Foreign Intelligence Now Behind More Than a Third of German Cyberattacks
Germany's cyberattacks are increasingly the work of state actors, not just criminal gangs chasing a payday. New data shows that foreign intelligence services were linked to 37% of attributed cyberattacks against German companies in 2026, a fivefold jump from just 7% in 2023. That shift marks a fundamental change in who is targeting German businesses and why, moving the conversation from opportunistic cybercrime toward organized, state-backed espionage.
The timing matters. This surge comes as artificial intelligence tools make it faster and cheaper for attackers, whether criminal or state-sponsored, to scan for vulnerabilities, automate phishing campaigns, and scale up intrusion attempts. AI isn't creating a new category of threat so much as it's supercharging the volume and speed of existing ones, letting fewer operators do more damage across more targets at once.
A Ransomware Standoff With National Security Stakes
The most visible flashpoint in this trend involves the Rhysida ransomware group, which claimed to have exfiltrated 5.79 terabytes of German state data from a network breach that occurred ahead of an election. Berlin refused to pay the ransom demand, a decision that underscores how governments are increasingly treating ransomware incidents involving state data as matters of national security rather than simple extortion to be quietly resolved.
That refusal echoes a broader pattern playing out globally. Organizations that pay ransomware groups can face serious legal exposure, particularly when the attackers are tied to sanctioned entities or hostile states. As outlined in our coverage of ransomware payments and OFAC sanctions risk, firms and governments alike are under growing pressure to avoid payments that could inadvertently fund sanctioned actors, even when the immediate cost is stolen data sitting on a criminal group's servers.
The blending of criminal ransomware tactics with state-level targets, especially around sensitive political moments like elections, illustrates why attribution has become so difficult and so important. A ransomware group's public claims don't always tell the full story of who ordered the operation or why.
Why Attribution Is Getting Harder, Not Easier
One of the more troubling threads in Germany's cyberattack data is that companies are struggling simply to confirm intrusions occurred and to identify who was responsible. This isn't unique to Germany. State-linked cyber operations increasingly borrow techniques from criminal ransomware crews, and criminal groups sometimes operate with tacit approval or resources from state actors, blurring the line between espionage and financially motivated crime.
This pattern isn't confined to Germany, either. Critical infrastructure elsewhere has faced similar state-linked intrusions, as seen when an Iranian-linked cyberattack hit water systems across Minnesota, showing how foreign intelligence-adjacent actors are willing to target infrastructure well beyond traditional espionage targets like defense contractors or government ministries. Germany's experience, with foreign intelligence services now implicated in over a third of attacks, fits into this wider trend of nation-states normalizing cyber operations against companies and public systems alike.
Governments are responding by expanding their own investigative powers, too. South Korea recently moved to let its intelligence service probe corporate hacks based on suspicion alone, a step detailed in our report on South Korea's NIS gaining new investigative authority. Germany's rising foreign intelligence attack numbers may prompt similar debates domestically about how much authority security agencies need to investigate and attribute state-linked breaches.
What This Means For You
If you work at a German company, or any organization handling sensitive data connected to critical infrastructure, elections, or government contracts, this data is a signal to reassess your threat model. Foreign intelligence services don't necessarily behave like typical ransomware crews. Their goals may include long-term data collection, disruption timed to political events, or positioning for future operations rather than a quick payout.
For everyday consumers and employees, the practical takeaway is more modest but still important. AI-accelerated attacks mean phishing emails, fake login pages, and social engineering attempts will likely become more convincing and more frequent. Basic hygiene, unique passwords, multi-factor authentication, and skepticism toward unexpected login prompts, matters more now, not less.
Key Takeaways
Germany's jump from 7% to 37% in foreign intelligence-linked cyberattacks over three years shows that state-sponsored threats are no longer a niche concern reserved for defense and government sectors. Companies across industries should treat unexplained network anomalies as potentially state-linked until proven otherwise, invest in incident response plans that account for ransomware demands tied to sensitive data, and stay alert to AI-enhanced phishing and intrusion attempts. Berlin's refusal to pay Rhysida's ransom demand reflects a broader shift toward treating these incidents as strategic threats rather than routine cybercrime, a mindset every organization handling valuable data should start adopting too.




