threat report 9 min read

315 German Organisations Named on Ransomware Leak Sites in 12 Months

An analysis of ransomware claim data from March 2025 to March 2026 and the Bitkom Wirtschaftsschutz 2025 study, with a focus on the German threat landscape. Germany ranked second worldwide with 315 claims — roughly one new organisation named every 71 minutes.

By Cyvance Intelligence
Cyvance Intelligence // March 2026

315 German organisations on ransomware leak sites. Here is what the data reveals.

Ransomware claim data from March 2025 to March 2026, cross-referenced with the Bitkom Wirtschaftsschutz 2025 study.

7,655
Global leak site claims in 12 months
315
German organisations named. Second worldwide.
€289B
Total damage from theft, sabotage, espionage (Bitkom 2025)
70%
Of all damage from cyberattacks. First year above €200B.
Damage trajectory

Three years of escalation

German enterprises reported €289.2 billion in losses from theft, sabotage, and industrial espionage in 2025. Up from €205.9 billion just two years earlier. Seventy percent of that total comes from cyberattacks. 87% of companies surveyed by Bitkom said they were hit in the past twelve months. This is the baseline now.

2023
€205.9B
72% cyber share. Baseline year.
2024
€266.6B
+29% YoY. €178.6B from cyberattacks.
2025
€289.2B
70% cyber share. €202.4B from cyberattacks. New record.

Ransomware is the single most damaging attack type. 34% of companies reported ransomware harm, ahead of DDoS, malware, and phishing. Among those hit, 15% paid. Of those who paid, half paid more than €100,000. Some paid over a million.

These losses don't start with an exploit. They start with an exposure nobody prioritised. A vulnerability that scored high in theory but wasn't connected to a production system. The gap between "we have a vulnerability list" and "we know which 23 of those 47,000 actually matter" is where most of this damage lives. That gap is what we built CyvanceIQ to close.

Threat actors // Germany

SafePay owns the German target list

72
claims against German organisations. 23% of all German postings.

A closed operation with Germany in its sights

SafePay is not ransomware-as-a-service. It is centrally managed, built on leaked LockBit 3.0 code, and the US and Germany are its two primary markets. Researchers at Flare, Bitdefender, and Check Point have all flagged the disproportionate focus.

Why Germany? Regulation is leverage. GDPR and NIS2 mean even small data exposures can trigger proceedings, lawsuits, and reputational damage that far exceeds the ransom itself. The playbook: flood employees with spam, impersonate IT support over Teams, encrypt everything within 24 hours.

LockBit 3.0 derivativeSocial engineeringTeams impersonationSub-24h kill chain
Top groups targeting Germany (March 2025 – March 2026)
SafePay
72
Akira
34
Qilin
34
INC Ransom
16
Play
13
Sector exposure + supply chain

Manufacturing and technology: 35% of all claims, and the backbone of German supply chains

Manufacturing leads globally with 890 claims. Technology follows at 843. Together they account for 35% of all sector-attributed victims. The reason is simple: downtime costs are enormous, schedules are unforgiving, and legacy OT sits alongside modern IT. Maximum payment pressure. The biggest damage category in Bitkom's study, disruption of production systems, hit €73.3 billion. Double what it was in 2023.

Global sector-attributed claims
Manufacturing
890
Technology
843
Healthcare
537
Construction
375
Financial svcs
362
Business svcs
339
28%

of German companies had a supplier attacked this year

Data theft, sabotage, or espionage against at least one supplier. Bitkom 2025.

41%

of those experienced direct consequences

Production disruptions. Delivery failures. Reputational damage. Measured, not theoretical.

When a precision engineering firm in Baden-Württemberg or a logistics provider in NRW appears on a leak site, the blast radius extends to every downstream operation. Two independent data sources arrive at the same conclusion: supply chain cyber risk is a recurring operational event, not an "emerging threat" for next quarter's board deck.

When your third-party risk team asks "is this vendor compromised?" they need an answer grounded in correlated threat data, not a questionnaire the vendor filled out six months ago. CyvanceIQ correlates ransomware claim data, vulnerability exposure, and SBOM-level software composition to answer that question in real time.

Attacker attribution // Bitkom 2025

The threat has gone state-level

Leak site data cannot tell you who is behind an attack. Bitkom's survey can. 28% of affected companies attributed attacks to foreign intelligence services. In 2023, that number was 7%. A fourfold increase in two years. 68% attributed attacks to organised crime. The line between the two has dissolved. Germany's Verfassungsschutz has said as much: state actors tolerate or actively use criminal groups as proxies.

Attributed attack origins (% of affected companies)
Russia
46%
China
46%
Eastern Europe
31%
United States
24%
EU (excl. DE)
22%
Germany
21%

The people trying to break into your network do not sort themselves into neat columns on a risk register. Your intelligence should not either.

Trend + ecosystem

Volume up 40%. 129 active groups. Nobody expects it to slow down.

First half of the observation period: 521 claims per month. Second half: 732. A 40% jump. December 2025 was the single highest month at 861. At the current rate, the ecosystem is on pace for 8,700+ claims per year.

73% of Bitkom respondents said attacks increased. 82% expect them to keep increasing. Chainalysis reported 8,000+ organisations on leak sites, a record, even as the share paying ransoms dropped to 28%. Fewer are paying. More are getting hit. Median demands jumped from ~$12,700 to ~$60,000. The economics have shifted toward volume.

129 distinct groups posted claims. The top group, Qilin, accounts for just 15%. Remove it and you still have 6,476 claims. Law enforcement takedowns matter but the ecosystem regenerates. When LockBit went down, SafePay and DragonForce absorbed the displaced affiliates within months.

AI is making it worse. 66% of Bitkom respondents see signs of AI in attacker operations. Only 6% of German companies use AI in their own security. That asymmetry is structural.

The readiness gap

The gap between how threatened companies feel and how prepared they are

59%

call cyberattacks existential

Up from 9% in 2021. The awareness arrived. The preparation has not.

39%

have no incident response plan

Four in ten German companies have no structured preparation for a security incident.

6%

use AI in security operations

While 66% see AI in attacker operations. The asymmetry is real.

67%

depend on US security vendors

While 53% now view the US as a potential threat. That tension is not sustainable.

Investment is moving. Security budgets doubled from 9% of IT spend in 2022 to 18% in 2025. But the threat has moved faster. Only 24% train all employees on security awareness. One in five does no training at all. In a world where social engineering is the primary way in, those numbers are not reassuring.

We built Cyvance as a German company for a reason. Not as a flag-waving exercise, but because data residency, regulatory alignment, and operational sovereignty are genuine requirements for the enterprises we serve. When 67% of your market depends on vendors from a country they increasingly distrust, building locally is not a positioning choice. It is a structural one.

Cyvance Technologies GmbH

47,000 CVEs in your environment. 23 that matter. We find the 23.

Continuous threat exposure management for enterprises in regulated industries. German-built. DACH-focused. Designed for the reality described above.

Request access
Data: ransomware.live (via CipherCue) · Bitkom Wirtschaftsschutz 2025 (n=1,002) · Comparitech · NordStellar · Chainalysis 2026 · BSI Lagebericht 2025 · Cyble Europe Q3 2025. Leak site claims are threat actor postings, not confirmed breaches.