Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Germany’s Federal Government attributed a months-long cyber espionage campaign to APT28, which it said operates for Russia’s military intelligence service, the GRU. The government said the group exploited a critical Microsoft Outlook vulnerability to compromise numerous email accounts, including those of the Social Democratic Party of Germany’s (SPD) executive committee. It also identified targets in several sectors and countries.

Who did Germany blame?

In its public attribution on 3 May 2024, Germany’s Federal Government said its national attribution procedure concluded that APT28 was responsible for the campaign and that the actor was attributable to the Russian Federation, specifically the GRU. The government described this as a conclusion based on information from its intelligence services: “Based on reliable information provided by our intelligence services, the actor APT28 has been attributed to the Russian Federation, and more specifically to the Russian military intelligence service GRU.” Germany’s statement links APT28 to the 2015 cyberattack on the German Bundestag as well.

This is Germany’s official assessment, not a public release of the underlying intelligence record. The statement explains the government’s conclusion but does not disclose the intelligence used to reach it. The Associated Press also referred to APT28 as Fancy Bear in its coverage.

What was targeted, and how?

The SPD and email accounts

Germany identified the SPD executive committee as a prominent target. It said APT28 exploited a critical Microsoft Outlook vulnerability that had not been identified at the time, compromising numerous email accounts over a relatively long period. The government’s release does not give a vulnerability identifier, describe the exploit chain, or state how many accounts were affected.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other sectors and locations

The campaign extended beyond the SPD. Germany listed government authorities and organizations in logistics, armaments, aerospace and IT services, as well as foundations and associations. Its statement described targets in Germany, other European countries and Ukraine. The EU’s same-day statement separately named Czechia as a target.

How long did the campaign last?

The German attribution release characterizes the compromise as lasting “a relatively long period.” Reporting by the Associated Press, citing the German Interior Ministry’s timeline, said the campaign began at least as early as March 2022 and that access to SPD headquarters email began in December 2022. Those dates come from AP’s account of the ministry’s statement, rather than the short public attribution release itself.

Germany made its public attribution on 3 May 2024. The Council of the European Union issued its statement condemning the campaign that day, and Germany’s Foreign Office published a further statement on 6 May repeating the attribution and target sectors. The full duration, total scope and damage assessment have not been disclosed in the cited public statements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How did Germany and the EU respond?

Germany condemned the campaign and said it was determined to work with European and international partners. The Council of the EU condemned the activity, identified Germany and Czechia as targets, and said institutions in Poland, Lithuania, Slovakia and Sweden had previously been targeted by the same actor. It described a coordinated European response posture and said the EU would use the full spectrum of measures to prevent, deter and respond to malicious Russian cyber activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The EU statement did not announce a new sanction specifically tied to this campaign. Its language sets out a response posture, not confirmation that a campaign-specific measure had already been imposed.

What is established publicly—and what remains undisclosed?

  • Germany’s assessment: The Federal Government attributed the campaign to APT28 and the GRU, based on information from its intelligence services.
  • Publicly described activity: Germany said the actor exploited a then-unidentified critical Outlook vulnerability and compromised numerous email accounts.
  • Publicly named targets: The SPD executive committee and organizations across government, logistics, armaments, aerospace, IT services, foundations and associations, in Germany, elsewhere in Europe and Ukraine.
  • Not specified in the cited statements: A CVE number, the exploit chain, the number of affected accounts, the complete scope of compromise and the full damage assessment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.