
The blurring of organized crime and state intelligence — Wintergerst's explicit point — is the mechanism that makes attribution nearly impossible for defenders. A ransomware attack on Lidl's IT provider could be FSB-contracted cybercriminals, or it could be Russian state operators using criminal cover.
Berlin cannot respond to criminal extortion the same way it responds to state espionage, so the ambiguity itself becomes a weapon. If German companies cannot distinguish the attacker's flag, the government cannot escalate without risking miscalibration — which is precisely why Moscow and Beijing blur the line.
German defense and industrial primes are now under coordinated state-level collection pressure at a scale that has tripled in three years.
Thyssenkrupp, Siemens, Rheinmetall, and the AUKUS supply chain that feeds UK and allied procurement now operate in an environment where more than one in three breaches trace to Beijing or Moscow — meaning every contract award, every R&D schedule, every supply-chain vulnerability is being actively harvested. Sinan Selen's public acknowledgment that foreign intelligence has "intensified hybrid activities" signals Berlin is moving from denial to attribution, which forces NATO capitals to assume German industrial secrets (turbine designs, missile guidance algorithms, microelectronics specs) are already in PLA and FSB hands. Watch the German government's response in September — if Berlin announces new export controls on dual-use tech or restricts Chinese joint ventures in defense-critical sectors, the survey's impact will have crossed from industry warning into policy.
Does the Bitkom survey break down which industrial sectors (defense, semiconductors, energy, chemicals) drew the highest state-actor targeting? The article cites defense as 'particularly attractive' but doesn't quantify the share of attacks.
Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.