Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 9/10

Cybercrime 2025: Germany Records 334,000 Cases and 202 Billion Euros in Damages

Germany recorded 334,000 cybercrime cases with damages of 202.4 billion euros. Ransomware attacks are up 10%, DDoS attacks up 25%. AI is intensifying the threat.

Cybercrime wave reaches new dimensions

The Federal Situation Report on Cybercrime 2025 paints a worrying picture of the IT security situation in Germany. With around 334,000 registered cybercrime cases in the narrower sense, the Federal Republic remains a prime target in cyberspace as the world's third-largest economy. The estimated volume of damage has reached a new record of 202.4 billion euros, equivalent to around 4.5 percent of gross domestic product.

Particularly alarming is the high share of cross-border attacks: around 207,888 offences were committed from abroad or from unknown locations. This development makes prosecution considerably more difficult and underlines the international dimension of cybercrime.

Ransomware and DDoS attacks in focus

Ransomware remains highly dangerous

Ransomware attacks remain one of the most dangerous threats to German companies and public institutions. The statistics record 1,041 reported ransomware attacks in 2025, an increase of 10 percent on the previous year. Total ransom payments amounted to around 15.5 million US dollars.

Despite the rising number of attacks, the number of actual payments is interestingly falling, which points to growing resilience among many organisations. International measures such as "Operation Endgame" have already shown initial success in combating malware infrastructures and led to the identification of suspects.

Sharp rise in denial-of-service attacks

DDoS attacks (denial-of-service attacks) are developing even more dramatically: with 36,706 cases in 2025, the authorities recorded an increase of 25 percent on the previous year. The hacktivist group "NoName057(16)" is proving particularly active, deliberately targeting German institutions - among other things in the context of the geopolitical situation surrounding Ukraine.

The attacks are directed above all against public authorities and administrations as well as transport and logistics companies. As a countermeasure, international security authorities carried out the operations "Eastwood" and "PowerOFF" against the relevant infrastructures and so-called stresser services.

Artificial intelligence as a game changer

A key driver of the current development is the increased use of artificial intelligence in cybercrime. Cybercriminals are using AI technologies to automate attacks, select targets more precisely and professionalise their methods. This development is producing a new quality of threat, as attacks become faster, more targeted and harder to detect.

At the same time, AI is also opening up new opportunities for cyber defence, particularly in the early detection of vulnerabilities. This dual nature of the technology makes it a decisive factor in the future cybersecurity landscape.

High number of unreported cases and investigative challenges

The official figures represent only the tip of the iceberg. Because of a large volume of unreported cases, the actual number of cyberattacks is likely to be considerably higher. Security authorities assume that many cases are neither reported nor detected. The substantial share of cross-border or anonymised attacks makes prosecution even harder.

Government response: strengthening defensive capacity

In view of these dramatic developments, Federal Interior Minister Alexander Dobrindt announced a strengthening of the security authorities. "Cybercriminals attack Germany every day - our companies, our authorities and our infrastructure", Dobrindt emphasised. The response, he said, is an expansion of the authorities' powers, technical equipment and enforcement capability.

BKA Vice President Martina Link pointed to the successes of measures taken so far but warned against complacency: "Our successful measures against cybercrime show that police action works - but they must not obscure the fact that the threat situation in cyberspace remains highly dynamic. Cybercriminals continually adapt their methods and thereby increase the pressure on the state, the economy and society."

Outlook: the threat remains highly dynamic

The figures in the Federal Situation Report on Cybercrime 2025 make clear that Germany remains a focus for international cybercriminals. The combination of the country's economic importance, advancing digitalisation and the geopolitical situation makes the Federal Republic an attractive target.

The integration of AI technologies will continue to change the threat landscape, creating both new risks and new defensive options. What will prove decisive is how quickly and effectively the state, the economy and society can respond to these developments. The announced strengthening of the security authorities is only one building block in a comprehensive cybersecurity strategy that must also include preventive measures and greater resilience for critical infrastructures.