Ransomware in Germany: From IT Incident to Insolvency Risk

Ransomware in Germany is no longer an abstract IT concern — in 2026, it is one of the more concrete threats to whether a company survives at all. Two recent cases illustrate how differently this threat can play out. ZEGO Textilveredelungszentrum filed for insolvency following a cyberattack, without the attack type ever being publicly confirmed. Industrial supplier Jäcklin Industrial GmbH was listed as a victim by the ransomware group SafePay on its leak site. Both cases sit against a backdrop that, according to the BKA and BSI, remains tense and continues to intensify.

The Numbers: Germany and DACH in the Crosshairs

Ransomware in Germany — BKA, BSI, Kaspersky and Check Point statistics for Germany and the DACH region

The BKA recorded 1,041 ransomware attacks in Germany in 2025, a 10 percent increase over the previous year, while Check Point measured a 124 percent rise in ransomware and hacktivist activity across the DACH region.

  • According to the BKA’s 2025 cybercrime report, Germany recorded 1,041 ransomware attacks in 2025 — an increase of 10 percent year over year, with companies and public-sector organisations especially affected. Fewer victims paid, but the average ransom payment rose sharply; in total, the BKA recorded roughly USD 15.5 million in ransom payments.
  • The BSI’s current situation report, covering 1 July 2024 to 30 June 2025, describes Germany’s IT security situation as “tense.” Per the BSI, digitalisation continues to expand the country’s attack surface faster than preventive measures can keep pace, and the agency names ransomware and data leaks among the greatest current cybercriminal threats to the German state, economy, and society.
  • Kaspersky recorded a rise in ransomware attacks in Germany in 2025, with 384 attacks logged in the country, alongside higher overall activity across the DACH region.
  • Check Point’s figures for the region are starker still: ransomware and hacktivist activity across DACH rose 124 percent in 2025, with Germany accounting for more than 80 percent of the regional incidents in its dataset.
  • This sits within a still larger picture. The German federal government’s summary of the BKA report puts Germany’s total estimated cybercrime damage at €202.4 billion, across roughly 335,000 recorded cases. Ransomware is only one segment of that total — but a disproportionately damaging one, because it does not just steal from a business, it stops it from operating.

Case One: ZEGO — When a Cyberattack Leads to Insolvency

Ransomware in Germany — ZEGO Textilveredelungszentrum cyberattack-related production shutdown and insolvency

ZEGO Textilveredelungszentrum has not confirmed whether ransomware was involved in the cyberattack that halted production for nearly six weeks before the company filed for insolvency.

ZEGO Textilveredelungszentrum was hit by a cyberattack on 29 March 2026 that caused a production outage of nearly six weeks. The company said the resulting financial fallout made insolvency necessary. What ZEGO has not publicly confirmed is the type of attack involved, whether ransomware was part of it, or whether any data was stolen. The accurate way to describe the case is as a cyberattack-linked insolvency, or a cyberattack-related production shutdown — not as a confirmed ransomware incident (The Register; IT-Daily; t-online; Gigazine).

That ambiguity is part of what makes ZEGO worth paying attention to. For the business impact, it ultimately matters little whether an attack is formally classified as ransomware, sabotage, or something else. What matters is that a security incident was able to trigger a six-week production halt, and that a halt of that length was enough to determine a company’s financial viability. For a mid-sized business in textile finishing — an industry with thin margins and continuous delivery obligations to customers — an outage of that duration can be the difference between continuing to operate and filing for insolvency, regardless of how the incident is technically classified.

Case Two: Jäcklin Industrial — Another German Manufacturer on a Leak Site

The case of Jäcklin Industrial GmbH shows that German industrial firms remain squarely in the sights of active ransomware groups. Several ransomware-tracking and breach-monitoring sources report consistently that the SafePay ransomware group listed the company as a victim on its leak site in July 2026 (Darkfield; DeXpose; Ransomware.live; BreachSense; Breach House).

The framing matters here too: this information comes from leak-site and aggregator sources, not from a statement by the company or confirmation by law enforcement. The accurate description is that Jäcklin was claimed by SafePay, or listed on SafePay’s leak site — not that the company was definitively breached. Setting that caveat aside, the case reinforces a pattern that has held for years: German manufacturing and industrial firms — often mid-sized, often running IT environments that grew organically rather than by design — remain a preferred target for double-extortion ransomware, where encryption is paired with the threat of publishing stolen data.

Strategic Implications: Backups Alone Are Not Enough

Ransomware in Germany — DIESEC governance, MDR and incident readiness for SMEs and manufacturers

Segmentation, continuous detection, and tested incident-response plans matter more than backups alone once a cyberattack threatens production continuity.

ZEGO and Jäcklin represent two different stages of the same underlying problem. One shows the end state — insolvency following an extended production outage. The other shows an earlier stage — a company that, according to monitoring sources, has already been targeted by an active ransomware group. Together, they illustrate that ransomware in the DACH region is increasingly a business-continuity and insolvency risk, not only an encryption-and-extortion problem.

Backups remain necessary, but on their own they are no longer a sufficient answer. If an attack shuts down production for weeks, a restored backup does little unless network segmentation, recovery planning, and supplier dependencies have already been thought through. A few practical priorities follow from these two cases, particularly for SMEs and manufacturers:

  • Segmentation between IT and OT environments, so an incident in office systems does not automatically take down production
  • Exposure reduction through disciplined patch management and hardening of internet-facing systems
  • Continuous detection and response to catch attacks before they escalate into a production-affecting event
  • Regular penetration testing to find exploitable weaknesses before attackers do
  • Tested incident-response and recovery plans that also cover supply-chain and customer communication, not just technical restoration

DIESEC works with companies on exactly these areas: continuous monitoring and threat detection through SOC as a Service, Penetration Testing to identify exploitable weaknesses before attackers do, and structured incident-readiness preparation that shortens response time when an incident occurs. The goal is not to eliminate risk entirely — that is not realistic. The goal is to reduce the likelihood that a security incident turns into an existential event for the business.

Conclusion

The BKA and BSI figures point to a threat picture for Germany and the wider DACH region that remains tense and shows no sign of easing. ZEGO shows how a cyberattack — even without publicly confirmed ransomware involvement — can determine a company’s future. Jäcklin shows that German industrial firms continue to be actively targeted by ransomware groups. Both cases lead to the same conclusion: ransomware is no longer purely an IT risk. It is an operational and financial risk that belongs on the board’s agenda, not only in the IT department’s.

Contact us to learn more.