Lyce · Hybrid Watch

hw_fe167c5dc884c412

Rheinmetall AG suffers a cyber-attack.

In mid-April 2023, German prosecutors in Cologne confirmed that Rheinmetall, a major German arms-manufacturer supplying military hardware to NATO and Ukraine, had suffered a cyber-attack on its business division servicing industrial customers (especially automotive), while its military division reportedly remained unaffected. The geography of the incident is Germany’s core industrial base–this is not a front-line border area, but a deeply internal target, which illustrates that hybrid-warfare threats can strike in the heart of an allied state’s defence-industrial complex. For Germany, the incident highlights its vulnerability in the defence-industrial sector–not just military bases or borders–but factories, supply-chains and dual-use systems are part of the contested domain. Although the origins of the attack were described as “unknown” in the Reuters piece, analysts pointed to the tempo of Russia-aligned adversary actions (especially given Rheinmetall’s support to Ukraine) as a plausible backdrop for such operations. The incident did not cause public disclosure of major system collapse, but the fact that the civilian-industrial arm was hit while the military arm was spared may reflect a deliberate targeting decision: to inflict economic/production disruption without triggering immediate war-time escalation. The cost and reputational impact for Rheinmetall–and by extension Germany’s defence posture–are significant: a reduced capacity, increased vulnerability, and the need for remediation and higher cyber-resilience.

Occurrence
2023-04-14
Publication
2023-04-14T16:47:48Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
DE
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2023-04-14T16:47:48Z

    In mid-April 2023, German prosecutors in Cologne confirmed that Rheinmetall, a major German arms-manufacturer supplying military hardware to NATO and Ukraine, had suffered a cyber-attack on its business division servicing industrial customers (especially automotive), while its military division reportedly remained unaffected. The geography of the incident is Germany’s core industrial base–this is not a front-line border area, but a deeply internal target, which illustrates that hybrid-warfare threats can strike in the heart of an allied state’s defence-industrial complex. For Germany, the incident highlights its vulnerability in the defence-industrial sector–not just military bases or borders–but factories, supply-chains and dual-use systems are part of the contested domain. Although the origins of the attack were described as “unknown” in the Reuters piece, analysts pointed to the tempo of Russia-aligned adversary actions (especially given Rheinmetall’s support to Ukraine) as a plausible backdrop for such operations. The incident did not cause public disclosure of major system collapse, but the fact that the civilian-industrial arm was hit while the military arm was spared may reflect a deliberate targeting decision: to inflict economic/production disruption without triggering immediate war-time escalation. The cost and reputational impact for Rheinmetall–and by extension Germany’s defence posture–are significant: a reduced capacity, increased vulnerability, and the need for remediation and higher cyber-resilience.