Good-Faith Security Researchers Still at Risk of Prosecution in Germany, Court Ruling Shows
Published on 06/14/2026 at 03:54 | Redaktion boerse-global.de
A German IT service provider who discovered a plaintext password and accessed data belonging to roughly 700,000 individuals has been fined €3,000 for unauthorized data access — even though he reported the vulnerability immediately. The Federal Constitutional Court upheld the conviction under Section 202a of the German Criminal Code (StGB), reaffirming that without explicit written authorization from the software vendor, accessing a system remains a criminal offense regardless of intent.
The ruling highlights a persistent legal hazard for cybersecurity researchers in Germany. The new NIS2 implementation law does not create blanket exemptions for such researchers and even permits the forwarding of reports to law enforcement authorities. A promised reform of the so-called "hacker paragraph," included in the coalition agreement, has yet to materialize.
Meanwhile, internal whistleblowing is skyrocketing across Europe. According to the NAVEX 2026 report, European companies averaged 0.85 reports per 100 employees in 2025 — a 60.4% jump from 2022, when the figure stood at 0.53. In North America, the increase was a more moderate 13.4%, but the baseline there is higher at 1.86 reports per 100 employees. Across Europe, 58% of internal reports are submitted anonymously, and the median processing time is 53 days. The data suggests that compliance mechanisms are gaining acceptance but are increasingly straining legal departments.
The surge in internal reporting is also fueling workplace tensions. At Commerzbank, the central works council announced in mid-June 2026 that it would file a criminal complaint against UniCredit on suspicion of market manipulation and misleading behavior. The dispute centers on share purchases that could push UniCredit’s stake in Commerzbank to as high as 37% on a calculated basis. At KölnBäder GmbH, tensions between management and staff representatives have escalated. ver.di is criticizing the suspension of a works council member accused of a working-time violation. Management is seeking dismissal, while the works council refuses consent and accuses the company of union busting.
German courts have also set tight boundaries for employers considering dismissals after internal incidents or public statements. On June 12, 2026, the managing director of the Bremen Jobcenter, Thorsten Spinn, was removed from office. The reason: costs for a so-called creative space ballooned from a planned €99,000 to over €900,000 — without involving the funding bodies. Earlier, an employee had been summarily dismissed for making critical remarks about benefit recipients in a media report.
The Munich Administrative Court (VGH MĂĽnchen) examined the case of a pregnant employee who posted negative comments about customers on a private Facebook account. The court indicated that such remarks could be protected by freedom of speech as long as they do not constitute abusive criticism. During pregnancy, dismissal is permissible only for extremely serious violations. On the other hand, old breaches of duty can still lead to valid dismissal years later. The Frankfurt am Main Regional Labour Court (LAG Frankfurt) upheld the summary dismissal of a technician who had carried out private jobs billed to a client of his employer in 2007. The company only learned of the conduct in 2011, yet the court ruled the dismissal lawful.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
