Summary
- The heads of Germany’s three federal intelligence services appeared before the Bundestag on 5 October.
- All three identified Russia as the country’s most serious current security challenge.
- Officials described a broader hybrid threat spanning cyber operations, espionage, sabotage and pressure against European institutions.
Germany’s intelligence chiefs have described Russia as the country’s most serious current security challenge, warning that hostile activity against Germany and Europe has moved beyond scenarios previously treated as longer-term risks.
Martin Jäger, president of the Federal Intelligence Service, appeared alongside domestic intelligence chief Sinan Selen and military counterintelligence president Martina Rosenberg before the Bundestag’s Parliamentary Oversight Panel on 5 October.
All three placed Russia at the centre of their current security assessment, while describing an environment in which cyber operations sit alongside espionage, sabotage, influence activity, drone incidents and other forms of pressure.
Jäger told lawmakers that the deterioration in the security environment predicted during 2025 had fully materialised, with Russia escalating its war in Ukraine while increasing pressure on Europe and Germany. He also warned that the possibility of more direct confrontation could not be treated solely as a distant military scenario.
Selen said threats sometimes associated with a possible future conflict were already visible in the intelligence environment. Recent activity across Europe has included suspected sabotage, interference with navigation systems, reconnaissance and cyber operations, although responsibility for individual incidents still depends on the evidence available in each case.
Grouping those events under a hybrid threat model does not make every hostile action a cybersecurity incident. Intelligence services use the category to describe combinations of tools that can support the same strategic objective while operating through very different mechanisms.
A cyber intrusion might provide access to sensitive information or infrastructure, for example, while physical sabotage or influence activity can create pressure without requiring access to a computer system at all. Keeping those methods distinct remains important because attribution, defensive responsibility and legal authority differ between them.
Germany has spent much of 2026 examining how its institutions should respond to the overlap. Proposed legislation has sought to expand cyber defence and intelligence capabilities while lawmakers debate which agencies should hold intrusive powers and what oversight should apply.
The public intelligence hearing took place on the same day that the Bundestag Interior Committee examined separate legislation intended to strengthen Germany’s cyber defence. Although the proceedings concerned different powers, both reflect growing pressure on the government to respond more quickly to activity that can cross intelligence, criminal, military and cybersecurity boundaries.
Attribution makes that coordination harder because hostile cyber operations can use compromised infrastructure in multiple countries, while sabotage or influence networks may rely on intermediaries whose relationship with a state is deliberately obscured.
Public intelligence assessments consequently combine technical findings with classified reporting and wider behavioural analysis. The intelligence chiefs did not disclose the underlying evidence behind every attribution or security assessment during the public hearing.
Germany and other European governments have nevertheless repeatedly linked cyber operations and wider hostile activity to Russian state organisations and associated actors. Moscow has denied Western allegations that it is conducting hybrid attacks across Europe.
For organisations responsible for critical services or strategically important information, the threat model extends beyond financially motivated compromise. Intelligence collection, disruption and access retained for possible future use can all produce different attacker behaviour from ransomware or ordinary criminal fraud.
That difference affects detection because an espionage operation may prioritise persistence and secrecy over immediate impact. Infrastructure can remain valuable even when the attacker does not cause visible disruption during the initial compromise.
The 5 October hearing did not announce a single new cyber incident or provide attribution for every recent disruption affecting Europe. Instead, it placed those events inside the intelligence services’ broader assessment that hostile Russian pressure has intensified and is likely to remain a sustained security problem.
The Parliamentary Oversight Panel is responsible for scrutinising Germany’s federal intelligence services, giving lawmakers a continuing role as the government considers how wider powers should respond to that environment.





