⏳ Curating articles…
Technology 3 min read 2h ago · Updated August 25, 2026 at 03:42 UTC

German Ethical Hackers Face Legal Risk

  • Germany's Gesellschaft für Informatik has published a white paper demanding legal protection for ethical hackers who responsibly disclose software vulnerabilities.
  • Paragraphs 202a–202c of the German Criminal Code, in force since 2007, criminalise security research tools and fail to distinguish malicious intent from legitimate white-hat work.
  • The GI calls for intent-to-harm as a statutory requirement, coordinated disclosure safe harbours, and reforms to copyright and trade-secrets law, citing Poland, Belgium, and
German Ethical Hackers Face Legal Risk
German Ethical Hackers Face Legal Risk

Security researchers who discover and responsibly report software vulnerabilities in Germany continue to risk criminal prosecution, and the country's leading computer science body is demanding that the federal government act to end the impasse. The Gesellschaft für Informatik (GI), alongside partners from industry, cybersecurity research, and digital-policy non-governmental organisations, has published a white paper calling for a comprehensive overhaul of German computer criminal law.

The law that criminalises the tools of the trade

At the centre of the dispute are paragraphs 202a to 202c of the Criminal Code — collectively known as the Hackerparagrafen — in force since 2007. Paragraph 202c is identified as especially problematic: it criminalises the mere provision and use of software tools that are, according to the white paper's authors, indispensable for legitimate security analysis. The analysis argues the legislation fails to draw an adequate distinction between malicious criminal intent and the work of so-called white-hat hackers who act in the public interest. The case involving the software Modern Solutions is cited as a prominent illustration of the consequences: a researcher who uncovered and reported a vulnerability found himself facing charges rather than recognition.

This legal uncertainty produces what the GI describes as a chilling effect. Valuable security disclosures go unreported, or must be routed through anonymous intermediaries at considerable cost and inconvenience — a dynamic that ultimately leaves digital infrastructure less secure. As incidents involving AI agents breaching research environments and persistent AI-enabled cyber threats demonstrate, the risks posed by unpatched vulnerabilities are growing rather than diminishing.

Advertisement
Ad Unit · 728×90 / Responsive

What the white paper proposes

The GI argues that a narrow amendment to criminal law is insufficient. It calls for a holistic reform that would make demonstrable intent to cause harm an explicit element of any offence, and would shield researchers who report vulnerabilities in good faith to manufacturers or competent authorities. Adjacent areas of law — including copyright provisions, trade-secrets legislation, and data-protection rules — would also need to be amended so that common research methods such as decompiling code or examining unencrypted wireless transmissions are no longer treated as unlawful. The paper points to Poland, Belgium, and Portugal as countries that have already established workable legal frameworks for ethical hacking without undermining the prosecution of genuine cybercrime.

Building a reporting culture

Beyond legislative change, the GI calls on companies and public authorities to view the independent discovery of security flaws as a cost-free contribution to their own resilience, rather than grounds for a criminal complaint. Standardised processes — including the publication of a security.txt contact file and functioning coordinated vulnerability disclosure (CVD) procedures — are presented as practical first steps. The paper also endorses public recognition schemes, such as halls of fame maintained by bodies including the Federal Office for Information Security (BSI), and state-backed bug-bounty programmes as means of raising the professional standing of security researchers.

With new European regulations including the Cyber Resilience Act approaching implementation, the GI is urging the federal government to honour commitments made in its coalition agreement and launch a reform process that involves all relevant stakeholders without further delay.

Advertisement
Ad Unit · 300×250 / Responsive

More in Technology

Read in another language

← Home