Lyce · Hybrid Watch

hw_54a40bae1130c1a0

Russian “hacktivists” briefly knock several German websites offline.

In late January 2023, a coordinated distributed-denial-of-service (DDoS) campaign attributed to the pro-Russian hacktivist group Killnet targeted multiple German websites including government portals, financial institutions and airport services. The campaign was reportedly triggered in response to Germany’s decision to send Leopard 2 battle tanks to Ukraine. German cybersecurity agency Bundesamt für Sicherheit in der Informationstechnik (BSI) said the attacks caused temporary inaccessibility but no major long-term system damage or service outages. The dynamics demonstrate a classic hybrid-warfare tactic: low-cost, high-visibility disruption aimed at signalling, raising cost and imposing uncertainty without direct kinetic confrontation. For Germany, the incident underscores that state, banking and transport IT systems form part of the modern battlefield when facing Russian-style hybrid operations. Although the article does not attribute the attack directly to the Russian government, the group’s alignment with Russian strategic aims and the timing of the action make it a pertinent example of Russian-influenced hybrid warfare. The event triggered warnings from Germany’s interior ministry and accelerated efforts to enhance resilience of digital critical infrastructure, particularly in defence, finance and transport sectors. It also illustrates how hybrid threats do not require territorial invasion—cyber-campaigns can reach deep into an allied state’s internal networks.

Occurrence
2023-01-25
Publication
2023-01-24T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
DE
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-01-24T23:00:00Z

    In late January 2023, a coordinated distributed-denial-of-service (DDoS) campaign attributed to the pro-Russian hacktivist group Killnet targeted multiple German websites including government portals, financial institutions and airport services. The campaign was reportedly triggered in response to Germany’s decision to send Leopard 2 battle tanks to Ukraine. German cybersecurity agency Bundesamt für Sicherheit in der Informationstechnik (BSI) said the attacks caused temporary inaccessibility but no major long-term system damage or service outages. The dynamics demonstrate a classic hybrid-warfare tactic: low-cost, high-visibility disruption aimed at signalling, raising cost and imposing uncertainty without direct kinetic confrontation. For Germany, the incident underscores that state, banking and transport IT systems form part of the modern battlefield when facing Russian-style hybrid operations. Although the article does not attribute the attack directly to the Russian government, the group’s alignment with Russian strategic aims and the timing of the action make it a pertinent example of Russian-influenced hybrid warfare. The event triggered warnings from Germany’s interior ministry and accelerated efforts to enhance resilience of digital critical infrastructure, particularly in defence, finance and transport sectors. It also illustrates how hybrid threats do not require territorial invasion—cyber-campaigns can reach deep into an allied state’s internal networks.