315 German Organisations Named on Ransomware Leak Sites in 12 Months
An analysis of ransomware claim data from March 2025 to March 2026 and the Bitkom Wirtschaftsschutz 2025 study, with a focus on the German threat landscape. Germany ranked second worldwide with 315 claims — roughly one new organisation named every 71 minutes.
315 German organisations on ransomware leak sites. Here is what the data reveals.
Ransomware claim data from March 2025 to March 2026, cross-referenced with the Bitkom Wirtschaftsschutz 2025 study.
Three years of escalation
German enterprises reported €289.2 billion in losses from theft, sabotage, and industrial espionage in 2025. Up from €205.9 billion just two years earlier. Seventy percent of that total comes from cyberattacks. 87% of companies surveyed by Bitkom said they were hit in the past twelve months. This is the baseline now.
Ransomware is the single most damaging attack type. 34% of companies reported ransomware harm, ahead of DDoS, malware, and phishing. Among those hit, 15% paid. Of those who paid, half paid more than €100,000. Some paid over a million.
These losses don't start with an exploit. They start with an exposure nobody prioritised. A vulnerability that scored high in theory but wasn't connected to a production system. The gap between "we have a vulnerability list" and "we know which 23 of those 47,000 actually matter" is where most of this damage lives. That gap is what we built CyvanceIQ to close.
SafePay owns the German target list
A closed operation with Germany in its sights
SafePay is not ransomware-as-a-service. It is centrally managed, built on leaked LockBit 3.0 code, and the US and Germany are its two primary markets. Researchers at Flare, Bitdefender, and Check Point have all flagged the disproportionate focus.
Why Germany? Regulation is leverage. GDPR and NIS2 mean even small data exposures can trigger proceedings, lawsuits, and reputational damage that far exceeds the ransom itself. The playbook: flood employees with spam, impersonate IT support over Teams, encrypt everything within 24 hours.
Manufacturing and technology: 35% of all claims, and the backbone of German supply chains
Manufacturing leads globally with 890 claims. Technology follows at 843. Together they account for 35% of all sector-attributed victims. The reason is simple: downtime costs are enormous, schedules are unforgiving, and legacy OT sits alongside modern IT. Maximum payment pressure. The biggest damage category in Bitkom's study, disruption of production systems, hit €73.3 billion. Double what it was in 2023.
of German companies had a supplier attacked this year
Data theft, sabotage, or espionage against at least one supplier. Bitkom 2025.
of those experienced direct consequences
Production disruptions. Delivery failures. Reputational damage. Measured, not theoretical.
When a precision engineering firm in Baden-Württemberg or a logistics provider in NRW appears on a leak site, the blast radius extends to every downstream operation. Two independent data sources arrive at the same conclusion: supply chain cyber risk is a recurring operational event, not an "emerging threat" for next quarter's board deck.
When your third-party risk team asks "is this vendor compromised?" they need an answer grounded in correlated threat data, not a questionnaire the vendor filled out six months ago. CyvanceIQ correlates ransomware claim data, vulnerability exposure, and SBOM-level software composition to answer that question in real time.
The threat has gone state-level
Leak site data cannot tell you who is behind an attack. Bitkom's survey can. 28% of affected companies attributed attacks to foreign intelligence services. In 2023, that number was 7%. A fourfold increase in two years. 68% attributed attacks to organised crime. The line between the two has dissolved. Germany's Verfassungsschutz has said as much: state actors tolerate or actively use criminal groups as proxies.
The people trying to break into your network do not sort themselves into neat columns on a risk register. Your intelligence should not either.
Volume up 40%. 129 active groups. Nobody expects it to slow down.
First half of the observation period: 521 claims per month. Second half: 732. A 40% jump. December 2025 was the single highest month at 861. At the current rate, the ecosystem is on pace for 8,700+ claims per year.
73% of Bitkom respondents said attacks increased. 82% expect them to keep increasing. Chainalysis reported 8,000+ organisations on leak sites, a record, even as the share paying ransoms dropped to 28%. Fewer are paying. More are getting hit. Median demands jumped from ~$12,700 to ~$60,000. The economics have shifted toward volume.
129 distinct groups posted claims. The top group, Qilin, accounts for just 15%. Remove it and you still have 6,476 claims. Law enforcement takedowns matter but the ecosystem regenerates. When LockBit went down, SafePay and DragonForce absorbed the displaced affiliates within months.
AI is making it worse. 66% of Bitkom respondents see signs of AI in attacker operations. Only 6% of German companies use AI in their own security. That asymmetry is structural.
The gap between how threatened companies feel and how prepared they are
call cyberattacks existential
Up from 9% in 2021. The awareness arrived. The preparation has not.
have no incident response plan
Four in ten German companies have no structured preparation for a security incident.
use AI in security operations
While 66% see AI in attacker operations. The asymmetry is real.
depend on US security vendors
While 53% now view the US as a potential threat. That tension is not sustainable.
Investment is moving. Security budgets doubled from 9% of IT spend in 2022 to 18% in 2025. But the threat has moved faster. Only 24% train all employees on security awareness. One in five does no training at all. In a world where social engineering is the primary way in, those numbers are not reassuring.
We built Cyvance as a German company for a reason. Not as a flag-waving exercise, but because data residency, regulatory alignment, and operational sovereignty are genuine requirements for the enterprises we serve. When 67% of your market depends on vendors from a country they increasingly distrust, building locally is not a positioning choice. It is a structural one.
47,000 CVEs in your environment. 23 that matter. We find the 23.
Continuous threat exposure management for enterprises in regulated industries. German-built. DACH-focused. Designed for the reality described above.
Request access