hw_b47ed727953c8cc1
Cyberattack on German Air Safety and Infrastructure.
The German Foreign Ministry formally accused the Russian military intelligence service (GRU) of conducting a sophisticated cyberattack against the nation’s air traffic control systems. Intelligence services identified the “handwriting” of the APT28 hacker collective (Fancy Bear), which is directly managed by the GRU, in the breach of German Air Safety protocols. The attack was not an isolated incident but part of a broader “hybrid pressure” campaign aimed at undermining public trust in democratic institutions ahead of the 2026 general elections. Beyond technical disruption, the GRU was found to be using deepfake images and disinformation to divide German society and target prominent politicians. German officials warned that these cyber operations are increasingly being synchronized with physical sabotage efforts across the European Union. In response, Berlin announced a series of countermeasures, including new individual sanctions against hybrid actors and stricter monitoring of Russian diplomats within the Schengen Area. The incident underscores Russia’s intent to use its cyber capabilities to create “latent threats” that can be activated to paralyze critical infrastructure during political transitions.
E/M/R/S scores
- EExistence0/4 · Not assessed
- MIntent0/4 · Not assessed
- RRussian actor link0/4 · Not assessed
- SRussian state responsibility0/4 · Not assessed
Facts
No facts
Sources
-
- Role
- discovery_lead
- Date
- 2025-12-04T18:34:57Z
The German Foreign Ministry formally accused the Russian military intelligence service (GRU) of conducting a sophisticated cyberattack against the nation’s air traffic control systems. Intelligence services identified the “handwriting” of the APT28 hacker collective (Fancy Bear), which is directly managed by the GRU, in the breach of German Air Safety protocols. The attack was not an isolated incident but part of a broader “hybrid pressure” campaign aimed at undermining public trust in democratic institutions ahead of the 2026 general elections. Beyond technical disruption, the GRU was found to be using deepfake images and disinformation to divide German society and target prominent politicians. German officials warned that these cyber operations are increasingly being synchronized with physical sabotage efforts across the European Union. In response, Berlin announced a series of countermeasures, including new individual sanctions against hybrid actors and stricter monitoring of Russian diplomats within the Schengen Area. The incident underscores Russia’s intent to use its cyber capabilities to create “latent threats” that can be activated to paralyze critical infrastructure during political transitions.