Germany says hackers infiltrated government computers; sources point to Russian group APT28, say malware could have been in the system for up to a year
German security services have admitted they uncovered a cyberattack on the government in December. Sources say the malware had been planted …
Context & Ripple Effects
This disclosure lands on top of an established pattern: Germany's domestic intelligence head had already said Russia took large amounts of data in the 2015 parliament breach, with Berlin at that point only exploring legal options for offensive operations. The new report extends the arc from a one-time data theft to a long-dwell implant — sources say malware linked to APT28 could have sat inside government computers for up to a year before security services uncovered it in December.
First-order effects
- German security services must now sweep government networks for a year-long APT28 implant, and the public admission forces Berlin to answer what data was exposed during the dwell time.
Second-order effects
- Attribution to a Russian group hardens the case for the offensive cyber options Berlin floated after the 2015 breach, moving the debate from legal theory to operational policy.
- Recurring Russian intrusions push German ministries and the parliamentarians targeted in the 2021 GRU phishing campaign toward hardened, segmented government infrastructure and tighter vendor access rules.
Third-order effects
- If the pattern holds — the same actors later blamed for the 2023 takedown of German government websites — persistent state-on-state cyber operations become a normalized condition of European governance, with Germany building standing defensive and retaliatory capability rather than responding incident by incident.
The trend: European governments are shifting from forensic disclosure of Russian state hacking toward institutionalized cyber defense and retaliation, as each successive intrusion erodes the political cost of going on offense.