In the quiet corridors of German industry, a shadow has shifted its gaze — from the halls of government to the laboratories and server rooms of private enterprise. Germany's domestic intelligence agency has warned that APT 27, a Chinese hacker group long associated with state interests, is now targeting pharmaceutical and technology firms for their trade secrets and intellectual property. The move signals not merely a tactical adjustment, but a deeper contest over the knowledge that will shape the economies of tomorrow.
Chinese hackers target German pharma and tech firms, BfV warns
Hackers may use compromised firms as entry points to infiltrate multiple organizations
So the BfV is saying this group APT 27 has switched from targeting governments to going after private companies. Why would they do that?
Governments are harder targets—they have dedicated security teams, air-gapped networks, the works. Private companies, especially in pharma and tech, have valuable intellectual property but often less mature security infrastructure. It's a shift toward easier, more profitable targets.
But we should be careful here. The BfV says APT 27 "may be trying" to use this cascading approach through customer networks. That's an assessment, not confirmed activity. We don't know how many companies have actually been breached or what was taken.
The circular went to companies—so did they give specific indicators of compromise, or was it more of a general warning?
The source material doesn't specify what technical details were in the circular. It just says the BfV warned companies about the threat. That's a gap in what we know.
Right. And the connection between APT 27 and the Chinese state—that's "believed to" and "suspected of." It's not formally attributed by Germany. The US and allies made accusations last year, but China denied them. So we're reporting on a warning about a group with suspected ties, not confirmed state sponsorship.
Does the timing matter? Why now?
The warning comes as US-China tensions over cyberespionage are high. Whether the BfV's disclosure is a response to new activity or a delayed public warning about ongoing operations isn't clear from what we have.
Exactly. We know the warning happened on Wednesday. We don't know if this is a new campaign or something the BfV has been tracking for months.
O Pulso
- Germany's BfV intelligence agency has sounded the alarm: APT 27, also known as 'Emissary Panda,' has pivoted from targeting Western governments to actively hunting German pharma and tech companies.
- The hackers are not simply raiding single targets — they are using compromised firms as bridges into customer and service provider networks, turning one breach into many.
- This cascading infiltration strategy dramatically multiplies the potential damage, threatening entire supply chains and business ecosystems rather than isolated organizations.
- The warning lands against a charged backdrop: the US and allied nations formally accused China of global cyberespionage last year, accusations Beijing continues to deny.
- Germany now finds itself at the center of an escalating contest over economic intelligence, with its most strategically vital industries squarely in the crosshairs.
In the quiet corridors of German industry, a shadow has shifted its gaze — from the halls of government to the laboratories and server rooms of private enterprise. Germany's domestic intelligence agency has warned that APT 27, a Chinese hacker group long associated with state interests, is now targeting pharmaceutical and technology firms for their trade secrets and intellectual property. The move signals not merely a tactical adjustment, but a deeper contest over the knowledge that will shape the economies of tomorrow.
Germany's Federal Office for the Protection of the Constitution issued a stark warning this week: the Chinese hacker group APT 27 has turned its attention toward German pharmaceutical and technology companies, seeking to extract trade secrets and intellectual property. The alert was distributed directly to businesses across the country.
What distinguishes this campaign from past activity is a significant shift in targeting. APT 27, long associated with attacks on Western government agencies, now appears to be pivoting toward private industry — a sign that economic espionage may be taking precedence over traditional intelligence gathering. The BfV had previously documented the group's operations in its 2019 constitutional protection report, where it was linked to attacks on embassies and critical infrastructure.
Perhaps most alarming is the group's reported methodology: rather than extracting data from a single victim and moving on, the hackers appear to be using compromised companies as entry points into broader networks of customers and service providers. A single successful intrusion could ripple outward, granting access to dozens of connected organizations.
The disclosure arrives as international pressure over Chinese cyberespionage continues to mount. Last year, the United States and its allies formally attributed a sweeping global hacking campaign to China — accusations Beijing has firmly rejected. Germany's warning adds fresh weight to a growing body of evidence that state-linked Chinese actors are systematically pursuing sensitive knowledge from Western institutions and industries.
Germany's domestic intelligence agency issued a warning on Wednesday that a Chinese hacker group known as APT 27 has begun targeting German companies in pharmaceuticals and technology sectors. The Federal Office for the Protection of the Constitution, or BfV, disclosed the campaign in a circular distributed to businesses across the country.
APT 27 has long been suspected of orchestrating cyberattacks against Western government agencies, but this marks a notable shift in targeting strategy. The group, also identified by the alias "Emissary Panda," appears to be pivoting toward private industry, focusing on stealing trade secrets and intellectual property from German firms. The BfV flagged the threat as part of its ongoing monitoring of foreign intelligence operations on German soil.
What makes this campaign particularly concerning, according to the intelligence agency, is the group's apparent strategy of using compromised companies as stepping stones. Rather than simply extracting data from a single target, the hackers may be attempting to breach customer networks and service provider relationships, creating a cascading effect that could allow them to infiltrate multiple organizations through a single initial compromise. This approach multiplies the potential damage and extends the reach of any single successful intrusion.
The BfV had previously documented APT 27's activities in its 2019 constitutional protection report, noting the group's history of targeting foreign embassies and critical infrastructure sectors. The shift toward German pharmaceutical and technology companies suggests either an expansion of the group's operational scope or a deliberate reorientation of resources toward economic espionage in strategically important industries.
The warning arrives amid broader international tensions over Chinese cyberespionage. Last year, the United States and allied nations formally accused China of conducting a sweeping global hacking campaign targeting government and private sector targets worldwide. China has rejected these accusations, denying involvement in coordinated cyberattacks. The BfV's disclosure of APT 27's activity in Germany adds another data point to the growing body of evidence that Chinese state-linked hacking groups are actively pursuing sensitive information from Western companies and institutions.
Citações Notáveis
The hackers may be trying to penetrate customers' and service providers' networks to infiltrate several companies at once— Germany's Federal Office for the Protection of the Constitution (BfV)