Infosecurity
Chinese and Russian spies are stepping up cyberattacks on German companies, new survey finds
Published
45 minutes agoon

German companies point the finger at foreign spies
The hulking steelworks of Thyssenkrupp on the Rhine in Duisburg might seem an unlikely digital battleground. But according to a new survey, foreign intelligence services — especially those from China and Russia — are increasingly behind cyberattacks on German companies.
Nearly four in 10 German businesses hit by data theft, industrial espionage or sabotage in the past year said they could trace at least one incident back to a foreign intelligence service. That’s a sharp jump from 28% last year and just 7% in 2023, according to the German digital industry association Bitkom.
The findings come from a survey of 1,003 German companies with at least 10 employees. They paint a picture of a corporate sector increasingly caught in the crosshairs of state-sponsored hacking.
China and Russia lead the pack
China was the most frequently cited foreign source of attacks. More than half of the companies that experienced an incident said they had traced at least one attack to Beijing. Russia ranked second, and Iran emerged as a significant player too — roughly one in 10 affected companies linked an incident to Tehran.
Sinan Selen, president of Germany’s domestic intelligence agency, didn’t mince words at the study’s presentation. “Foreign intelligence services have intensified their hybrid activities and are increasingly responsible for attacks on the German economy,” he said. He singled out Germany’s security and defense industry as a particularly attractive target.
What’s striking is the sheer scale of the problem. More than two-thirds of surveyed companies said they had experienced a successful cyberattack of some sort in the last 12 months. That’s not a niche concern — it’s the new normal for German business.
The blurred line between criminals and spies
Organized crime remains the biggest source of attacks identified by companies. But Bitkom’s president, Ralf Wintergerst, argues the distinction between criminal gangs and state intelligence agencies is dissolving.
“The lines between organized crime and intelligence services are blurred in many countries,” Wintergerst said. “Intelligence services utilize criminal structures, and conversely, criminals are given free rein as long as they choose their targets in accordance with political directives.”
That blurring makes attribution harder and defense trickier. A ransomware gang might look like a purely profit-driven outfit, but its targets can align suspiciously well with a foreign power’s strategic interests.
The staggering cost of cyberattacks on German firms
The economic toll is hard to overstate. Bitkom estimates that cyberattacks cost German businesses between $186 billion and $240 billion over the past year. That includes business interruptions, investigations, recovery efforts, legal disputes, extortion payments, and lost revenue and competitive advantages.
Ransomware remains the most common form of attack, with one in four companies reporting that attackers encrypted their data and demanded payment. But the threat landscape is broader: phishing, password attacks, distributed denial-of-service attacks, malware infections, communications interception and corporate data theft all made the list.
The damage often ripples outward. A successful attack on one company can cause production outages at business partners or reputational harm for customers, the researchers noted. It’s not just the direct victim that bleeds.
Real-world incidents hit German institutions
This isn’t abstract. Several prominent German organizations have disclosed cyber incidents this year.
- Lidl — the discount supermarket giant revealed in July a data breach after attackers gained access to customer information held by one of its IT service providers.
- Unimed — in April, hackers targeted this external billing provider used by medical centers across Germany. Several university hospitals later said patient information had been stolen.
- Dresden State Art Collections — in January, one of Europe’s oldest museum networks was hit by a targeted cyberattack that disrupted large parts of its digital infrastructure.
These are not obscure targets. They’re household names and critical institutions. And they show that no sector is off-limits.
What German businesses can do about state-sponsored hacking
The Bitkom survey is a wake-up call, but it’s not all doom and gloom. There are practical steps companies can take to harden their defenses against state-sponsored hacking and industrial espionage Germany faces.
First, treat threat intelligence seriously. Knowing who’s likely to target you — and why — helps prioritize defenses. Second, invest in basics: multi-factor authentication, regular patching, and employee training on phishing. Third, have an incident response plan ready before the breach, not after.
For smaller firms, the cost of robust security can feel prohibitive. But the price of a single ransomware attack or data theft often dwarfs the investment in prevention. The survey’s numbers make that math painfully clear.
The threat from foreign intelligence services isn’t going away. It’s growing, becoming more sophisticated, and increasingly indistinguishable from organized crime. German companies — and businesses everywhere — need to adapt or risk becoming the next statistic.
You may like
Infosecurity
Manchester Airports Group Confirms Data Breach: What Travelers Need to Know
Published
4 hours agoon
August 28, 2026
What Happened in the MAG Cyber Incident?
The Manchester Airports Group (MAG) — the operator behind Manchester, London Stansted, and East Midlands airports — has confirmed a cyber incident that exposed customer data. An unauthorized third party accessed information tied to car park reservations, lounge bookings, Fast Track passes, and in-airport Wi-Fi sign-ups.
The breach was contained quickly, according to MAG, which is now working with specialist advisers and the relevant authorities. The group moved fast to restrict access to affected systems.
Here’s the key reassurance: passenger safety and aviation security were not compromised. Airport operations continue to run normally.
What Customer Data Was Exposed?
The stolen data includes email addresses, phone numbers, vehicle registration numbers, and postcodes. That’s a nasty mix for travelers, because it gives attackers a head start on crafting believable scams.
MAG was quick to clarify that neither it nor the affected system stored bank or payment details. So no credit card numbers were taken — but the exposed info is still dangerous.
Raghu Nandakumara, VP of industry strategy at Illumio, called this “a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports.”
His warning is blunt: the exposed data increases the risk of targeted phishing and smishing attempts. Attackers can use legitimate travel-related details to make malicious communications look convincing.
Why This Data Is a Goldmine for Scammers
Think about it. A scammer with your email, phone number, vehicle registration, and postcode can craft a message that looks like it’s from MAG. They might reference your actual booking or your car’s license plate to seem legitimate.
That’s the core danger here. It’s not just about the data itself — it’s about how believable the follow-up scams can be.
Phishing and Smishing Risks
Phishing comes via email. Smishing via SMS. Both are designed to trick you into clicking links or opening attachments that install malware or steal credentials.
MAG has contacted affected customers directly and advised them to stay alert for suspicious emails, texts, and phone calls. Their guidance is simple: don’t click links or open unexpected attachments.
Are Your Bookings Still Valid?
Yes. MAG says all upcoming bookings remain valid, and customers don’t need to take action regarding existing reservations. That’s a relief for anyone with summer travel plans.
However, the online Manage My Booking service has been temporarily suspended as a precaution. If you need to amend a booking within 72 hours, you’ll have to contact MAG’s customer services team directly.
The team is available on weekdays between 9am and 5pm, though call wait times may be longer than usual. Patience will be required.
How MAG Is Responding
The company has restricted access to affected systems, engaged specialist cybersecurity experts, and notified the relevant authorities. Its Data Protection team is overseeing the response.
Nandakumara emphasized that measures like network segmentation can help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident.
That’s a technical detail, but it matters. It shows MAG is thinking about containment, not just cleanup.
What Should Affected Customers Do Now?
If you’ve used car parks, lounges, Fast Track, or Wi-Fi at any of the three airports, here’s your action plan:
- Watch for suspicious emails, texts, or calls claiming to be from MAG or related travel services.
- Don’t click links or open attachments unless you’re certain of the sender.
- Be extra cautious with any message that references your vehicle registration or postcode — that’s data scammers now have.
- Consider changing passwords for email accounts and any travel-related online services.
- Report any suspicious communications to MAG’s customer services team.
The incident did not affect airport operational systems, and passengers have been told to continue traveling as normal. The airports themselves remain open and functional.
This is a reminder that airport cyber security isn’t just about keeping planes in the air — it’s about protecting the personal data of every traveler who passes through. For more on how airports handle these threats, check out our coverage of the supply chain attack that caused airport chaos earlier this year.
Stay safe out there. And if you get a suspicious message about your airport booking, think twice before you click.
Infosecurity
Interpol’s Operation Jackal IV Exposes 263 Suspects in Global Crackdown on West African Cybercrime
Published
1 day agoon
August 27, 2026
A Coordinated Eight-Month Push Against Financial Fraud
Interpol has pulled back the curtain on a sprawling investigation that identified 263 suspects and resulted in 58 arrests. Operation Jackal IV, which ran from November 2025 to June 2026, spanned 22 countries across six continents. The announcement came on August 25, with Interpol framing the effort as a direct strike against West African organized crime groups profiting from cyber-enabled financial fraud.
The operation didn’t just chase street-level criminals. It targeted the infrastructure that keeps these networks alive — money laundering channels, high-value targets, and the assets that fund further criminal activity. This wasn’t a single raid. It was a coordinated, multi-national campaign designed to dismantle entire ecosystems.
This latest push builds on the momentum of Operation Jackal III, which saw 300 arrests in 2024. The pattern is clear: Interpol is doubling down on African cybercrime, and the results are compounding.
South Africa: Romance Scams and Retiree Targets
In South Africa, police executed raids at seven locations tied to a syndicate that ran romance and investment scams. Their victims? Retirees living in English-speaking countries. The emotional toll of these schemes is hard to quantify, but the financial damage is not.
Authorities arrested 39 people, froze 257 bank accounts, and seized $2.67 million in assets. It’s a significant blow, but it also highlights how lucrative these operations have become. Scammers aren’t just phishing for pocket change anymore. They’re running sophisticated operations that drain life savings.
Romania: A Call Center Disguised as an Investment Firm
Romanian authorities took down a different kind of beast — a call center operation that peddled fake investment opportunities. The pitch was familiar: high returns from stocks and cryptocurrencies. The reality was a €143 million fraud machine.
The arrests netted 11 people, along with roughly €330,000 ($385,000) in cash and cryptocurrency. Police also seized six properties and a collection of luxury watches. When you see assets like that, you understand the scale of the grift. This wasn’t a side hustle. It was an industry.
Argentina: The Crime-as-a-Service Connection
Perhaps the most intriguing piece of the puzzle emerged in Argentina. Interpol identified a 196-person Crime-as-a-Service (CaaS) network that allegedly supplied website domains and money laundering support to West African organized crime groups. Seventeen people were arrested.
This is the modern face of cybercrime. Criminal groups are outsourcing their technical needs to specialists, much like legitimate businesses outsource their IT. The CaaS model means you don’t need to be a tech genius to run a global scam. You just need to know who to pay.
Interpol’s country-level arrest figures actually total more than the 58 arrests reported for the operation overall, suggesting some cases are still being processed or transferred between jurisdictions.
A Growing Concern: Sextortion and Child Victims
Beyond the financial toll, investigators flagged a disturbing trend: an increase in sextortion targeting minors. Some victims were as young as 14. This isn’t just a money crime anymore. It’s a threat to vulnerable young people, and it demands a different kind of response.
Interpol also noted that some criminal networks were purchasing CaaS capabilities from external providers to outsource money laundering and other activities. The lines between different types of cybercrime are blurring, and law enforcement is having to adapt.
Following the Money to Break the Cycle
Tomonobu Kaya, director of the Interpol Financial Crime and Anti-Corruption Centre, summed up the strategy: “following illicit financial flows across borders” to target what he called the lifeblood of organized crime. It’s a simple concept with complex execution.
The results speak for themselves. Millions in assets seized, hundreds of suspects identified, and a clear message sent to criminal networks: your money is traceable, and your operations are not invisible.
For a deeper look at how Interpol is leveraging international cooperation, check out our coverage of the Chinese-funded Interpol cybercrime crackdown that led to 5,800 arrests. The scale of these operations is growing, and the collaboration between nations is becoming more sophisticated.
If you’re interested in how these scams actually work on the ground, our analysis of romance scam tactics and prevention offers practical insights. And for those tracking the evolution of digital fraud, our piece on Crime-as-a-Service business models explains why these networks are so hard to dismantle.
Infosecurity
Agent Tesla v4: New Malware Variant Hides in Emoji to Steal Credentials
Published
1 day agoon
August 27, 2026
Agent Tesla v4: A Smarter, Sneakier Infostealer
There’s a new version of Agent Tesla malware making the rounds, and it’s brought some tricks that should worry anyone in finance. Researchers at KnowBe4 just published a deep dive on Agent Tesla v4, an infostealer that’s been spotted arriving via a business email compromise (BEC) lure aimed squarely at accounting departments.
The headline feature? Unicode emoji characters scattered through the malicious code. Hearts, water droplets, the works. It sounds almost playful, until you realize what those little symbols are doing: breaking string-based signature matching and making the code noisy enough to slip past casual review.
This isn’t your run-of-the-mill credential stealer. It’s designed to evade detection at every turn, and it’s good at it.
How the Attack Unfolds
The delivery mechanism is a JScript dropper, which can be launched with a simple open-with dialog. The email itself is a forwarded thread, made to look like internal correspondence. The recipient is brought in late, told to confirm an attached document, and reply. Classic social engineering, executed well.
The attackers spoofed the address of Metropolitan Bank and Trust Company, a legitimate Philippines-based commercial bank. The whole thread feels like an in-progress discussion you’ve just been pulled into. That urgency, that sense of being out of the loop—it works.
The Emoji Obfuscation Trick
Once the JScript dropper runs, it writes two files to C:UsersPublicLibraries. One is a decoy. The other passes the payload into DonutLoader shellcode for reflective PE injection. That means the final Agent Tesla binary never touches the filesystem. File-based scanners? Useless.
The emoji characters are interleaved directly through the script body. They disrupt signature matching and make the code visually noisy. A human glancing at it in a text editor sees a mess. An automated scanner sees something it doesn’t recognize. Both are defeated.
KnowBe4’s researchers note that any YARA rule looking for the Unicode code points alongside JScript-specific patterns will catch this family. A rule matching both the emoji distribution pattern and WScript.Shell or CreateObject calls will do it. That’s the mitigation playbook, in a nutshell.
Evasion Techniques That Go Beyond Emojis
The obfuscation doesn’t stop at the dropper. Agent Tesla v4 is scrambled with ConfuserEx, an obfuscator tool that makes the assembly nearly unreadable. Its embedded metadata presents the malware as a Python installer. A little misdirection, a little disguise.
The malware also checks for debuggers using a standard Windows function. If it detects one, it stops running. No analysis, no sample collection, no fun for researchers.
Before harvesting anything, it creates a persistent hardware fingerprint. That lets attackers track victims across OS reinstalls and IP rotations. Even if you rebuild your machine, they know it’s you.
It also disables validation for all outgoing connections, ensuring smooth communication with C2 infrastructure without triggering security alerts or errors. Persistence is the name of the game.
Credential Theft and Data Exfiltration
Once it’s settled in, Agent Tesla v4 sweeps credentials from more than 40 applications. Web browsers, messaging platforms, native Windows credential repositories—it’s all fair game. It also has a keylogger and clipboard tool for intercepting keystrokes and copied text.
All exfiltrated files carry a system fingerprint header: timestamp, username, computer name, OS name, CPU, RAM, public IP, and the MD5 hardware ID. That’s a lot of identifying information, all packaged neatly for the attacker.
The credential dump lands on the attacker’s FTP server within seconds of execution. No delayed staging, no waiting around. The whole operation is fast, efficient, and ruthless.
What Security Teams Should Do
KnowBe4’s advice is straightforward: update email security rules to catch Agent Tesla before it can harvest credentials. The emoji obfuscation doesn’t survive YARA rules that look for the specific Unicode code points used alongside JScript patterns.
For defenders, that means:
- Deploy YARA rules that match emoji distribution patterns combined with WScript.Shell or CreateObject calls.
- Monitor for unusual JScript activity, especially in environments where it’s rarely used.
- Train finance teams to recognize BEC lures, even when they look like internal threads.
- Keep an eye on outbound FTP traffic to unknown domains.
Agent Tesla has been around for years, but this version shows the threat is evolving. Emoji obfuscation is a new twist on an old problem. The fundamentals, though, remain the same: verify before you click, and keep your email filters sharp.
For more on defending against credential theft, check out our guide on phishing email detection best practices and learn how to secure your email gateway against BEC attacks.

5 More Vinyl Record Myths We Should Stop Believing Today

Chinese and Russian spies are stepping up cyberattacks on German companies, new survey finds

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia: The Inside Story of Their Downfall
Trending
CyberSecurity6 months agoLeakBase Data Breach Forum Seized in Major Europol Operation
How To5 months agoThe Truth About Fast Charging Apps for Android: Can They Speed Up Your Battery?
CyberSecurity6 months agoZero-Day Attacks Hit Record High as Enterprise Software Becomes Prime Target
CyberSecurity6 months agoRussian Hackers Target WhatsApp and Signal in Global Espionage Campaign
Social Media6 months agoYouTube Live Streaming API: A Developer’s Guide to Managing Live Broadcasts
Infosecurity6 months agoCybersecurity Communication: Why Fear-Based Messaging Fails and What Works
Video4 months agoSamsung One UI 8.5 Official Update Is Here: Release Timeline, Eligible Devices & Key Features
CyberSecurity6 months agoContextCrush Vulnerability: How a Trusted AI Tool Became an Attack Vector



