Article Content

MarketFlick Insights

German Security Service Warns of Rising Foreign Intelligence Attacks on Companies

Wednesday, August 26, 2026
4 min read
German Security Service Warns of Rising Foreign Intelligence Attacks on Companies

At a glance

  • A growing share of cyber incidents affecting German companies are attributed to foreign intelligence services up to 37 percent in 2026 among affected firms.
  • China (52 percent) and Russia (49 percent) are the most frequently cited origins of identified attacks.
  • Bitkom estimates the economic damage from data theft, industrial espionage and sabotage at between €211 billion and €271 billion in the past year.
  • Artificial intelligence is increasingly used in attacks automating adaptation, producing high-quality deepfakes and enabling more credible phishing.
  • Collaboration between companies and state agencies is improving: 50 percent of firms that could identify attackers received information from authorities.
  • Officials warn against a dangerous normalization of cyber risk and stress the need for early detection, evidence preservation and rapid intelligence sharing.

Security Threats to the Economy

Berlin Germanys domestic intelligence service is sounding the alarm: foreign intelligence agencies are increasingly targeting German businesses with espionage and sabotage, and the threat is growing more sophisticated. Sinan Selen, president of the Federal Office for the Protection of the Constitution (Bundesamt für Verfassungsschutz, BfV), warned that these actors have intensified their hybrid activities and are responsible for a rising share of attacks on the German economy, comments he made while presenting the 2026 economic protection report in Berlin.

The report draws on a representative survey conducted by the digital industry association Bitkom. Researchers questioned 1,003 companies with at least ten employees and annual revenues of at least one million euros. Among firms that had experienced data theft, industrial espionage or sabotage in the past year, more than one in three were able to attribute at least one incident to a foreign intelligence service a jump from 28 percent to 37 percent in only one year. In 2023 that figure stood at seven percent.

These findings underline the tangible danger that espionage and sabotage now pose to Germany as a business location. Attacks can freeze production lines, break supply chains, and deprive companies of critical technical know-how. Selen singled out the security and defence sectors as a particularly attractive target for foreign services.

Recent Incidents, Geography and the Role of AI

The scale of the threat was illustrated by several recent incidents. In April, the Russian defence ministry published addresses of defence companies across Europe including locations in Munich and Hanau implicitly naming potential targets in reaction to announced drone deliveries to Ukraine. Moscows public naming of companies prompted the German foreign ministry to summon the Russian ambassador. In early August 2026, an apparent drone attack near Leipzig/Halle airport a key logistics and military hub exposed a drone rigged with explosives and a detonator close to Ukrainian transport aircraft; the federal prosecutors office has characterized the episode as a serious attack on Germanys transport and logistics infrastructure.

The Bitkom survey also explored the geographic origin of attacks. Among companies certain they had been targeted, 52 percent identified China as the origin of at least one attack, followed by Russia at 49 percent. Eastern European states outside the EU were cited by 34 percent of respondents, the US by 27 percent, and other EU countries by 26 percent. The data reinforce BfVs assessment that state and non-state actors alike have included the German economy in the target spectrum of cyber operations.

Another emerging concern is the concealed use of artificial intelligence in cyberattacks. Selen and Bitkoms president, Ralf Wintergerst, warned that AI is changing the attack landscape. In some cases, less-skilled adversaries now gain access to powerful tools: AI can generate malware, enable autonomous attacks, and produce convincingly realistic audio, video and personalised messages that make fraud easier and detection harder. According to the survey, 31 percent of companies report seeing clear evidence of AI use in attacks, and 51 percent suspect it; signs include automated adaptation of attack attempts, high-quality deepfakes and unusually polished phishing messages.

Bitkom puts the economic damage from data theft, industrial espionage and sabotage over the past 12 months at between €211 billion and €271 billion. A remarkable 96 percent of surveyed firms said they were demonstrably or probably affected by intelligence-led attacks.

Strengthening Cooperation and the Challenges Ahead

There are signs of closer collaboration between the private sector and state authorities. Half of the companies that were able to identify either perpetrators or origin of attacks said they had received leads from government agencies up from 35 percent a year earlier and 24 percent two years ago. Wintergerst argued that a shared operational picture is now essential so both sides can benefit from timely threat intelligence and coordinated defensive action.

Still, he cautioned against complacency. Frequent attacks risk normalising the threat and creating a false sense of security inside companies. Even a single successful cyberattack can still be fatal for a business. Wintergerst urged firms to detect and repel attacks early, preserve forensic evidence and share insights rapidly with authorities to limit espionage and sabotage more effectively.

Both officials highlighted that while AI also offers defensive potential helping to spot and mitigate attacks earlier it simultaneously lowers the bar for attackers. Policymakers and business leaders face the dual task of accelerating defensive capabilities, expanding information sharing and adapting legal and operational responses to counter increasingly covert and automated threats.

The message from Berlin is clear: foreign intelligence activity against German industry is rising, damage is substantial, and an effective response will require closer public-private cooperation, investment in cyber resilience, and vigilance against the new tools attackers are deploying.

MarketFlick Insights

Get the latest analysis and top articles of the week delivered directly to your inbox.

No spam. Unsubscribe anytime.