Bavaria’s 2026 cyber report: authorities and critical infrastructure face growing pressure

August 31, 2026

Bavaria’s latest cybersecurity assessment points to a threat landscape that is becoming both more complex and more politically charged. Alongside businesses, public authorities and critical infrastructure operators are increasingly being targeted by professional attackers, while artificial intelligence is lowering technical barriers and accelerating the scale of cyber operations.

Bavaria recorded more than 49,400 reported cybercrime cases in 2025, according to the newly published Cybersecurity in Bavaria 2026 report. The Bavarian Ministry of the Interior assumes that the true number is significantly higher, reflecting a substantial level of unreported incidents.

One of the clearest developments identified in the report is the growing use of artificial intelligence in cyberattacks. AI tools can reduce the level of technical expertise required to launch attacks and make it easier for less experienced actors to automate or scale malicious activity. At the same time, politically motivated DDoS attacks, disinformation campaigns and other hybrid activities are becoming more prominent.

Established attack methods remain a major part of the threat picture. Phishing, quishing and ransomware continue to affect organisations across the state. The Bavarian State Criminal Police Office recorded 230 ransomware cases in 2025, an increase of 18 per cent compared with the previous year.

Public-sector IT infrastructure is also under sustained pressure. The Bavarian State Office for Information Security recorded 105 DDoS attacks against government websites and handled around 6,000 security-relevant incidents during the year. Bavaria’s Cyber Defence Center analyses approximately 2.7 billion data records every day, while the state’s IT security infrastructure blocked around 838 million suspicious emails at the point of reception in 2025.

Bavaria’s response is based on close cooperation between police, prosecutors, domestic intelligence and the State Office for Information Security, supported by specialist investigative structures and AI-assisted analytical methods.

For the wider European security sector, the report highlights a broader shift in cyber defence. Effective protection increasingly depends not only on individual security technologies, but on integrated situational awareness, rapid response and permanently developed specialist expertise. As cybercrime, politically motivated operations and hybrid threats become more closely intertwined, organisational coordination is becoming as important as technical detection.

From 5 September 2026, you will also be able to read a feature article here on ‘CYBERSECURITY IN BAVARIA 2026 – Report on Cybersecurity in Bavaria’!

Related Articles

Payroll moves from back-office process to strategic risk function

Payroll is becoming one of the more consequential risk functions inside large international organisations. It combines highly sensitive employee data, financial transactions and an increasingly fragmented body of employment and tax regulation – while many companies...

Berlin faces multi-million-euro ransom demand following cyberattack

Berlin is facing a ransom demand following the cyberattack on several of the German capital’s Senate administrations. Governing Mayor Kai Wegner has ruled out paying the attackers, while state and federal security authorities continue to investigate the extent to...

Share This