🚨  NIS2 is now in effect. Security awareness training is now a legal requirement for thousands of EU organisations.

Check compliance
Log in
Back to Resource Center

The biggest cyber attacks in Germany

German Cyber Attacks

German companies and public bodies are among the most attacked in Europe. The Bundeskriminalamt registered 333,922 cybercrime cases in 2025, with damages estimated at 202.4 billion euros. In the same year, 1,041 ransomware attacks were reported, and Germany ranked third worldwide in confirmed ransomware incidents.

Behind those numbers are concrete cases: a municipal IT provider that took 72 towns offline, a car parts giant that lost 40 terabytes of data, a university hospital that had to turn patients away. This article covers six documented attacks, what they cost, and the one thing almost all of them have in common.

The biggest cyber attacks in Germany

1. Südwestfalen IT (2023): 72 municipalities offline

On 30 October 2023, the municipal IT service provider Südwestfalen IT was hit by ransomware attributed to the Akira group. The data centre cut its connections to the municipalities it served, taking 72 member towns and districts offline at once. Citizens could not register vehicles, request documents or use municipal services.

Around 170 people worked on recovery, spending roughly 43,000 working hours, and full restoration of services ran into autumn of the following year. It remains the largest and most complex incident of its kind in Germany.

2. Continental (2022): 40 terabytes stolen

In the summer of 2022, the LockBit group breached the networks of automotive supplier Continental and stayed undetected for around a month. They stole about 40 terabytes of data: budget, investment and strategy plans, personnel files, and confidential communications from executives and the supervisory board. Data belonging to customers, including Volkswagen, was part of the haul.

The attackers published a file listing the storage paths of 55 million files. Continental wrote to tens of thousands of affected people and publicly called for a ban on ransom payments.

3. Universitätsklinikum Düsseldorf (2020): a hospital turned away

A ransomware attack on the university hospital in Düsseldorf forced it to deregister from emergency care. Systems were encrypted and patients had to be diverted to other hospitals. The case drew international attention as one of the starkest examples of what happens when critical care infrastructure goes down. German security authorities attributed it, along with other incidents, to the group known as Double Spider.

4. Landkreis Anhalt-Bitterfeld (2021): the first cyber disaster declaration

After a ransomware attack, the district of Anhalt-Bitterfeld declared a Katastrophenfall, a formal disaster situation. It was the first time a German authority took that step because of a cyber attack. Benefit payments and citizen services were disrupted for weeks, and the district needed months to return to normal operations.

5. Funke Mediengruppe (2020): a publisher without a newsroom

One of Germany’s largest media groups was hit by ransomware that spread across editorial and production systems. Newspapers appeared in emergency editions. As with Düsseldorf and Anhalt-Bitterfeld, German authorities pointed to the Double Spider group.

6. The pattern behind the headlines (2025)

Individual cases make the news, but the trend line matters more. In 2025 the manufacturing sector accounted for 23 percent of all German data leaks, followed by legal and consulting services at 14 percent and construction and engineering at 11 percent. According to Google Threat Intelligence, the SafePay group was responsible for roughly a quarter of German data leak publications that year. The targets are no longer only the household names.

How does your organisation prevent a major hack?

Most incidents start with one person clicking, opening or approving something. Guardey trains employees to recognise phishing, baiting and social engineering in weekly challenges of three minutes.

Start your free 14-day trial

What these cases have in common

Read the reports side by side and a pattern appears. These were not exotic zero-day exploits against hardened systems. In case after case, attackers got in through an ordinary door: a stolen credential, a convincing email, an employee who acted before questioning.

The Continental case is instructive. The attackers were inside the network for around a month before anyone noticed. That is not a failure of firewalls, it is a failure of detection and of the human signals that precede it. Someone, somewhere, saw something that did not look right.

This is why the BSI and BKA keep pointing at the same weak spot. Technical controls stop known threats. They do not stop an employee opening an attachment that looks like an invoice, plugging in a USB drive found in the car park, or approving a login request after a phone call from someone claiming to be IT support. That last method has been used in some of the largest European breaches of recent years, and baiting works on exactly the same principle: curiosity, not a technical flaw.

How to protect your organisation

Backups, patching and network segmentation are the baseline, and every one of the organisations above had some version of them. What separates the companies that absorbed an attack from the ones that made headlines is usually how quickly someone recognised what was happening.

That recognition is trainable. Three things make the difference in practice:

  • Regular, short training instead of an annual session. Awareness decays. A yearly session teaches facts that are forgotten by March; weekly repetition builds a reflex.
  • Realistic phishing simulations. Reading about phishing is not the same as receiving one. Simulations show you which departments need support before an attacker finds out for you.
  • A culture where reporting is normal. The employee who clicked and says so within five minutes is worth more than the one who stays quiet for five days.

For organisations covered by NIS2, this is no longer optional. The directive names awareness training explicitly, and our NIS2 guide walks through what that means in practice.

Turn your employees into the layer that catches it

In a 30-minute demo we show how Guardey combines weekly awareness training with realistic phishing simulations, and how the reporting shows you exactly where your risk sits.

Schedule a personal demo
Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo