Bundestag Hack (2015)
Jump to navigation Jump to search
|Date||Detected in May 2015|
|Suspected actor||The investigations of the German Authorities indicate that the Russian hacking group 'APT 28' is responsible for the attack.  The British Cyber defense agency has alleged that this group is linked to the Russian military secret service 'GRU' which has also been accused of meddling with the US Presidential elections in 2016. |
|Target||The network of the German Federal Parliament used by all MPs as well as the German chancellor|
|Method||At the beginning of 2015, MPs received an email from the address 'UN.org' which was designed like a UN News Bulletin. Clicking on the link contained in the email led to the installation of the malware on the computer. The malware was then able to spread and eventually infiltrated the networks of the Parliament. |
|Purpose||The hackers were able to access internal confidential communication data (such as confidential emails of MPs), their schedules, meeting details as well as other sensitive data.|
|Result||The group was able to maintain unauthorized access for several months until the attack was detected in May 2015 and even managed to access a computer in the parliamentary office of the chancellor.  Approximately over 16 GB of data was stolen. |
|Aftermath||The German parliament's computer system was shut down for four days for maintenance works and additional safety mechanisms were installed.  Investigations initiated by the German intelligence service led to the conclusion that the attack had been launched by a 'foreign intelligence service'. According to Die Zeit, the Chancellery staff considered responding to the malicious activity since they were convinced that the intruders had been acting on behalf of Russia. |
|Analysed in||Scenario 02: Cyber espionage against government departments|
- BBC, "Russia 'was behind German parliament hack", (13 May 2016), BBC News.
- UK National Cyber Security Centre, "Reckless campaign of cyber attacks by Russian military intelligence service exposed", (3 October 2018), NCSC News.
- J Delcker, "Germany fears Russia stole information to disrupt election", (20 March 2017, last updated 28 January 2018), Politico.
- A Biselli, "Wir veröffentlichen Dokumente zum Bundestagshack: Wie man die Abgeordneten im Unklaren ließ", (7 March 2016), Netzpolitik.
- M Baumgartner, P Beuth, J Diehl, C Esch et al, "The Breach from the East", (18 March 2018), Der Spiegel.
- AFP, "Bundestag IT system shut down after hacker attack", (20 August 2015), Deutsche Welle
- P Beuth, K Biermann, M Klingst, H Stark, "Merkel and the Fancy Bear", (12 May 2017), Die Zeit.