Investigation details how a hacking group called OceanLotus has been spying on Vietnamese opposition members and dissidents for years, including in Germany
BR24 : Tweets: @campuscodi , @snlyngaas , @sienaanstis , and @hatr Tweets: Catalin Cimpanu / @campuscodi : This was, by far, the best cybersecurity article published last week. It's a long read but worth it. This is also a visual experience, so don't use text-to-speech readers. View it in your browsers, desktop preferably. https://twitter.com/... Sean Lyngaas / @snlyngaas : Adding my voice to the chorus of people praising this brilliant story from @hatr et al. The best infosec journalism is about humans, their rights, their quest to protect themselves from malicious forces. This story skillfully illuminates that struggle: https://web.br.de/... Siena Anstis / @sienaanstis : Absolutely genius use of graphics & fascinating reporting shining a light on digital threats faced by dissidents in Germany and the failure of authorities to respond. @RonDeibert @SharlyChan @jsrailton https://web.br.de/... Hakan / @hatr : Here is the english version of our investigation on #APT32/#OceanLotus, a group that is relentlessly targeting civil society. We're telling the stories of the people affected, of threat intel analysts tracking them and one (potential) mistake they've made https://web.br.de/...
Context & Ripple Effects
German audiences already know the shape of state-backed intrusion from the years-long Winnti campaign against German corporations uncovered by Bayerischer Rundfunk in 2019 — but that story was about companies as targets. The new BR24 investigation moves the target to people: OceanLotus (APT32) spying on Vietnamese opposition members and dissidents, including on German soil.
The reporting lands amid a broader documentation effort by security journalists and researchers — Catalin Cimpanu, Sean Lyngaas, and Siena Anstis among those amplifying it — into how spy work is increasingly outsourced and commercialized, from the hacker-for-hire group RocketHack compromising thousands of email and Telegram accounts to APT40's use of front companies. The relationships here note a sharp detail: German authorities failed to respond to the digital threats against the dissidents OceanLotus targeted.
First-order effects
- Vietnamese dissidents and opposition members in Germany remain exposed today, because the investigation documents that German authorities did not act on the digital threats against them — protection currently depends on the targets themselves and the researchers documenting the attacks.
Second-order effects
- Berlin faces an awkward position it helped create: it has opposed EU plans to ban Chinese suppliers like Huawei from telecom networks under new cybersecurity rules, while its own territory hosts state-linked spying on political exiles — giving domestic critics and EU partners leverage to question whether Germany's threat model covers people, not just firms.
Third-order effects
- If the pattern holds across the documented cases — Winnti hitting corporations, RocketHack selling intrusion to whoever pays, OceanLotus tracking dissidents abroad — the structural shift is toward espionage-as-a-service aimed at individuals, forcing democracies to decide whether diaspora protection becomes a formal security obligation rather than an ad hoc gap.
The trend: State-linked hacking is expanding from corporate espionage toward surveillance of exiled dissidents and civil society, with host governments like Germany slower to defend people than companies.