top of page
Germany in the Crosshairs of Hybrid Operations

30. Juni 2026

Richard Krauss

The Essentials in 30 Seconds


Russia treats Germany as an intelligence, influence and potential disruption environment. Military logistics, defence industry, transport, energy, digital infrastructure and political decision-making are priority target sets.

The 2025 constitutional protection report documents sabotage preparation against transport infrastructure, reconnaissance of military-relevant routes and persistent cyber access. It also identifies the use of low-level agents as a Russian operating pattern. Russian direction of extremist actors in Germany for sabotage has not been proven.

China pursues long-term strategic acquisition and influence activity against technology, research, industry and political target structures. Iran is intensifying surveillance and repression against the exile opposition, Jewish and Israeli institutions, and US-linked targets.

Intelligence Assessment


Germany is a priority operating environment for foreign intelligence services because it combines NATO military-logistics functions, continued support to Ukraine, defence-industrial capacity and critical infrastructure with high political and economic connectivity.

Russia presents the most immediate hybrid threat. Its operating model combines intelligence collection, cyber access, influence operations, disinformation and sabotage preparation. The target set extends beyond government and defence institutions to transport corridors, energy systems, logistics providers, industrial supply chains and political or societal multipliers.

The strategic objective extends beyond physical disruption. Russian sabotage activity also seeks to test NATO and member-state responses, weaken support for Ukraine, erode cohesion within the EU, NATO and German society, and strengthen political actors at the margins that amplify Russian narratives.


Russia: Reconnaissance, Proxies and Prepared Disruption


The available evidence does not establish a nationwide Russian sabotage campaign in Germany. It does establish concrete preparatory activity against transport and traffic infrastructure with direct relevance to military logistics.

In May 2025, three individuals were arrested in Germany and Switzerland on suspicion of preparing sabotage for Russia. They allegedly agreed with persons believed to be acting on behalf of Russian state actors to conduct arson and explosive attacks against the transport and traffic sector of critical infrastructure. The suspected purpose was to reconnoitre and obstruct arms deliveries and assistance shipments to Ukraine. One individual reportedly sent test packages containing GPS trackers to identify transport routes.

The case demonstrates a complete operational chain: target selection, route reconnaissance, compartmentalised preparation, use of intermediaries and potential disruption of military-relevant logistics. Limited incidents can create disproportionate effects by delaying movement, forcing additional protective measures, diverting investigative resources and increasing uncertainty about the resilience of transport networks.

A central feature of the Russian approach is plausible deniability. The operating pattern makes it difficult to distinguish Russian-directed sabotage from extremist activity, criminal conduct, accidents or technical failures. Public denial and ambiguous methods complicate attribution and can amplify public uncertainty.

The use of low-level agents reinforces this mechanism. Recruited individuals may not know that the ultimate tasking originates from a foreign intelligence service. This reduces visibility of command structures, increases deniability and lowers the operational threshold for hostile activity.


Attribution: No Automatic Link Between an Incident and a Hybrid Operation


Not every fire, outage or attack against critical infrastructure constitutes a Russian intelligence operation. Russia may nevertheless benefit from uncertainty if public debate assigns responsibility before an evidentiary chain is established.

The attack against Berlin’s energy-sector critical infrastructure on 3 January 2026 illustrates the requirement for analytical discipline. The incident is security-relevant. It does not, by itself, establish Russian direction.

Assessment must integrate target selection, method of attack, prior reconnaissance, communications patterns, financial flows, travel movements, digital traces and intelligence indicators. Political or media attribution cannot substitute for verified operational assessment.

Some suspected incidents may have a probable sabotage background while others show no indicators of state direction. This distinction must remain intact throughout the assessment process.


Extremism and False-Flag Risk


Russian services may find pragmatic or ideological access points within extremist and criminal milieus. This creates a risk that independently motivated actors could be influenced or exploited for Russian objectives, including attacks against critical infrastructure or false-flag operations.

The evidentiary boundary remains clear: there is currently no proof that Russian state bodies have instrumentalised extremists in Germany to conduct sabotage. This remains a risk scenario, not an established case pattern.

Violence-oriented left-wing extremism retains its own target logic. Defence firms, suppliers, the Bundeswehr, police institutions and critical infrastructure remain relevant target categories. Any overlap with Russian strategic interests must therefore be assessed case by case rather than presumed.

The report does not identify a distinct additional mobilisation effect within German right-wing extremism resulting from Russia’s war against Ukraine. Its threat profile nevertheless remains high, particularly due to younger, digitally networked and action-oriented groups.


Cyber Domain: Access Before Effect


Russian cyber operations primarily support intelligence collection, but the separation between cyber espionage and cyber sabotage is often not operationally clear. The same intrusion can provide intelligence on a target environment while creating the technical conditions for later disruption.

Malware deployed for information collection in an energy company may unintentionally—or deliberately—cause supply outages. State cyber actors can also establish concealed access or pre-position malicious code inside IT environments for possible later activation in sabotage operations. Critical infrastructure is particularly exposed because compromise of control systems can affect essential public services and damage confidence in state capacity.

The current assessment remains limited. During the reporting period, only isolated, low-threshold attempts linked to cyber sabotage were identified. There is no evidence of concrete pre-positioning campaigns that produced material operational effects. Pre-positioning is therefore a documented method and capability risk, not evidence of an ongoing cyber-sabotage campaign against German critical infrastructure.

Persistent access to communications systems, user accounts and internal documents enables the reconstruction of decision processes, contact networks, schedules and personal vulnerabilities. This information can support influence operations, recruitment, targeted engagement and later disruption activity.

Device-code phishing is a relevant technique against politically affiliated non-governmental organisations. APT 28, attributed to the Russian military intelligence service GRU, again obtained internal data from a German political foundation in 2025. The operational value lies in sustained situational awareness within political and societal target structures rather than in the extraction of individual documents.


China: Strategic Penetration


China pursues a long-term intelligence, procurement and influence approach. Germany is among its important targets for access to political, military, economic and scientific information, strategic technology and decision-making processes.

Relevant target areas include dual-use research, high technology, specialised industrial supply chains, satellite technologies, maritime technologies and research institutions holding security-relevant knowledge. Chinese activity also includes the monitoring of regime-critical structures abroad and attempts to influence political and economic decision-makers in the interests of the party-state.

China’s operating model is not primarily designed for immediate disruption. It seeks sustained access to knowledge, technology, dependencies and channels of influence. The report refers to several investigations and arrests linked to suspected Chinese intelligence activity in 2024 and 2025.


Iran: Repression, Target Reconnaissance and Escalation Risk


Iranian intelligence services focus on the exile opposition, Jewish and Israeli institutions, pro-Israeli individuals and increasingly US-linked targets. The threat picture intensified after the violent suppression of protests in Iran from late December 2025 and the onset of the Iran war in late February 2026.

Iranian activity includes digital and physical surveillance, mapping of private and professional networks, identification of movement patterns and collection of information on security arrangements. Such reconnaissance can support intimidation, abduction, attacks or targeted killings.

Iranian intelligence services increasingly use state-terrorist means against pro-Israeli and pro-Jewish targets. In 2025, German authorities held concrete intelligence on reconnaissance activity directed at relevant institutions and individuals.


Net Assessment


Russia currently has the strongest immediate capacity to combine intelligence collection, cyber access, influence operations, low-level-agent recruitment and sabotage preparation against German target sets. Its objectives extend beyond local disruption: testing NATO responses, weakening Ukraine support and eroding cohesion are integral elements of the operating model.

China remains the principal long-term actor for strategic technology acquisition, industrial penetration and influence in research, business and political decision-making environments.

Iran presents a focused but acute threat to exile opposition networks, Jewish and Israeli target groups, and US-linked institutions through surveillance, transnational repression and potential preparation for physical violence.

The core operational challenge for German authorities is rapid, evidence-based distinction between independently motivated extremist violence, criminal conduct, technical failure and foreign-state-directed activity. This attribution determines whether an incident remains a local security event or forms part of a wider hybrid operating picture.


Glossary


APT 28
Russian cyber group attributed to the GRU, Russia’s military intelligence service.


Device-Code Phishing
A social-engineering technique used to bypass multi-factor authentication and seize control of user accounts.


False Flag
An operation designed to create the impression that another state, actor or organisation is responsible.


GRU
Military intelligence service of the Russian Federation.


Low-Level Agent
A recruited intermediary who conducts limited operational tasks and may not know that the ultimate tasking originates from a foreign intelligence service.


Pre-Positioning
The covert establishment of access or placement of malicious code in a target environment for possible later activation.


Critical Infrastructure
Infrastructure whose failure or disruption could substantially impair supply, public security or state capacity to act.


State Terrorism
The use of serious crimes by state services or state-directed proxies—including abductions, attacks, killings or preparatory reconnaissance—to harm individuals, intimidate a population or compel political action. It represents the escalatory end of transnational repression but is not synonymous with it.


Transnational Repression
Coercive or unlawful action by a state against opposition figures, regime critics or diaspora members outside its own territory. It includes surveillance, intimidation, threats, digital intrusion and pressure against family members. In severe cases, it can escalate into state terrorism.


References


Federal Office for the Protection of the Constitution
Verfassungsschutzbericht 2025
Chapter: “Effects of Russia’s War of Aggression Against Ukraine on Germany’s Security Situation”, pp. 74–89


Federal Office for the Protection of the Constitution
Verfassungsschutzbericht 2025
Chapter: “Espionage, Cyberattacks and Other Security-Endangering or Intelligence Activities on Behalf of a Foreign Power”, pp. 332–395


Federal Office for the Protection of the Constitution
Verfassungsschutzbericht 2025
Chapter: “Left-Wing Extremism”, especially attacks against critical infrastructure and business targets, pp. 164–195

Expertise Tags (no search)
bottom of page