JatzoOnline Security

← All case studies

CASE STUDY 01 · 5 MINUTE READ

When a convincing email became a parliamentary crisis

Germany's Bundestag, 2015. A targeted intrusion, stolen information and a difficult recovery.

What happened?

In April and May 2015, attackers compromised the German federal parliament's information systems. The EU later reported stolen data, affected parliamentary email accounts, including Angela Merkel's, and disruption lasting several days. This was an attack on parliament; it is not evidence that every German government system was compromised.

The doorway: an email and a malicious link

The reported entry route was familiar: targeted emails containing a malicious link. A recipient following such a link could expose their computer to an infection and give an attacker an initial foothold. One person acting on one convincing email can be enough to put an organisation at risk.

This is spear phishing: a deceptive message tailored to its recipients. In the Bundestag case, the reported email route led into a wider intrusion. Initial access to a computer and access across a network are different stages; the attacker still needs ways to extend that access.

How the incident unfolded

  1. April to May 2015
    Intrusion
    Systems were compromised and information was stolen. The EU's later account places the attack in this period.
  2. June 2015
    Containment was still uncertain
    On 11 June, Bundestag officials said that a recent absence of detected data outflow did not mean the attack was over.
  3. October 2020
    Attribution and sanctions
    The EU sanctioned two individuals and a Russian military-intelligence unit. Its legal decision links the unit to the attack and lists APT28 and Fancy Bear among its industry names.

Why one compromised computer can matter

An independent forensic investigation of the Left parliamentary group's systems found tools that allowed remote commands and tunnelling. With enough privileges, such tools can help an intruder move through a network. The report covered a particular part of the incident; it was not a complete reconstruction of the original email.

For a business, the lesson is that prevention and containment work together. Email checks and staff awareness help at the entry point. Limited account permissions, updated software, protected sign-in and monitoring help reduce what an intruder can do next.

Three actions to remember

  1. Check the request, not just the sender name. If an email unexpectedly asks you to sign in, open a document or provide information, use a known website or contact route to verify it.
  2. Report a suspicious click quickly. Do not wait for visible damage. Tell your IT contact what you opened and when; follow their containment instructions.
  3. Make reporting easy and blame-free. A quick report gives the organisation a chance to investigate. Hiding a mistake can give an attacker more time.

Where Jatzo fits

Jatzo can help explain warning signs in a submitted email, and our courses let you practise safer decisions. We have not tested the original attack email and do not claim Jatzo would have prevented this incident. Email analysis is one safeguard alongside the organisation's wider security controls.

Practise spotting phishing

Sources and editorial notes

Reviewed 8 September 2026. The email-entry account comes from the Swiss MELANI report, which cites contemporary German reporting. It describes targeted emails with a prepared link, but does not establish an exact count of messages or clicks. The one-person example explains the risk, rather than claiming a complete reconstruction of the first infection. Official statements support the impact and attribution. This story does not claim the attack remained completely unnoticed, or that every account was breached.