
AI-generated summary
Due to the lack of its own large IT companies and control over digital platforms, Germany is dependent on foreign technology. Since the Bundestag hack in 2015, there have been repeated attacks on authorities and municipalities, with the highest number of attacks recorded in 2025.
The hacker attack on the Berlin administration was not a wake-up call; it was the most massive attack to date in the capital of Europe's largest economy - and it worked. First, the attackers hijacked central parts of the city administration's networks and computers, then they accessed huge amounts of data, took them virtually hostage and, after refusing to pay the required ransom, finally made their stolen goods public in the darkest corners of the Internet.
In view of the captured information on important arms companies and nationwide infrastructure, on vital facilities, personal data, civil defense, crisis, emergency and operational plans, this is a catastrophe not only for the capital, but for the entire country. Because functioning cyber protection is the basis for what is often presented as an honorable goal: digital sovereignty. But this cannot be achieved without the security of existing systems.
See F.A.Z. articles more often in your search results
F.A.Z. prefer on Google
Blatant weaknesses
Germany has no longer been able to act independently in virtual space using its own strengths and resources for a long time. On the other hand, it lacks its own large IT companies, its own cutting-edge technologies and digital platforms that it controls. The country has no well-known manufacturers of computers, processors or memory chips. The majority of the software used in Germany comes from overseas; the important providers of AI systems are based in America or China.
This weakness makes you vulnerable. So it's no wonder that no other country in the EU is in the crosshairs of hackers as often as Germany. Every day, local authorities register thousands of serious cyber crimes; Every day, six out of ten Internet users fall victim to cyber criminals, and every day nine out of ten companies are hit by hacker attacks. Every third attack can be attributed to foreign states. The damage now amounts to a massive 270 billion euros per year.
But it's not just about the money. Since the hacker attack on the Bundestag network in 2015, it has been clear that the digital snipers have also set their sights on politics. In 2017 they targeted local party foundations and in 2018 they targeted the federal administration. In 2021 they paralyzed the computers of the Anhalt-Bitterfeld district, and in 2023 those of 70 municipalities in North Rhine-Westphalia. In 2025, more attacks were registered nationwide than ever before. And now it hit Berlin.
The big mess
The metropolis's digital infrastructure is as complicated as its bureaucracy itself. In addition to twelve district administrations, there is the central headquarters including the ten senate administrations and their around 40 subordinate institutions, offices and authorities. The state network is structurally designed centrally, but is used decentrally, as many individual districts maintain their own IT systems. The Senate can issue guidelines for everyone, but ultimately cannot affect the structures of the individual districts.
This two-tier system, with its tens of thousands of computers and hundreds of specialized programs, is expensive and confusing, but from a technical point of view that doesn't have to be a disadvantage. Because IT that is confusingly decentralized is harder to hack than one that is clearly organized centrally. The latest cyber attack was not aimed at the small-scale IT systems of the Berlin districts, but at those of the large headquarters. Here the hackers found what they were looking for: vulnerabilities in the system of two Senate administrations.
This is not only due to deficiencies in assigning passwords or careless use of technology by employees. The vulnerability also stems from a larger gap. The state administration is generally covered by the EU guidelines on network and information security. However, due to Germany's federal constitution, it is at least partially excluded from the binding federal catalog of obligations incorporated into national law. In addition to the big IT confusion, there is also a no less big legal confusion.
After the defeated traffic light government promised a lot when it came to digital security and delivered nothing, the incumbent government did well to provide clarity and act quickly. In May she presented a draft law to strengthen cybersecurity. By the end of the year, the Federal Ministry of the Interior will have presented a plan for a national detection and cyber defense system. The Federal Office for IT Security is to be expanded into a federal-state platform for cybersecurity. The intelligence services will have more powers in virtual space than before. The attack on Berlin's IT systems was not a wake-up call, but a declaration of war.
AI outlook — possibilities, not facts
The Federal Ministry of the Interior will present a plan for a national detection and cyber defense system by the end of the year.
Likely · Within months
The Federal Office for IT Security is being expanded into a federal-state platform for cybersecurity.
Likely · Within months
The intelligence services will have more powers in virtual space than before.
Likely · Within months
ESA has promised €200 million in funding to Bavarian startup Isar Aerospace following the successful test flight of the Spectrum rocket in September. ESA chief Josef Aschbacher emphasized the symbolic value of the launch and announced additional funding for a European observation system to monitor hybrid threats to compete with the US and China.
Digital Minister Karsten Wildberger and DGB boss Yasmin Fahimi debate the use of AI in Germany: Wildberger calls for rapid introduction for growth and competitiveness, Fahimi emphasizes co-determination, qualification and social security. Both see opportunities only through joint action.

AI expert Stuart Russell warns of the risks of out-of-control AI at the DLD conference in Munich. He criticizes current regulatory approaches and advocates safer technological development in order to avoid existential threats.

The AI company Anthropic publishes a security report about the misuse of its Claude service. Users are already using AI for illegal activities such as data theft, fraud and assisting in the production of weapons.
After Mayor Kai Wegner refused to pay a two million euro ransom in Bitcoin, the hacker group Rhysida's ultimatum for sensitive data from Berlin expired.

Anthropic researcher Jacob Coxon has left the company, warning that AI could kill all humans by the end of the decade. Expert Nate Soares calls for a state oversight board.