – errors or social engineering victims. Stolen credentials have appeared in 31 percent of all breaches over the last ten years.

In healthcare, 70 percent of data protection breaches trace back to internal actors. Human errors (wrong email recipient, accidental cloud sharing) drive 28 percent of all breaches.

7. OT/IoT attacks: 900 million attacks and +114 percent

Nozomi Networks documents 900 million OT/IoT attacks in 2024 – an increase of 114 percent on the 420 million of the previous year. Germany ranks number 3 globally for IoT attacks (7 percent of all observed attacks), behind the US (54 percent) and Hong Kong (15 percent).

Particularly critical: the energy sector saw a 459 percent increase in IoT malware activity against electricity and oil/gas companies. The growing interconnection of OT systems with IT networks creates attack surfaces that classic network segmentation alone can no longer contain.

8. Malware evolution: 256 percent more 64-bit Windows exploits

The BSI registers 309,000 new malware variants per day – 26 percent more than in the previous year. Particularly notable: malware exploiting vulnerabilities in 64-bit Windows versions is up 256 percent. Android malware grew 48 percent, and 6 of the 10 most active botnets specifically target Android devices.

In parallel, 78 new security vulnerabilities were discovered per day – 14 percent more than in the previous year. CISA registered a total of 619 ICS-CERT vulnerabilities in industrial control systems in 2024.

“Cyber incidents rank at number 1 of the Allianz Risk Barometer for the fourth year in a row – with the biggest gap ever. Ten years ago, cyber risk was still at number 8.”
– Allianz Risk Barometer, January 2025, translated

9. Cloud misconfigurations and identity attacks

Cloud misconfigurations remain one of the most common causes of data breaches. Microsoft blocks 600 million identity attacks per day, including 7,000 password attacks per second. Only 41 percent of Entra enterprise users are protected by MFA – a gap that attackers systematically exploit.

Identity-based attacks make up the bulk of all compromises: stolen credentials were the cause of 22 percent of all data breaches in 2024 (Verizon DBIR). Adaptive MFA and passkeys are the most effective countermeasures.

10. Regulatory pressure: NIS2, DORA and CRA in parallel

2026 is the year in which three EU regulations apply in parallel: NIS2 (in force since December 2025, 29,500 companies), DORA (financial sector) and the Cyber Resilience Act (CRA, from 2027 for connected products). The compliance burden is a threat of its own for many companies – especially in the Mittelstand: skilled staff are missing, budgets are limited, and the reporting obligations (24 hours to the BSI, 72 hours to the data protection authority) require processes that many have not yet implemented.

ENISA Top 7 threat categories 2024

# Threat category Change
1 Availability attacks (DDoS) New at number 1
2 Ransomware Dropped from number 1
3 Threats Against Data Stable
4 Malware Stable
5 Social Engineering Stable
6 Information Manipulation Stable
7 Supply Chain Attacks Stable

Conclusion: the threat is structural, not cyclical

The numbers don’t show cyclical swings but a structural shift. AI-powered attacks, geopolitical escalation and regulatory pressure create a triple burden that the security budgets and staff capacities of many companies cannot keep up with. The answer is not a single tool, but an integrated approach: prevention (Adaptive MFA, Zero Trust), detection (SIEM, ITDR), response (a tested incident response plan) and compliance (NIS2 reporting chains).

First step: match your own risk landscape against the ENISA Top 7. Which scenarios are most relevant for your organization? Where are the biggest gaps between threat and protective measure? This prioritization costs one workshop afternoon – and prevents budget from flowing into the wrong measures.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What are the biggest cyber threats to German companies in 2026?

According to the BSI situation report and ENISA, DDoS attacks (now number 1), ransomware (number 2) and supply chain attacks are the biggest threats. Complemented by 22 active APT groups in Germany and the industrialization of AI-powered phishing. Total damages in 2024 came to 178.6 billion euros (Bitkom).

How many cyber attacks are there daily in Germany?

The BSI registers 309,000 new malware variants per day. Microsoft blocks 600 million identity attacks globally per day. The BKA reports “two to three serious ransomware cases a day” being filed. The actual number is significantly higher, because many incidents are not reported.

Why is Germany a prime target for cyber attacks?

Three factors: Germany’s consistent support for Ukraine makes it a priority target for Russian APT groups (BfV assessment). The export-heavy economy with a lot of intellectual property attracts industrial espionage. And the high OT/IT convergence in industry (mechanical engineering, automotive, chemicals) offers a large attack surface. In Q1 2025, Germany was the most-attacked country worldwide for DDoS.

What does a cyber attack cost a German company?

According to the IBM Cost of a Data Breach Report 2024, an average of 4.9 million euros per incident – the highest figure in the study’s history. In 2025 the figure dropped to 3.87 million euros for the first time, among other things due to AI-based SOC tools that can shorten the breach lifecycle by up to 89 days.

How can companies protect themselves against the top threats?

An integrated approach: Adaptive MFA and Zero Trust for identity protection (addresses ransomware entry and credential theft). SIEM and ITDR for detection. A tested incident response plan with NIS2 reporting chains (24h BSI, 72h data protection authority). Supply chain security through SBOM and vendor assessments. And regular tabletop exercises, which are mandatory under NIS2.

Editor’s picks

  • Cybersecurity trends 2026: seven developments
  • Adaptive MFA 2026: how risk-based authentication replaces standard MFA
  • Incident response plan 2026: NIS2 reporting duties and checklist

Further reading in the MBF Media network

  • cloudmagazin – Cloud, SaaS and IT infrastructure
  • Digital Chiefs – strategies for IT decision makers
  • MyBusinessFuture – digitalization in the Mittelstand

Cover image source: Pexels / Tima Miroshnichenko (px:5380664)

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH