Hybrid attacks on the Bundeswehr and critical infrastructure are increasing significantly
Since 2022, Germany has recorded a noticeable rise in hybrid attacks on the Bundeswehr and critical infrastructure. This was confirmed by Vice Admiral Thomas Daum, the Bundeswehr's Chief of Cyber and Information Domain Service, at the NATO cyber defence exercise Locked Shields in Kalkar on the Lower Rhine. The threat situation has fundamentally worsened and now includes not only classic cyberattacks but also drone operations, disinformation campaigns and physical sabotage.
What has happened? – Key facts on the current threat situation
The cyberattacks are specifically targeted at two areas: Bundeswehr data centres in Germany and troops deployed abroad. A concrete example is the situation in Lithuania, where stationed Bundeswehr soldiers report attempts to eavesdrop on telephone conversations. Particularly notable is the parallel running of disinformation campaigns – false claims about contingent commanders were spread, for example, in order to create confusion and destabilisation.
In addition to the digital attacks, physical threats are also being documented: drone sightings in sensitive areas around barracks, intrusion attempts, damage to data cables and supply lines in the Baltic Sea as well as targeted jamming of the GPS system. This coordinated approach points to a systematic campaign to destabilise German defence structures.
The details – background and scale of the threats
According to a Bundeswehr spokesperson, four countries have been identified as the main perpetrators of these hybrid attacks: Russia, China, Iran and North Korea. These countries operate with different tactics and objectives, but partly coordinate their activities.
The attack methods are varied and differ depending on the target. While attacks on data centres are primarily cyberattacks, operations against troops abroad are aimed at psychological influence and creating uncertainty. The Lithuania example illustrates this strategy: it is not only the technical infrastructure that is attacked, but also the trust and morale of soldiers through deliberately spread false information.
Maritime infrastructure is also in the crosshairs. Damage to data cables and supply lines in the Baltic Sea points to concerted acts of sabotage intended to impair digital connectivity and energy supply.
Critical infrastructure in focus – the KRITIS network under pressure
Critical infrastructure (KRITIS) in Germany includes large energy suppliers, banks and IT service providers. According to estimates, the KRITIS network comprises more than 29,000 companies. The potential attack surface is therefore considerable.
Ukraine provides a cautionary example: shortly before Russia's large-scale attack, residents' registration offices there were attacked with the aim of deleting population data and hindering an organised mobilisation. This scenario shows that public authorities and administrative bodies can also come into the focus of cyberattacks – not just private companies.
Ukraine was able to protect itself by securing its data in good time. This underlines the importance of comprehensive backup and continuity measures for all organisations that are part of critical infrastructure.
Assessment – why is this development relevant?
The increasing hybrid attacks on the Bundeswehr and KRITIS mark a turning point in how the threat is perceived. The problem is no longer just individual cyberattacks, but coordinated campaigns combining digital and physical measures, disinformation and psychological influence. This approach makes defence and response considerably more difficult.
For operators of critical infrastructure this means that traditional security concepts are no longer sufficient. The threats are asymmetric, multidimensional and in part difficult to attribute. A focus purely on cybersecurity falls short – physical protection of infrastructure elements, information security and resilience planning are equally important.
NATO exercise Locked Shields – the largest multinational cyber defence exercise
In response to these threats, NATO is running the Locked Shields exercise. Around 40 nations take part in what is currently the world's largest and most complex multinational cyber defence exercise, including the Bundeswehr's cyber forces.
The exercise simulates real-time attacks by a "red team" that have to be repelled by a "blue team". Alongside military forces, civilian actors are also involved: German police and security authorities as well as IT specialists from companies such as Telekom. This illustrates that cyber defence is today a whole-of-society concern and cannot rest in the hands of the state alone.
Practical tips – recommended action for KRITIS operators
Based on the threat situation described, several concrete fields of action emerge:
- Data backup and redundancy: The Ukraine example shows the critical importance of regular, tested backups. KRITIS operators should back up data multiple times and across separate locations.
- Physical protection: Data cables, supply lines and barracks perimeters require increased protection. Access control and surveillance are essential.
- Training and awareness: Employees must be informed about disinformation campaigns and social engineering attempts.
- Plan incident response: Hybrid attack scenarios should be rehearsed and response protocols established.
- National and international cooperation: Sharing threat intelligence with authorities and partners is indispensable.
Outlook – further developments and requirements
The rising frequency and complexity of hybrid attacks will significantly increase security requirements in Germany. The Bundeswehr and civilian authorities will have to further expand their cyber defence capabilities.
The focus is on resilience rather than perfection: the aim is not to prevent every attack completely, but to be able to respond quickly and recover from attacks. The NATO exercise Locked Shields is a step in this direction, but must be supplemented by continuous operational adjustments.
For private KRITIS operators this means in concrete terms: investment in cybersecurity is not optional, but strategically necessary. It protects not only the individual company, but also contributes to the resilience of Germany's entire infrastructure – a responsibility that weighs more heavily than ever in times of hybrid threats.