Hesse’s Interior Minister Roman Poseck and LfV President Bernd Neumann present the organisational restructuring of the State Office for the Protection of the Constitution. ©LfV Hessen
Germany’s financial and logistics hub responds to growing hybrid threats with dedicated structures for counter-espionage, operational intelligence and the protection of business, research and public authorities
Cyberattacks, sabotage, drone incidents, disinformation campaigns and traditional espionage can no longer be treated as separate security phenomena. Modern hostile operations frequently combine digital intrusion, physical reconnaissance, political influence and covert intelligence activity. Their perpetrators may be state agencies, state-backed groups or non-state actors whose involvement is deliberately concealed.
The State Office for the Protection of the Constitution in Hesse, known as the LfV Hessen, is responding with a comprehensive organisational restructuring. A dedicated division will focus exclusively on counter-espionage, hybrid threats, foreign influence operations and transnational repression. A second division will consolidate operational intelligence capabilities, while the existing economic protection unit will be expanded into a competence centre serving businesses, research institutions and public authorities.
Hesse’s Interior Minister Roman Poseck and LfV President Bernd Neumann presented the new structure in Wiesbaden. According to the state government, the model is currently unique in Germany because both counter-espionage and operational intelligence will be organised as independent, specialised divisions.
A strategically important target
From an intelligence perspective, Hesse is of exceptional strategic importance. Frankfurt is one of Europe’s leading financial centres and is home to a major international airport, critical transport and logistics networks, military facilities and one of the world’s largest internet exchange points. This concentration of infrastructure, capital, technology and international connectivity makes the state an attractive target for espionage, sabotage and influence operations.
Poseck pointed in particular to activities associated with foreign intelligence services and state-controlled or state-supported groups. Since the beginning of Russia’s war against Ukraine, the number of cases with a suspected Russian connection handled by the authority has more than doubled, at one stage exceeding 2,000 cases.
China- and Iran-related activity is also placing increasing pressure on counter-intelligence resources. For 2026, the LfV expects the number of suspected cases with links to Iran to rise by more than 45 per cent to approximately 800. According to the Interior Ministry, the first quarter of the year also brought a notable increase in suspected reconnaissance and sabotage activity, including incidents involving drones.
These figures illustrate how far modern counter-espionage has moved beyond the observation of traditional agents. Contemporary operations may combine cyber intrusion, physical surveillance, attempted recruitment, influence activities, preparations for sabotage and the use of unmanned systems.
Hybrid activity below the threshold of war
Hybrid threats often operate in the grey zone between open conflict and domestic security. Their objective is not always to cause immediate and clearly visible damage. They may instead seek to create uncertainty, undermine trust in public institutions, intensify social divisions or repeatedly disrupt essential services.
The methods involved range from cyberattacks on public authorities and companies to disinformation campaigns and acts of sabotage against energy, transport and communications infrastructure. Drones may be used for reconnaissance, disruption or attacks.
Poseck referred in this context to a suspected attack scenario at Leipzig Airport involving a drone reportedly equipped with explosives. Important details of the incident remain unresolved. Nevertheless, the case demonstrates from the Interior Ministry’s perspective that the potential severity of drone-related threats is changing.
For security authorities, this creates a significant analytical and operational challenge. Digital indicators, physical observations and intelligence reporting must be combined and assessed more quickly. An isolated cyber incident, drone sighting or suspicious contact may initially appear inconclusive. Only by linking different pieces of information can a coordinated hostile operation become visible.
The restructuring of the LfV is intended to improve precisely this form of cross-domain analysis.
Dedicated division for espionage and foreign influence
The new counter-espionage division will consolidate responsibilities that were previously distributed across several organisational units. Alongside traditional counter-intelligence, its remit will include hybrid threats, foreign state influence and transnational repression.
Transnational repression refers to measures used by foreign governments to monitor, intimidate or pressure political opponents, critics or particular communities beyond their own national borders. Such activities may range from digital surveillance and threats to physical observation and targeted intelligence collection.
By bringing these areas together, the LfV aims to improve professional cooperation and accelerate the assessment of complex cases. This is particularly important where individual incidents do not initially reveal their wider significance. A suspicious contact, an attempted cyber intrusion and a drone flight may appear unrelated when viewed separately. Together, they may indicate reconnaissance, preparation for sabotage or a broader influence operation.
The effectiveness of the new division will therefore depend not only on the volume of information available, but on the authority’s ability to identify connections quickly and convert intelligence assessments into appropriate protective measures.
Operational capabilities brought under central control
A second new division will assume responsibility for operational intelligence. It will consolidate intelligence measures that were previously organised within different parts of the authority.
These measures include the observation of extremist targets and surveillance conducted under Germany’s Article 10 Act, commonly known as the G10 Act. The legislation permits interference with the privacy of correspondence, post and telecommunications only under narrowly defined legal conditions.
By centralising operational resources, the LfV intends to shorten coordination processes, accelerate decisions and deploy personnel and technical capabilities more flexibly.
Neumann noted that the authority’s last major reorganisation took place approximately ten years ago. Since then, both the geopolitical environment and the technical means available to hostile actors have changed fundamentally. The new structure is therefore designed to bring specialist analysis and operational capabilities into closer alignment.
This integration is especially important in hybrid cases. Analytical units may identify a possible threat pattern, but operational teams must be able to verify suspicions, collect evidence and observe relevant individuals or networks. Delays between analysis and operational action can allow hostile actors to change methods, destroy evidence or complete preparatory activities.
Greater protection for business and research
Another major element of the restructuring is the expansion of preventive security support. The existing economic protection unit will become a competence centre for business, science and public-authority protection.
The change reflects the fact that foreign intelligence services do not focus exclusively on government institutions and traditional critical infrastructure. Innovative companies, universities, research institutes and technology providers may also possess information of considerable strategic value.
Particularly exposed sectors include those working with dual-use technologies, sensitive research data, advanced industrial systems, military applications or strategically important supply chains. Intelligence collection does not always begin with a cyberattack. Personal contacts, research partnerships, business relationships, investment approaches and apparently legitimate cooperation proposals may also be used to obtain access to protected knowledge.
The expanded competence centre is intended to strengthen advisory services, awareness programmes and cooperation networks. Its objective is to help organisations recognise suspicious activity earlier and report it more rapidly to the appropriate authorities.
The LfV already conducts security-awareness consultations with particularly exposed companies. According to the state government, the number of these meetings almost doubled last year compared with 2024. This development underlines that economic security can no longer be treated as a task for intelligence services alone. It requires close cooperation between public authorities, companies, research organisations and universities.
New legal and technical instruments
The organisational reform forms part of a broader security-policy programme in Hesse. The state previously amended its police legislation, including provisions expanding the use of artificial intelligence in video surveillance.
Hesse’s constitutional-protection legislation has also been revised. According to the Interior Ministry, the new legal framework permits the LfV to conduct remote searches of information-technology systems under strict conditions.
Such powers are politically and legally sensitive. They are intended to enable authorities to investigate digitally active targets and complex threat scenarios, but they remain subject to significant statutory thresholds and oversight requirements.
The restructuring therefore follows a three-level approach: expanded legal authority, improved technical capabilities and a revised internal organisation.
Whether this combination proves effective will depend on implementation. Additional powers provide little operational benefit if specialist personnel, technical systems and analytical processes are not available. Conversely, powerful technology without clear legal foundations and effective oversight risks undermining public confidence.
Cases illustrate the range of modern espionage
Several proceedings mentioned in connection with the reform demonstrate the diversity of current espionage and influence activity.
Three men are standing trial before the Higher Regional Court in Frankfurt. They are accused of having conducted surveillance of a Ukrainian national in Hesse on behalf of a Russian intelligence service. The individual reportedly served as a soldier in the war in Ukraine. According to investigators, the alleged reconnaissance may have been intended to prepare further operations, potentially including a targeted killing. The court will determine whether the allegations are proven.
Another example is the “Doppelgänger” disinformation campaign, which is alleged to have sought to influence political debate ahead of Germany’s federal election.
The authorities also referred to the arrest of a married couple in Munich in May on suspicion of spying for China. They are accused of having collected information on advanced technology with potential military applications. Again, the allegations remain subject to judicial determination.
The cases differ in their methods and objectives. What they share is the combination of traditional intelligence interests with modern technological, economic and social vulnerabilities.
Security authorities must operate as connected systems
The restructuring of Hesse’s domestic intelligence service reflects a wider transformation in national security. Espionage, cyberattacks, sabotage, drone activity and political influence can no longer be assessed as independent developments.
Security authorities must combine information more rapidly, connect technical and operational capabilities and deepen cooperation with business, research and public administration. At the same time, they require clear responsibilities, specialised personnel and legally robust investigative powers.
The new organisational model is therefore a logical response to a more complex threat environment. Its success, however, should not be measured by the number of newly created divisions or legal instruments.
The decisive questions are operational: How quickly can the authority assess a warning? How effectively can it connect initially unrelated incidents? How rapidly can it support an exposed company, research institution or public authority? And can it identify preparations for hostile action before they develop into sabotage, coercion or violence?
Protection against hybrid threats is not achieved within intelligence and police agencies alone. It begins in companies, universities, public administrations and critical-infrastructure organisations whose employees may be the first to notice an unusual contact, an unexplained drone flight, an attempted intrusion or a suspicious business approach.
Hesse’s reform acknowledges this reality. The next challenge will be turning organisational concentration into faster analysis, earlier warning and measurable protection.



