China read a ministry’s e-mail for two years, and that is not all. The BIS annual report for 2025
China read a ministry’s e-mail for two years, and that is not all. The BIS annual report for 2025

Today we are not going to dissect a single vulnerability but a whole year through the eyes of Czech counter-intelligence. And because BIS does not work with cyber incident figures in its report, we will supplement it with two other documents: NÚKIB’s report for the Czech Republic and the National Security Authority’s report for Slovakia.
Why should this matter to you as a manager or security professional? Because in the report BIS names the specific types of companies that are in the crosshairs: suppliers of aid to Ukraine, logistics, technology companies, engineering, and even the smallest industrial operations. A boiler room, a pump, a small hydropower plant.
BIS describes an interesting trend. In the first half of 2025, the number of detected sabotage operations coordinated from Russia fell. From the second half of the year, it has been rising again.
And who carries out these sabotage operations? BIS uses the term “disposable agent”. Typically an amateur, often with a criminal record, motivated by money. And when they get caught, Russia disowns them. Hence disposable.
Interestingly, the agent does not receive a plan. First they report to their handler which targets in their area they can reach. Only then do the instructions arrive.
What does that mean for you? That your infrastructure is not a strategic target. It is a target of opportunity. What matters is not how important you are. What matters is who can get to you. A temp worker, an agency employee, a driver.
The agents are also tasked with photographing and filming the attack. That footage feeds propaganda with a simple message: Europe is burning. And the aim of the whole campaign is to convince the public that supporting Ukraine does not pay.
Adverts offering rewards for sabotage circulate on Telegram. BIS speaks of hundreds of thousands of posts a year. But note: the attacks mostly target Ukraine and other EU countries. And for no incident investigated in the Czech Republic in 2025 was Russian coordination reliably confirmed.
Now to cyberspace. BIS writes that Russian state actors were active in the Czech Republic in 2025 as well, and that attacks on Czech companies were usually part of broader campaigns.
Russian actors use Czech internet infrastructure to attack targets outside the Czech Republic. That means your unsecured server, router or camera may be a proxy for an attack on someone else. You are not the target, you are the tool.
BIS also contributed to a joint NSA advisory from May 2025. The advisory concerns the unit known as APT28, which for more than two years targeted logistics and technology companies involved in aid to Ukraine. Password spraying, spearphishing, manipulation of permissions in Exchange mailboxes. And mass compromise of IP cameras in Ukraine and NATO countries.
Then there are the hacktivists. BIS is clear on this. They are not independent collectives. Their DDoS attacks are trivial, but something new has appeared: attacks on small, poorly secured technical operations. The attacker gets into the control system and changes the parameters of a pump or a boiler.
In the Czech Republic, this ended in an automatic safety shutdown. Abroad, it has also caused equipment damage. In December, NÚKIB added that the attackers are getting in through weakly secured VNC.
And now the figures from NÚKIB.
203 incidents, 65 fewer than the year before. The decline is driven mainly by hacktivist DDoS attacks, which fell year-on-year to less than half, thanks among other things to Operation Eastwood, in which Europol and partners including the Czech Republic dismantled the infrastructure of the NoName057(16) group in July.
NÚKIB also warns that APT28 is spreading spyware across Europe via Signal and WhatsApp. It has not yet been observed in the Czech Republic, but NÚKIB puts the future likelihood at 25–50%.
28 May 2025. For the first time in its history, the Czech Republic publicly attributed a cyberattack on a state institution to a specific state.
The APT31 group, associated with China’s Ministry of State Security, operated inside the Foreign Ministry’s systems from at least 2022 until July 2024.
The government named the People’s Republic of China as responsible, and NÚKIB states in its report that APT31 is behind the attack with 75–80% probability.
For two years, someone had access to the Foreign Ministry’s e-mail. Translate that into a corporate environment and the sentence “we have no incidents” may actually mean “we have no detection”.
But China does not operate only in cyberspace. BIS describes Chinese intelligence officers working in the Czech Republic mainly under journalistic and diplomatic cover.
In the cyber chapter, BIS did something unusual. It included a checklist for small industrial operations with remote access.
It recommends things that should be a matter of course and that I keep repeating too. Change the manufacturer’s default password. Use unique, complex passwords. Deploy two-factor authentication on all accounts. Use a VPN and close unused ports. Deploy IP whitelisting. Run remote administration accounts with the lowest possible privileges. Update firmware regularly. Check for vulnerabilities regularly. And replace whatever the manufacturer no longer supports.
NÚKIB adds an interesting statistic. Nine out of ten organisations have encountered phishing, and more than a third do not test their people at all. Attackers do come in through vulnerable systems, but the initial vector is very often people.
And now to Slovakia.
In July, the National Security Authority published its report for 2025, in which it mentions two major security incidents.
The outage of the land registry systems, after which other state institutions began checking what they have exposed to the internet, through penetration tests and audits of connected devices. Reactively, only after the incident.
And then Jaguar Land Rover, where in the third quarter of 2025 a targeted attack halted production in several countries. The Nitra plant disconnected its local systems and did not return to full operation until October.
And two more figures from the NBÚ. Only four in ten Slovaks know the term ransomware. And the most common finding from inspections? Missing supplier risk analysis and the absence of security monitoring.
What to take away from this? There are fewer cyber incidents in the Czech Republic, but more serious ones. Attacks on operational technology are the new normal. And two years of undetected access to a system is a lesson for every company, not just a ministry.
Berlin refuses to pay ransom to ransomware gang
Berlin has confirmed that it is being extorted following the compromise of its administrative network, Landesnetz Berlin, and has declared that it will not meet the attackers’ demands.
After an extraordinary session of the Senate on Friday 28 August, Governing Mayor Kai Wegner said the state had become the victim of a serious crime and was being blackmailed. Together with Interior Senator Iris Spranger, he ruled out Berlin giving in to the demands.
Forensic analysis uncovered a further data leak from the Senate Department for Mobility, Transport, Climate Protection and the Environment, dated between 7 and 12 August 2026. According to the Senate, the content and volume of the affected data are still being examined, and it cannot be ruled out that they include personal or other non-public data.
Attribution so far rests solely on the attackers’ own claims. Der Spiegel was the first to name the Rhysida group on 28 August, citing an entry on the group’s website. The Hacker News subsequently confirmed via a monitoring service that an entry titled “Berlin, Germany” appeared on Rhysida’s site the same day. The post claims the attackers obtained 5.79 terabytes of data and roughly 1.44 million files, including the personal data of 12,076 individuals.
The monitoring service cited by The Hacker News recorded 280 Rhysida victims as of 29 August, nine of them in Germany, including the Stuttgart city administration in May 2026 and the humanitarian organisation Welthungerhilfe in June 2025.
HOOKEDGE backdoor linked to APT28 targets European diplomats via Word macros
On Thursday 27 August, Recorded Future’s Insikt Group published an analysis of a series of initial-access campaigns that ran from late September 2025 to early April 2026 against government and diplomatic organisations and defence industry companies in Romania, Spain and Turkey.
The campaigns delivered a previously undocumented backdoor named HOOKEDGE, a lightweight implant in the form of a Windows batch script, distributed via macro-enabled Microsoft Word documents.
Insikt Group attributes the activity with medium confidence to BlueDelta, the name Recorded Future uses for the group linked to Russia’s military intelligence service, the GRU, better known as APT28, Fancy Bear or Forest Blizzard.
The assessment is based on significant code and tradecraft overlaps between HOOKEDGE and the HEADLACE backdoor, a batch-script implant Recorded Future documented for BlueDelta in 2023, as well as matching infrastructure patterns and target selection consistent with the known priorities of Russian intelligence services.
Infection is fairly simple — the recipient only has to click “Enable Content”.
Alleged TeamPCP members charged in Australia over Trivy, KICS and LiteLLM supply chain attacks
On 26 August, the Australian Federal Police (AFP), working with the Western Australia Police Force (WAPF) and in a parallel investigation with the US FBI, charged two men from Western Australia with a total of 14 offences over their alleged role in the TeamPCP group, the group behind this year’s compromise of the open-source security scanner Trivy, Checkmarx KICS and the LiteLLM AI gateway.
Police allege both men were core participants in the group and received cryptocurrency payments for their roles. Thomson, a 21-year-old from Cottesloe, faces eight charges, including four counts of unauthorised modification of data with intent to commit a serious offence, one of dealing with proceeds of crime worth at least AUD 100,000, and one of refusing to provide access to seized devices.
Gaebler, a 23-year-old from Mandurah, faces six related charges.
At the first hearing, the magistrate indicated she would not release Thomson on bail because of the risk of evidence tampering. Gaebler remains in custody until the next hearing, scheduled for 18 September. Police say they have already extracted around 100 terabytes of data from devices seized at one of the addresses.