Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

BSI Study: One in Nine Germans a Victim of Cybercrime

11% of internet users fell victim to online fraud in 2025. Online shopping fraud tops the list of offences at 22%. Many still underestimate the risks.

Alarming figures: cybercrime affects one in nine Germans

The latest figures from the German Federal Office for Information Security (BSI) paint a worrying picture of the digital security situation in Germany. The current Cybersecurity Monitor 2026 (CyMon), produced together with the Police Crime Prevention Programme of the federal states and the federal government (ProPK), reveals a high rate of exposure to cybercrime.

One in nine internet users (11 percent) became a victim of crime in the digital realm last year. The picture becomes even more dramatic when the whole lifetime is considered: more than one in four Germans (27 percent) has already been affected by cybercrime at least once. These figures are based on a representative survey of 3,060 people aged 16 and over, conducted nationwide in January 2026.

Online shopping fraud dominates the list of offences

The analysis of the various types of offence clearly shows where cybercriminals strike most often. At 22 percent, fraud in online purchases is the most widespread offence among those affected. For consumers this means a considerable risk in everyday online shopping.

The other leading offences are:

  • Unauthorised third-party access to online accounts (14 percent)
  • Online banking fraud (13 percent)
  • Phishing attacks (12 percent)

This distribution shows that criminals are primarily active where financial transactions or sensitive personal data are involved. The high share of online shopping fraud in particular underlines the need for stronger protective measures in e-commerce.

High level of damage among victims

For victims of cybercrime, the attacks are by no means without consequences. Almost nine out of ten of those affected (88 percent) suffered damage. The effects are varied and go beyond purely financial losses:

  • A third of victims (33 percent) suffered financial losses
  • 29 percent recorded a loss of trust in online services
  • 23 percent complained about time lost dealing with the consequences

These figures make clear that cybercrime not only causes immediate material damage but also has long-term psychological and practical consequences for those affected. The loss of trust in digital services can lastingly impair victims' digital participation.

Dangerous complacency despite the high rate of exposure

Paradoxically, the study shows a troubling discrepancy between the actual threat situation and the public's perception of risk. More than half of respondents (55 percent) rate their personal risk of becoming a victim of cybercrime as low or even rule it out entirely.

This misjudgement is also reflected in how people inform themselves: only 14 percent of respondents regularly seek out information on cybersecurity. Forty percent engage with the topic only occasionally. This reluctance to actively seek information stands in stark contrast to the real threat situation.

Inadequate protective measures in practice

Another problem emerges in the implementation of concrete protective measures. Of 19 suggested security precautions, only strong passwords and antivirus programs are known to the majority of respondents. Even these basic measures are actually used by only 46 and 40 percent of internet users respectively.

Respondents named the following as the main obstacles to better protection:

  • A deceptive subjective sense of security (27 percent)
  • Perception of the measures as too complicated (23 percent)
  • Feeling overwhelmed by the complexity (23 percent)

Responses after a cyberattack

Once an attack has occurred, victims react differently. 32 percent file a report with the police, while 35 percent contact the operator of the service in question. These figures show that there is a certain willingness to report cybercrime, even if not all cases are reported to the authorities.

Calls for simpler security solutions

The study results led to clear demands from those responsible. Stefanie Hinz, chair of the ProPK, stressed at the presentation of the study that cybercrime through fake emails or fraud when shopping has long since arrived at the heart of society.

BSI President Claudia Plattner called for cybersecurity in everyday life to become "simpler, more present and more understandable". She also placed industry under obligation: "Manufacturers and providers of digital devices and applications must make secure products and services the standard."

Outlook: the need for a paradigm shift

The results of the Cybersecurity Monitor 2026 highlight the urgency of a paradigm shift in digital security. While the threat situation is continuously increasing, both users' awareness and their preventive measures remain inadequate.

The high damage figures combined with the low perception of risk show that traditional awareness and information approaches alone are not sufficient. Instead, systemic solutions are required that build security into digital products and services from the outset.

For companies and institutions this means that cybersecurity can no longer be treated as an afterthought but must be understood as an integral part of digital transformation. Only through a combination of user-friendly security technologies, improved awareness and systemic protective measures can the growing threat of cybercrime be effectively countered.