Signal
Submitted
Apr 28, 2026, 14:01 UTC
The German Federal Cybersecurity Agency (BSI) reports a 'disturbing' and rapidly worsening threat environment with increased politically motivated cyberattacks on government institutions, critical infrastructure, and political parties in 2024.
On November 12, 2024, Germany's Federal Office for Information Security (BSI) published its 2024 cybersecurity report highlighting an alarming rise in cyberattacks, many politically motivated linked to geopolitical conflicts like Russia's war on Ukraine and the Gaza conflict. The report identifies 22 active advanced persistent threat (APT) groups operating in Germany, including APT28, tied to Russia's military intelligence, responsible for hacking the SPD party headquarters and sectors like logistics, defense, and IT service providers. Political parties, including the CDU, also faced severe cyberattacks, though attribution is uncertain. The BSI warns that cyberattacks on state and political institutions, as well as disinformation campaigns, are targeted attempts to undermine democracy, especially around elections in 2024. Distributed denial-of-service (DDoS) attacks, particularly by supporters of the Russian war effort, have surged in frequency and sophistication. Ransomware and data extortion have become mass criminal enterprises affecting entities from major corporations to small and medium-sized enterprises, municipalities, universities, and research institutions. Despite legal obligations for critical infrastructure operators to mitigate cyber threats, proposed stricter cybersecurity legislation (NIS2 implementation) faces political uncertainties in Germany post government coalition collapse. The BSI president and Federal Interior Minister advocate expanding the BSI into a centralized federal cyber incident response agency, but constitutional hurdles and regional opposition complicate this. The report stresses the need for heightened self-protection among companies and municipalities to address growing cyber extortion impacts, which include significant operational shutdowns and loss of citizen services.
Confidence: High
The article explicitly describes multiple politically motivated cyberattacks attributed to Russian-linked APT groups targeting German government institutions, political parties, and critical infrastructure in 2024. It details active cyber aggression including DDoS attacks, ransomware extortion, and influence operations. This indicates clear aggressor activity, constituting a hybrid warfare signal.
Source URL
https://tagesschau.de/inland/innenpolitik/cybersicherheit-lagebericht-bsi-100.html
Source reliability
A
Info credibility
6
Event time
Nov 12, 2024, 00:00 UTC
Event time confidence
exact
Location
Germany
Primary actor
APT28
Country
Germany
Countries
Germany
Tags
offensive cyber operations, APT28, Russia, cyberattacks, ransomware, DDoS, political interference, BSI, Germany, elections 2024
Nodes
Node 1: Borders, Node 2: 5th Column, Node 3: Political Disruptions