Germany Approves Postwar Overhaul of Spy Laws, Clearing Agencies to Hack and Sabotage
Germany's cabinet cleared the biggest overhaul of its spy laws since the war, letting the BND and BfV hack foreign systems, sabotage adversaries' supply chains, and feed false information to extremists at home. The domestic-disinformation power is already the most contested piece.
Germany's cabinet has approved legislation that would let the country's intelligence agencies hack foreign systems, sabotage adversaries' supply chains, and feed false information to extremists inside Germany — a package that officials and outside analysts alike describe as the biggest overhaul of the country's spy laws in the postwar era.
The draft rewrites the statutes governing both the BND, Germany's foreign intelligence service, and the BfV, its domestic agency for the protection of the constitutional order, moving them from largely passive intelligence collection toward active, operational capabilities. Cabinet approval is a starting gun rather than a finish line: the bill still has to clear the Bundestag before any of it becomes law. For the first time, German spy services would be authorized to attack computer systems abroad, tamper with physical supply chains, and deliberately mislead domestic extremists — the kind of powers the country's postwar settlement was deliberately built to withhold.
The government, as The Record reported, has framed the changes as a response to a threat environment reshaped by Russia's invasion of Ukraine and a run of sabotage and cyber incidents across Europe. Interior Minister Alexander Dobrindt said the government was “expanding the technical capabilities of the intelligence services and granting them active, operational powers,” adding that the goal was “about being able to take active measures against our attackers and adversaries,” according to a Reuters report.
What the Cabinet Actually Approved
Three capabilities sit at the center of the draft. The first is offensive cyber: operations to disable servers operated abroad by hostile state-sponsored hackers and disinformation networks. The second is supply-chain sabotage — the authority to interfere with an adversary's deliveries, which reporting describes as including the substitution of faulty components into shipments or cyber operations aimed at facilities such as drone factories. The third, and most politically charged, is the power to feed false information to extremists inside Germany.
Officials describe the offensive-cyber authority in defensive terms — the ability to disable the servers of hostile hackers and disinformation operators during a campaign rather than merely to watch them. The supply-chain power is broader still, extending intelligence work into the physical world of shipments and components. The domestic-disinformation piece is narrower on paper but the hardest to bound in practice, because it points the tools of an intelligence service inward, at people on German soil. The draft groups all three under one banner, but they answer to different legal traditions and, as the debate is already showing, to very different political instincts.
The enumeration matters because each capability carries a different risk profile. Hacking foreign infrastructure raises questions of attribution and escalation between states. Supply-chain sabotage blurs the line between intelligence work and physical disruption. And planting false information among people on German soil hands a domestic agency a tool that Germany's postwar institutions were built to keep out of government hands. Read together, the draft is less a single new authority than a bundle of very different ones, each with its own constituency of supporters and critics.
A Postwar Line, Redrawn
The postwar framing is not rhetorical. Germany built its intelligence architecture after 1945 around a deliberate separation between spy agencies and the police, a design meant to prevent the concentration of surveillance and coercive power the country had lived through. Reporting on the draft describes it as pulling the services closer to police-style operational authority, which is why even supporters treat it as a structural shift rather than a routine update. Calling it the biggest overhaul of the spy laws in the postwar era is, on the current reporting, an accurate description of scale rather than hyperbole.
Who Gets the New Powers
The bill covers two agencies by name: the BND and the BfV. Germany's military counterintelligence service, the MAD, is not the focus of the reporting on this draft, and the enumerated capabilities are tied to the foreign and domestic services rather than the armed forces. That distinction is worth holding onto as the text moves through parliament, because the domestic-versus-foreign split is exactly where the legal and constitutional fights tend to concentrate.
Germany has spent the past year publicly naming state-backed threats, from attributing Signal phishing against members of parliament to Russia to warning that China is close to fielding an AI-assisted “superhacker.” The new powers are the government's attempt to answer those threats with something more than statements — and to give its services the standing authority to act before an attack lands rather than only to document it afterward.
The Safeguards on Paper
According to live reporting on the draft — details the original brief flagged as not yet confirmed — active measures could proceed only after Germany's National Security Council declares what the legislation calls a “special intelligence situation,” a trigger that would then require sign-off from two-thirds of the Bundestag's parliamentary oversight panel. Supporters present that two-tier gate as a check that forces cross-party consensus before any operation, and note that the mechanism is written into the draft rather than left to agency discretion.
What the public text does not yet settle is equally important. The timeline for a Bundestag vote is not fixed, the precise legal limits on each capability remain to be tested, and it is not established from the current reporting whether coalition partners will line up behind the bill or how it would interact with the European Union's AI Act if the agencies deploy machine-learning tools. Those are open questions rather than settled facts, and they are where the working scope of the law will ultimately be decided.
The Civil-Liberties Objections
Critics have moved quickly. Reporters Without Borders warned that the hacking authorities could reach journalists and media organizations, which it argues would endanger source protection and press freedom. The domestic-disinformation provision has drawn the sharpest objections: letting an internal security service deliberately plant false information among people inside the country is, for civil-liberties groups, a categorically different thing from spying on a foreign adversary, and one they say invites abuse and erodes public trust.
Supporters counter that the intended target is a narrow set of violent extremists, that any operation would run through the declared-situation and oversight-panel gates, and that democracies facing organized sabotage cannot leave their services purely reactive. Both positions are now on the table; which one the final statute reflects depends on what survives the parliamentary process.
My read: The offensive-cyber and supply-chain pieces are the headline, but the domestic-disinformation power is the provision most likely to reshape the bill — or sink parts of it — as it moves through the Bundestag. Germany's constitutional court has a long record of narrowing intelligence powers that touch people at home, and a domestic agency authorized to spread falsehoods sits close to the center of what that jurisprudence tends to scrutinize. I would expect the foreign-facing capabilities to survive in some form and the domestic provision to be the one that gets rewritten, fenced with conditions, or challenged in Karlsruhe. Cabinet approval signals intent; it does not tell you what the enacted law will permit.
Why It Lands on Security Teams
For enterprises that operate in or with Germany, the practical signal is about governance and awareness rather than any immediate change to defenses. If a national service gains standing authority to sabotage supply chains and run offensive operations, that becomes one more input into vendor-risk and dual-use-tooling decisions — particularly for companies whose hardware, logistics, or software sit near flows an intelligence service might one day touch. It also fits a broader pattern: the same argument over state-sanctioned offensive action is playing out elsewhere, including in the United States, where the government has moved toward authorizing private firms to hack back against cybercriminals. Watching how democracies draw the legal boundaries around offensive cyber is becoming part of the risk picture, not a side story to it.
None of that means teams should act on capabilities that are not yet law. The useful posture is to track the bill's progress through the Bundestag, note which agencies end up holding which powers, and watch the safeguards closely — because the gap between what a cabinet approves and what a legislature enacts is where the real scope of these authorities gets set.