The Federal Office for Information Security (BSI) said in its latest situation report that cyber espionage groups were specifically targeting German public administration. The agency also reported a rise in phishing attacks, including a growing number of cases involving manipulated QR codes, known as quishing.

Public Administration Is the Main Target

According to the BSI report, cyber espionage groups are primarily interested in data held by public administration. Defense, justice and public security agencies were also affected, the report said.

Germany was the fourth most frequently targeted country worldwide by so-called APT groups (Advanced Persistent Threat), according to the report. Only the United States, India and Japan were more affected.

The Threat Situation in Numbers

4th Place

Germany is the fourth most frequent target of APT attacks worldwide, according to the BSI

€202 Billion

Damage to the German economy from cyberattacks within one year

Three Phishing Methods on the Rise

Alongside cyber espionage, the BSI described three phishing methods that it said were spreading:

1. Brand Impersonation

The number of fake websites posing as well-known online retailers rose sharply in the first half of 2025, according to the BSI. Criminals exploit trust in established brands to obtain payment details and personal information.

Affected: online shoppers directed to fake shop pages

2. Quishing (QR Code Phishing)

Manipulated QR codes are increasingly being placed in public spaces, the BSI said – on parking meters, charging stations, in official letters or as stickers on public transport. Scanning the codes leads to fake phishing websites.

Particularly at risk: drivers, users of public infrastructure, recipients of government mail

3. Vishing (Voice Phishing)

Vishing cases also rose, according to the report. Criminals pose as IT support staff on the phone to gain access to networks. Government agencies and companies whose employees were deceived by supposed support calls were frequently affected.

Target: employees of authorities and companies who give away access data on the phone

Almost 10,500 Citizen Inquiries – Phishing Reported Most Often

The BSI service center received nearly 10,500 inquiries from citizens within one year, the agency said. Almost half of them concerned specific cybersecurity incidents.

The most frequently reported incidents:

  • 1.Phishing attacks (emails, SMS, fake websites)
  • 2.Account abuse (stolen credentials)
  • 3.Identity theft (fake profiles, fraud in the victim's name)

Limits of Existing Protective Measures

Security experts say reactive measures such as awareness campaigns or removing manipulated QR code stickers often fall short.

Manipulated Codes Are Hard to Detect

Fake QR codes cannot be distinguished from genuine ones with the naked eye. Even trained employees often fail to recognize professional forgeries.

Delay Until Takedown

By the time a phishing page is reported and blocked, victims may already have entered their data.

No Shared Threat Database

Authorities rely on different systems without a common threat database. Municipalities generally handle cases individually.

Reaction Instead of Prevention

Existing systems usually act only after an incident. Checks before a page is first opened are often missing.

QRTrust: A Technical Approach to Checking QR Codes

Product note: QRTrust is verification software that analyzes the destination URL of a QR code before it is opened. The service is aimed at authorities, companies and private users.

How the Service Works:

6-Layer Security Check

Every QR code is checked in real time against Google Safe Browsing, a local threat database and AI models.

Redirect Tracking

The software follows up to 5 redirects and analyzes the final destination page, including nested URLs.

Real-Time Warning

Before a page classified as suspicious is opened, the app displays a warning with threat level and details.

Municipal Whitelisting

Authorities can have their official QR codes certified. Verified codes are marked with a green checkmark in the app.

Monitoring Dashboard for Authorities

Administrations receive an overview of suspicious scan patterns and automatic notices in case of manipulation.

Use Cases in Public Administration

For authorities, the service includes the following functions:

Checking Incoming QR Codes

Incoming QR codes, for example in official mail or emails, can be checked before scanning.

Verification App for Citizens

Municipalities can use the app as a verification tool for municipal QR codes, for example on parking meters or in government mail. Users receive feedback on the code's authenticity.

Incident Documentation

Detected phishing attempts are documented with screenshots, timestamps and URL history. The data can be used for investigations and prosecution.

Example Scenario: Fake QR Code in Official Mail

An illustrative example: A city administration employee receives a letter asking them to scan a QR code – supposedly for an 'important security update'.

Sequence without verification software:

  1. The employee scans the QR code with a standard camera app
  2. They land on a fake IT support page
  3. They enter credentials for the government network
  4. The attackers gain access to administration data

Sequence with QRTrust:

  1. The employee scans the QR code with the QRTrust app
  2. The software determines that the URL is not on the authority whitelist
  3. A notice appears: 'This URL is not registered as an official government channel'
  4. The page is not opened; the incident can be documented and reported to IT security

Context

The BSI report 2025 describes a persistently high threat level. Public administration is among the main targets, and methods such as quishing and vishing are on the rise, according to the report.

The BSI advises against scanning QR codes from unknown sources without verification and recommends checking the destination address before opening it. Suspicious incidents can be reported to the police or the BSI.

QRTrust for Public Authorities

QRTrust checks the destination URLs of QR codes against several threat databases. The provider offers a free initial consultation for public institutions.

Schedule Consultation

Sources

This article is based on the current BSI report on IT security and press reports: