Identity Theft in Germany: What SMEs Need to Know
Germany’s cybercrime problem has a number attached to it: an estimated €202.4 billion in damage to the German economy for the 2025 reporting period, around 4.5 percent of GDP, according to the Federal Criminal Police Office’s (BKA) latest Bundeslagebild Cybercrime report. Behind much of that damage sits a quieter but persistent issue: identity theft in Germany, and the stolen credentials that enable much of the rest of the attack chain.
Identity Theft in Germany Is the Real Driver of Cybercrime

Access, not malware, is what many attackers are actually buying and selling.
The BKA’s 2025 Bundeslagebild counted around 335,000 registered cybercrime cases in Germany, with roughly two-thirds (207,888) committed from abroad or an unknown location. The report describes “Cybercrime-as-a-Service” as the dominant business model behind this volume: an underground economy that now sells access, malware, and stolen data at industrial scale, a trend the BKA expects AI to accelerate further. Separately, the Federal Office for Information Security’s (BSI) own 2025 state-of-security report recorded an average of 119 newly disclosed vulnerabilities per day, up about 24 percent year over year.
Two different reports, two different measurements, but the same underlying story: attackers no longer need to build every tool themselves. They buy access, rent infrastructure, and — most commonly of all — use credentials someone else already stole.
Why Stolen Credentials Are an SME Problem Too
A YouGov survey, commissioned by Germany’s “Sicher Handeln” crime-prevention initiative, reported that 11 percent of German adults — more than one in ten — have been victims of online identity theft. The same survey found that a third of 18-24-year-olds reuse the same password across multiple accounts, compared to one in five adults on average. Weak habits like that don’t stay a personal problem for long.
The BKA’s cybercrime overview explains why: phishing and spam are typically used to obtain digital identities — passwords, email addresses, banking details — and attackers frequently impersonate trusted organisations or ride on current events to make their lures more convincing. In a business setting, the same stolen identity that empties someone’s personal inbox can just as easily grant access to a company mailbox, an accounting platform, or a cloud storage account. Once an attacker is inside using a legitimate-looking login, unauthorised payments, business email compromise, and quiet access to internal systems all become far easier than they would be from the outside.
Ransomware Still Hits Small Businesses Hardest

Smaller businesses absorb most of the ransomware risk, with the fewest resources to recover from it.
The BSI’s 2025 report registered 950 ransomware attacks in Germany over its own reporting period, and around 80 percent of reported ransomware incidents targeted SMEs — organisations that, in the BSI’s own words, often have fewer resources for independent defence. The BKA tracks ransomware separately, under its own reporting period and methodology, and logged 1,041 reported attacks, up 10 percent year over year — a different count of a different scope, but the same upward direction. Both authorities note that a serious ransomware incident can threaten the continued existence of the business it hits, which matters even more in a country built on a dense base of small industrial suppliers.
Germany Is the Focal Point of a Growing DACH Threat

Germany is the region’s largest and most visible attack surface.
Germany isn’t just the largest DACH economy — independent industry research also points to it as the region’s largest attack surface, though that data is worth reading as threat intelligence rather than an official crime statistic, since it’s measured differently from the BKA and BSI numbers above. Check Point Research found that Germany accounted for 82 percent of tracked cyber incidents across the DACH region in 2025, against 12 percent for Switzerland and 8 percent for Austria, with combined hacktivism and ransomware activity across the three countries up 124 percent year over year. It’s worth being precise about what’s driving that spike, though: around 66 percent of the incidents behind it were website-defacement campaigns, largely run by pro-Russian hacktivist collectives such as NoName057(16) — a different, noisier risk category than the credential theft and ransomware this article is mainly about.
Isolating ransomware specifically tells a more sobering story on its own: in the first half of 2026, Germany ranked as the world’s fourth most-targeted country by ransomware victim count (176), behind only the US, Canada, and the UK, while Switzerland (35 victims) and Austria (29 victims) ranked far lower globally. Because DACH organisations often share the same cloud platforms and identity providers, a phishing campaign written in German can spread across all three countries quickly — particularly when it impersonates a bank, a tax authority, or a public-sector portal.
What This Means for SMEs

Identity is a security control, not just an admin function.
None of this means every business is one email away from disaster, and it doesn’t call for alarmist language. But the pattern across the BSI’s, BKA’s, and independent researchers’ 2025-2026 data on identity theft in Germany is consistent: the threat is sustained, it’s increasingly professionalised, and it’s built around stolen and misused identity far more often than novel malware. That has a practical implication for SMEs specifically — security can’t stop at perimeter tools or a once-a-year awareness training session. Identity protection, phishing resistance, access governance, multi-factor authentication hygiene, and a clear incident-reporting and containment plan deserve at least as much attention as the endpoint and network layer.
For SMEs without a dedicated security team to own all of that in-house, that gap is where managed detection and response can help — continuous monitoring and rapid containment without having to hire and staff a SOC from scratch.
For organisations assessing their own identity risk, a review of access controls, MFA, and incident response readiness is a sensible starting point. Get in touch if that’s a conversation worth having.

