Germany cyberattack: The five most likely culprits

Published January 4, 2019 7:51pm ET



Such an astonishingly broad hack of hundreds of German officials and celebrities would normally indicate a state actor with significant technical capability. But the fact that the contacts and messages of those targeted were not held by German government servers means that we cannot take state actor involvement for granted. As I see it, considering capability and intent, five possible culprits stand out as most likely here. Note that, as of 18 hours since the publication of the attack, the five-eye alliance of Western intelligence services has not yet identified a culprit.

Let’s start with China. Through various organs of China’s Ministry of State Security and the People’s Liberation armed forces, China retains an exceptional cyberwarfare capability. Broad in reach, and possessing of boutique instruments that would normally only be expected with the world leaders in cyber-strike, the U.S. National Security Agency and Britain’s GCHQ, China is certainly capable of this attack. But why would Beijing choose this course of action? That’s much harder to answer. One possibility, however, is Germany’s growing frustration with those same concerns that motivate America’s present anger toward China: namely, its legal and illegal usurpation of intellectual property and its capricous disdain for global trade rules. This could be a Chinese warning shot off Berlin’s bow in the assessment that Germany is unlikely to retaliate. My likelihood rating of Chinese culpability: fifth most likely.

Trusted reporting.Unlimited access.

Subscribe for full access to Washington Examiner coverage, expert political analysis, and subscriber-only journalism.

Get Unlimited Access

Already a member? Log in

Cancel anytime.