One wrong click, one too many email attachments opened, and operations grind to a halt. Germany is one of the world's most important targets for cybercrime. Criminals are targeting companies in all sectors, government agencies, and critical infrastructure. The nightmare scenario of a hacker attack is increasingly affecting small and medium-sized enterprises (SMEs) such as craft businesses. This isn't because each company is individually targeted, but because attacks are now often automated . Perpetrators look for poorly protected systems, weak passwords, or employees who fall for (nowadays extremely sophisticated) phishing emails. The Federal Criminal Police Office (BKA) published current figures on May 12, 2026. The total damage to the German economy most recently amounted to €202,4 billion – approximately 4,5 percent of the gross domestic product. In 2025, around 335.000 cases of cybercrime were registered. Approximately two-thirds of the offenses (207.888) were committed from abroad or from unknown locations. The number of unreported cases is high; many attacks go unreported.
Ransomware is a major threat.
A key threat remains ransomware . Ransomware is malware that encrypts or blocks data or IT systems in order to extort a ransom for their release. The ransom is usually demanded in the form of cryptocurrencies such as Bitcoin. Organized crime makes a lot of money from ransomware.
In 2025, 1.041 ransomware attacks were reported in Germany – ten percent more than the previous year. Businesses and public institutions were particularly affected. Average ransom payments rose significantly, totaling around US$15,5 million (approximately €13,24 million). "At the same time, fewer victims are paying ransoms, which suggests greater resilience among many companies," reports the Federal Criminal Police Office (BKA). The number of unreported cases is likely high.
Furthermore, many cybercriminals are using AI to find vulnerabilities and prepare their attacks. The latest version of Claude AI even had to be stopped because it exploited this vulnerability. "At the same time, AI technologies are opening up new possibilities for IT security and the early detection of vulnerabilities."
The doors for the hackers are opened from the inside.
Security measures are essential for every craft business, as was made clear at the Düsseldorf Chamber of Skilled Crafts' "Cybersecurity" action day . The image of the hacker sitting alone in a basement, hacking into companies from the outside, no longer reflects modern cybercrime. Perpetrators no longer just try to overcome technical security barriers from the outside. They try to gain access from the inside – usually through employees, emphasized Kristina Sylvia Pelz , head of the Chamber's business consulting department.
The good news: Many risks can be significantly reduced with relatively simple measures . Chambers of Skilled Crafts throughout Germany regularly provide information on cybersecurity and also offer individual consultations. This is because skilled trades also possess valuable data that criminals could exploit. For example:
🟢 Customer data and addresses
🟢 Offers,
🟢 Invoices and payment information
🟢 Building plans, photos or project documentation
🟢 Access data for email accounts
🟢 Cloud services or online banking
🟢 Appointment and order planning
🟢 Interfaces to suppliers, manufacturers or larger clients
Don't just invest in technology, but also in employees.
At the Cybersecurity Action Day: Hanna Middendorf, Innovation and Technology Advisory Center (BIT), Alexandros Manakos, Apollon Security, Kristina Pelz, Head of Business Consulting, and André-Alexander Maaß, Business Consultant, Düsseldorf Chamber of Skilled Crafts (from left). Photo: © Hans-Jürgen Bauer for Düsseldorf Chamber of Skilled Crafts Cyber expert Alexandros Manakos , managing director of Apollon Security GmbH , likes to compare companies and government agencies to a medieval castle. The walls are the firewall, the guards the antivirus software, passwords the keys, and updates the repairs. But if the castle's inhabitants open the doors themselves to the supposedly friendly intruders, then none of that will help anymore.
Manakos outlined various types of threats: industrial espionage (primarily from China), cybercrime, competitive intelligence gathering, hybrid threats, and sabotage of critical infrastructure. Approximately 87 percent of companies in Germany have been affected at least once.
The most common vulnerability in companies is the human element. Criminals (usually not lone actors but professional organizations) use so-called phishing emails to trick employees into revealing login credentials or opening malware. Examples of such messages include fake invoices from suppliers, emails supposedly from the bank, messages from alleged customers with file attachments, or even internal emails that appear to come from the boss or the accounting department. A single click can be enough for attackers to gain access to systems. And you wouldn't notice a thing. "The attackers don't want to be detected," says Manakos.
The cybersecurity expert recommends a holistic security concept encompassing IT, organizational structure, and building security. This would also include shredders for important documents and regular updates for company printers, as these store print jobs. "And you should n't just invest in technology, but also in your employees ."
Tips for dealing with emails and links:
✔️ Never carelessly click on links in emails or open attachments
✔️ Beware of feigned urgency ("Your password expires in a few days" or "Your account is locked")
✔️ Avoid direct address in the email; instead, use "Good day" or "Dear Sir or Madam". However, these days hackers can easily find out the names of contact persons.
✔️ Emotions are appealed to ("You have won money", "Your coffee machine urgently needs servicing")
✔️ Always check if an email is trustworthy (do the name and email address really match, are there any typos or other inconsistencies?)
✔️ Hovering: Make links visible by hovering the mouse over them
✔️ Do not click on (unknown) links, but actively access the website yourself in the browser.
✔️ Introduce phishing tests within the company to raise employee awareness of the dangers
✔️ Warning: QR code phishing is also becoming increasingly popular
Has my password been leaked? Anyone unsure whether their passwords have been leaked following attacks on large companies is advised by cyber expert Alexandros Manakos to visit the websites haveibeenpwned.com/ or the leak check service of the Hasso Plattner Institute.
Weak passwords are among the most common entry points for cyberattacks. Recommendations:
✔️ Use long passwords
✔️ Use a separate password for each service
✔️ Do not reuse passwords
✔️ Use a password manager
✔️ Two-factor authentication
Significant consequences for businesses
The consequences of a cyberattack can be significant for craft businesses. They range from production shutdowns and the loss of sensitive customer data to a loss of trust among customers and business partners.
Then the perpetrators increase pressure, demand payments, and sometimes additionally threaten to publish stolen data or even contact the affected company's customers. Even if the pressure is immense, "Never pay the perpetrators ," advises Manakos. You never know if you'll actually get the decryption key . His urgent advice: "Invest in active defense." Standard antivirus programs are no longer effective.
Information and advice are available not only from the Chambers of Skilled Crafts, but also from federal agencies such as the Federal Criminal Police Office (BKA) and the Federal Office for Information Security (BSI) . Companies can also report IT incidents and obtain information from the BSI.
DHB now also available digitally! Simply click here and register for the digital German Crafts Journal (DHB)!
Text:
Kirsten Freund /
handwerksblatt.de
Write a comment