Cyberattacks on banks and insurers rise, increasing costs and the need for action
The number of cyberattacks on banks and insurers is rising, with foreign intelligence services now blamed for more than a third of the attacks. At the same time, AI‑driven techniques such as deepfakes and automated robo‑calls are significantly reshaping the threat landscape.
What’s changing
In the past twelve months, the share of firms that can attribute a cyberattack to foreign intelligence services has risen from seven percent in 2023 to twenty‑eight percent the year before, and now to thirty‑seven percent. At the same time, the use of artificial intelligence has broadened the attack spectrum: the share of damage caused by automated robo‑calls has climbed from three to fourteen percent, while deepfakes have doubled their share from four to eight percent. Today, 76% of all damage from data theft, industrial espionage and sabotage is caused purely through digital channels, compared with a much lower share via traditional means. These trends indicate that attacks are not only becoming more frequent but also harder to detect and attribute.
For banks and insurers, the rise of AI‑driven phishing attempts means that conventional filters and rule sets are increasingly being bypassed. Attackers leverage language models to generate convincingly authentic emails and voice recordings that include personal salutations and context‑specific details. This boosts the success rate of social‑engineering attacks, while the average time to detect an incident also lengthens. Bitkom reports that 82% of firms expect attackers to increasingly use artificial intelligence to automate and personalize their campaigns. This development forces financial institutions to fundamentally reassess their detection mechanisms and response processes.
What it costs
According to the latest Bitkom economic‑security study, the total economic damage from data theft, industrial espionage and sabotage in Germany ranges from €211 billion to €270.8 billion per year. Of this, purely cyber‑based attacks account for €160.4 billion to €205.8 billion – roughly three‑quarters of the total loss. The study is based on a survey of 1,003 companies with at least ten employees and an annual turnover of at least €1 million, conducted between calendar weeks 16 and 23 of 2026. No further publicly available figures for individual cost items such as ransom payments or restoration expenses were disclosed.
The survey also shows that 58% of the respondents have suffered a concrete loss from a cyberattack in the past twelve months. For 59% of the victims, the success of the attack is attributed to inadequate detection of security incidents, while 57% cite misconfigurations of IT systems as the primary cause. These factors generate direct costs such as system downtime, data recovery and possible regulatory fines, as well as indirect costs stemming from loss of trust among customers and partners. Because no detailed breakdown of individual cost items is available, companies must estimate the financial impact based on their own incident‑response expenses.
What breaks down
A successful cyberattack often results in prolonged system outages, especially when critical payment or account‑management platforms are affected. Companies report that, on average, several days to weeks may pass before affected interfaces to banks, clearing houses or card acquirers are fully operational again. This requires not only the IT department but also the payment operations, risk management and customer‑service units to be involved in the recovery process, creating a substantial coordination effort.
In addition to the outright outage, data‑migration issues frequently arise when backups from insecure sources need to be restored or compromised data sets must be cleansed. Interfaces to external payment‑service providers, ERP systems and identity‑ and access‑management solutions often require re‑configuration and testing to avoid misconfigurations. At the same time, training needs increase: staff must be retrained to spot phishing attempts, deep‑fake calls and manipulated transaction requests, with Bitkom noting that 55% of firms view inadequate identity and access management as a weakness.
What a switch demands
Switching to a more robust security concept first requires a comprehensive inventory of all existing systems, especially identity‑ and access‑management components and payment gateways. This process typically takes several months and involves not only the IT department but also risk management, the compliance unit and the payment‑operations leadership. During the analysis phase, vulnerabilities in logging, patch strategy and disaster‑recovery planning must be identified, with log‑file analysis remaining the primary source of insight for 68% of firms, according to Bitkom.
Subsequently, concrete measures must be defined and implemented: introducing multi‑factor authentication for all privileged accounts, updating patch‑management processes, deploying AI‑based anomaly‑detection systems and conducting regular penetration tests. The IT‑security budget should also be reviewed; while the average share of the IT budget currently stands at 18%, Bitkom recommends at least 20%, and 45% of firms already meet or exceed this threshold. Implementation requires clear responsibilities, a set timeline and the involvement of external specialists if internal resources are insufficient.
