Germany Germany BSI cybersecurity NIS2 implementation

Germany's Cybersecurity Bill Lets Police Alter Data on Hacked Victims' Own Systems, and the Bundesrat Wants a Judge's Sign-Off First

The Bundesrat's July 10 Stellungnahme demands judicial authorization for BKA hackback powers; Berlin has only partly conceded.

Germany's Hackback Bill, By the Numbers People of Internet Research · Germany 364 New BKA cyber-defense posts The May 2026 draft law also funds … ~€55M Estimated annual cost Yearly cost of staffing the new BK… 38.5% Firms registered under NIS2 Only ~11,500 of an estimated 29,50… peopleofinternet.com
Germany's Hackback Bill, By the Number… People of Internet Research · Germany 364 New BKA cyber-defense po… ~€55M Estimated annual cost 38.5% Firms registered under NIS2 peopleofinternet.com

Key Takeaways

A Bill That Reaches Past the Attacker

On May 27, 2026, Interior Minister Alexander Dobrindt introduced the Gesetz zur Stärkung der Cybersicherheit, a bill amending the BSI Act, the Federal Criminal Police Act (BKA-Gesetz), and the Federal Police Act. Dobrindt framed the shift bluntly: "Wir legen den Schalter um: von der Aufklärung, hin zur Abwehr" — from investigation to defense. The Bundestag held its first reading on June 25, 2026, and referred the bill to the Interior Committee (Bundestag, June 25 2026).

The powers are unusually broad. BKA, Bundespolizei and BSI would be able to block or redirect data traffic and to collect, delete, or modify data on IT systems identified as threats of "international" or security-political significance (Bundestag, June 25 2026). Critically, these powers are not confined to attacker infrastructure. They extend to compromised victim systems — a hijacked home router recruited into a botnet, for instance — allowing authorities to intervene without the system owner's knowledge (netzpolitik.org). BSI separately gains authority to act on mere "Anhaltspunkte" — indications — of an impending attack, including ordering domain registrars to redirect entries.

The Bundesrat Draws a Line

At its 1067th session on July 10, 2026, the Bundesrat adopted a formal Stellungnahme on the government's draft (Drucksache 21/6585). The states asked Berlin to review whether the overall compliance burden on companies is proportionate, to scale fines proportionally, to rule out parallel reporting duties, and to tighten limits on transferring sensitive data. They also pressed for clearer rules under Section 15(6) of the BSI Act governing secure transmission channels (Bundestag hib, kurzmeldungen-1201386).

The sharpest demand concerned judicial oversight. The Bundesrat insisted that BKA interventions in "non-private" IT systems require prior judicial authorization — a Richtervorbehalt — noting that private and commercial use of a given system "often cannot be clearly separated," so a carve-out that skips a judge for anything deemed non-private would swallow the safeguard entirely. The government's Gegenäußerung, published alongside the Stellungnahme as Drucksache 21/7406, rejected most of the Bundesrat's demands as unnecessary, but conceded genuine ambiguity around judicial authority for two specific planned BKA measures and pledged to fix it through amendments during the parliamentary process (Bundestag hib; Drucksache 21/7406).

The Case for the Bill

The government's argument deserves to be stated on its own terms. Ransomware crews and state-linked intrusion sets increasingly route attacks through compromised third-party infrastructure specifically to complicate takedowns and frustrate attribution — waiting for a slow, jurisdiction-by-jurisdiction notice-and-request process while an intrusion is live can mean the difference between containing a breach and losing a hospital's or utility's operational systems entirely. Purely defensive tools — patching, detection, reporting — do nothing to disrupt an attack already in progress on infrastructure Germany doesn't control. If a judge can authorize a wiretap in minutes, the argument goes, a judge should also be able to authorize disabling a command-and-control node before it does more damage.

Why the Bundesrat Is Right to Push Back

The steelman only goes so far, though. The bill's own text acknowledges the compromised-victim-system category, meaning it explicitly authorizes state action against Germans who did nothing wrong — without their knowledge, and without the judicial check the Bundesrat is asking for. Industry group Bitkom has separately flagged the misattribution risk: threat actors routinely leave false trails through third-party infrastructure precisely to redirect retaliation, and a hackback aimed at the wrong node doesn't just fail — it damages an uninvolved party's systems on the state's authority (taz, May 27 2026). AG KRITIS has warned that uncoordinated interventions in critical-infrastructure configuration data risk triggering the very operational disruptions the bill is meant to prevent. And because deletion and modification powers touch the data itself, they can compromise the evidentiary chain needed to prosecute the attacker afterward — undermining the law-enforcement rationale the bill invokes to justify itself.

The fiscal footprint is real, too: the draft funds 364 new BKA positions, 90 at Bundespolizei, and 21 at BSI, at an estimated €55 million a year (taz) — resources critics including Green MP Konstantin von Notz argue would do more for national resilience invested in BSI's defensive and detection capacity than in a rarely-used offensive toolkit.

The Backdrop: A BSI Already Behind

This debate is unfolding while Germany is still catching up on basics. Berlin transposed the EU's NIS2 Directive more than a year late, after the European Commission opened infringement proceedings in November 2024 and issued a reasoned opinion in May 2025; the law only took effect December 6, 2025. When the registration deadline for newly in-scope entities closed on March 6, 2026, just 11,500 of an estimated 29,500 obligated companies — 38.5 percent — had registered with BSI (netguardia.com).

A regulator still onboarding two-thirds of its NIS2 mandate is a reasonable place to add detection and reporting capacity. It is a much harder place to add the authority to alter data on systems belonging to people who never consented to being part of the fight. The Bundesrat's Richtervorbehalt demand is the minimum viable guardrail; the government's partial concession on "two planned measures" suggests it knows this. Parliament should not let the rest of the carve-out survive committee unchanged.

Sources & Citations

  1. Bundestag hib: Bundesrat verlangt Änderungen am Cybersicherheitsgesetz
  2. Bundestag Drucksache 21/7406 (Bundesrat Stellungnahme + Gegenäußerung)
  3. Bundestag: Regierungsentwurf zur Stärkung der Cybersicherheit beraten
  4. netzpolitik.org: Gefährliche Offensive
  5. taz: Don't call it Hackback
  6. netguardia: Germany's NIS2 registration shortfall