German East European studies association breached again, Russia suspected

Organization
German Association for East European Studies (DGO)
Exploit
Hacking
Industry
Non-profit Research

The German Association for East European Studies, known by its German initials DGO, said it was the target of a cyberattack at the end of March 2025. The Berlin-based body is Germany's largest research and policy network focused on Eastern Europe and Russia, and it advises government bodies and civil society organizations on the region.

The intruders reached the association's mail server and took a large volume of messages, according to the DGO, which described the operation as highly professional. It was the second such incident in roughly six months. An earlier compromise in October 2024, also suspected of having Russian origins, had prompted the association to strengthen its defenses, and the DGO said the March intrusion circumvented those improvements.

German security agencies did not publicly attribute the attack, though the DGO said the origin was Russian. Reporting indicated that intelligence officials suspected APT29, the group also tracked as Cozy Bear and linked to Russia's Foreign Intelligence Service. The association said the incident confirmed intelligence assessments that institutions like it sit in the crosshairs of Russian hybrid operations aimed at influencing democratic debate in Germany.

The DGO coordinated its response with the Federal Foreign Office, German intelligence services and federal security agencies. Lawmakers condemned the intrusion as part of a broader campaign against European democratic institutions. Germany's domestic intelligence service, the BfV, had warned of escalating Russian espionage and disinformation activity directed at the country.

Sources