
At the end of last year, we uncovered and responsibly reported security vulnerabilities in video and surveillance systems developed by the Israeli software company „Infodraw“. As we received no response despite a 90-day deadline and numerous reminders and attempts to make contact as part of the Coordinated Vulnerability Disclosure process, we involved CERTs worldwide, amongst other measures, and approached law enforcement agencies directly so that the relevant systems could be protected. One of the affected public authorities was the Special Police Unit (Unité Spéciale de la Police) in Luxembourg, which was able to take the system offline following our notification. Following a presentation at the Chaos Computer Club’s Easterhegg event and several media reports on the topic, a formal criminal investigation was opened against our founder and managing director, Tim Philipp Schäfers, which was closed without result in mid-2025. This case serves as a prime example of the repression faced by security researchers and why a reform of computer crime law is urgently needed in almost all European countries. Details of the case are provided below, along with an analysis.
A criminal investigation follows a report and inclusion in the „Hall of Fame“
It is best practice for security vulnerabilities in software products to be reported with confidentiality to the manufacturer first, as the manufacturer can then provide critical updates to protect against these vulnerabilities (release of a patch). It is also common practice to set a deadline by which information on the vulnerability is withheld; the industry standard is usually 90 days, though there are also some isolated vulnerability disclosure policies that stipulate a period of just 45 days (see, for example, the CERT Coordination Centre). In order to comply with this best practice, we contacted the manufacturer on several occasions (see timeline below). As no response was received via any of the channels and the 90-day deadline under the Coordinated Vulnerability Disclosure process had expired, we subsequently contacted numerous CERTs and operators worldwide.
As a critical system was believed to be affected in Luxembourg (it could be directly traced to the IP address range of the Police Grand-Ducale), contact was made with the official GovCERT.LU. On 16 April 2025, they received a report regarding the security vulnerability and the affected system, and the information on the reporting procedure described on the website was fully complied with. Consequently, as in numerous other cases, the system was taken offline and thanks were extended. Fortunately, GovCERT.LU subsequently even got in touch, as it operates a „Hall of Fame“ and had planned to include a listing there:

Following the submission of the requested data, an entry was made in the „Hall of Fame“. The case thus initially appeared to have been successfully resolved, as with many other instances of contact. As a large number of the affected systems (following responsible reporting and coordination between CERTs worldwide) were offline, a talk on the topic was given at the Chaos Computer Club’s Easterhegg on 19 April 2025, and there were several media reports on the matter. Just five days after the talk, Tim Philipp Schäfers received the following email:

A telephone conversation was arranged to signal a willingness to cooperate. During the call, it was explained that a formal criminal investigation had been launched in which Tim Philipp Schäfers was named as a suspect. There was apparently a suspicion that Article 509 §1 of the Criminal Code of the Grand Duchy of Luxembourg had been breached, namely that unauthorised access had been gained to a computer system.
Consequently, a solicitor was entrusted with the case and a request was made to inspect the case files. Curiously, in subsequent communications, the public authorities proposed:
„to conduct an interrogation in the traditional sense via video conference (e.g. via Zoom or Microsoft Teams) in the presence of his legal counsel, including the subsequent drafting of minutes“, which raises significant questions under data protection law.
Should an interview not take place, the following scenario was also described:
„The drafting of a report to the Luxembourg Public Prosecutor’s Office, followed by the initiation of mutual legal assistance proceedings by way of a European Investigation Order (EIO), questioning by the competent German public authorities (e.g. the LKA or BKA) and the continuation of the investigation by the Luxembourg judicial authorities. This would inevitably involve the German authorities.“
A statement to this effect was refused, and the case was subsequently dropped in June 2025. However, a number of conclusions can be drawn from the overall course of events:
GovCERT.LU apparently passed on the security researcher’s report (naming the individual) to the police, as it also operates the system. This is a questionable course of action, as those who report incidents must be protected. The BSI, for example, explicitly provides for anonymous reports and states that criminal prosecution is generally avoided.
Within the police force, there is a potential conflict of interest in this case, as it acts both as the investigating unit and as the operator of the system. It is unclear how such situations can be avoided in the case of government systems in the security sector.
Security researchers face considerable legal uncertainty when it comes to cross-border reports. In this particular case, Luxembourgish criminal law applies; German law enforcement agencies would only take action via a request for mutual legal assistance. For security researchers, it seems simply impossible to familiarise themselves with the exact details of the laws before every report. Fortunately, Luxembourg actually has a relatively progressive criminal law, as Article 509 §1 of the Criminal Code stipulates that there must be „fraudulent intent“; however, this has not prevented proceedings from being initiated.
For the reasons outlined above, it is important to establish legal certainty across Europe as a matter of urgency and to introduce a modern cybercrime law (see proposals below). A modern cybercrime law that permits white-hat hacking is important because it enables security researchers to legally discover and report vulnerabilities before they are exploited by criminals. This allows businesses and public authorities to secure their systems more quickly and prevent digital attacks more effectively. It also promotes innovation and transparency by creating a clear legal framework for the responsible handling of security vulnerabilities.
What is also absurd in the context of this case is that, to date, the company has not provided a patch for the security vulnerability and is not facing any legal action, whilst the IT security researcher was subject to a corresponding criminal investigation.
Specific cases from recent years
This case is one of many. In recent years, there have been several instances of responsible disclosure of vulnerabilities where actions that were clearly in the public interest nevertheless led to intimidation or accusations, whilst those actually responsible for the security issues were not held to account. A brief overview of cases from recent years:
In May 2021, security researcher Lilith Wittmann discovered that personal data could be accessed without further authentication in a CDU election campaign app. The CDU subsequently filed a criminal complaint against Wittmann (lilithwittmann.medium.com). In response, the Chaos Computer Club (CCC) announced that it would no longer report security vulnerabilities to the CDU. The investigation was later dropped, and a data protection inquiry was launched against the CDU.
In 2021, software developer Hendrik Heinle discovered that over 700,000 pieces of customer data (including orders, addresses and account details from online services such as Otto, Check24 and Kaufland) were inadequately secured and reported this to the service provider responsible, Modern Solution GmbH & Co. KG. Consequently, the company filed a criminal complaint, leading to a search of the security researcher’s home, and convictions, including fines, were upheld across several courts. The IT security researcher has now lodged a constitutional complaint, meaning the case will be heard before the Federal Constitutional Court, as the normal legal remedies have been exhausted.
In March 2022, software developer Daniel Ilin discovered a critical security vulnerability in the music service Beatclub and responsibly reported it to the company. The company then apparently hired a private detective to intimidate the software developer and provided those affected with only delayed and incomplete information about the incident (golem.de).
Even the Federal Office for Information Security (BSI), of all public authorities – the very public authority primarily responsible for cyber security in Germany – once threatened security researchers with legal action in 2013 when they discovered security flaws in the encryption algorithms of the BSI’s „GSTool“ (golem.de).
Better computer crime legislation is both important and possible: there are also positive international examples of progressive computer crime legislation. A comprehensive comparative legal analysis by the Research Service of the German Bundestag shows, for example, that some EU countries have already incorporated the mere intent to commit a potential offence into the definition of the criminal offence, which can protect whistleblowers acting in good faith.
It is time to act: the „hacker clause“ must be abolished
The cases described clearly demonstrate that there is an urgent need for action and that computer crime law must be reformed as a matter of urgency. The „traffic light“ coalition government had already planned a reform of computer crime law for 2024, and draft bills on the subject were available on the BMJV’s website until recently. The German Informatics Society (GI) and other associations have submitted comprehensive statements on the matter, with some calling for even greater protection. However, the collapse of the „traffic light“ coalition prevented the implementation of the reform. Partly due to strong advocacy from security researchers, the topic was included in the coalition agreement, which states on page 92: „We will create legal certainty for IT security research within cybercrime law, whilst preventing opportunities for abuse.“ Despite the growing threats, nothing has happened since then. Although key points for greater cyber security were recently agreed upon by the Federal Cabinet, the plans remain abstract and fall far short of expectations. In particular, a reform of computer crime law and the introduction of a legally binding obligation to respond to external reports of security vulnerabilities could bring about a real turnaround and ensure greater cyber security in the long term.
As long as these legal uncertainties persist, security researchers who discover serious security vulnerabilities often have no choice but to report them anonymously or via an intermediary such as the Chaos Computer Club, in order to act responsibly and emerge from such situations unscathed. At the end of last year, for example, it was revealed that the movement and contact data of 800,000 Volkswagen owners were accessible on the internet without any protection (spiegel.de).
At this year’s Internet Governance Forum organised by IGF-D on 10 September 2025 in Berlin, a panel discussion will also take place on a future-proof cybercrime law. It is to be hoped that the implementation of a reform will occur in the near future, which will enable security researchers to make a decisive contribution to the hardening of IT systems in a legally compliant manner, without having to bear the risk of disproportionate criminal prosecution. After all, society as a whole benefits when security vulnerabilities are highlighted and reported transparently (ccc.de). This enables us to learn how to avoid mistakes in future and protect data effectively, which should be in everyone’s interest.
Finally, we would like to take this opportunity to express our sincere thanks to Beata Hubrig of the Hubrig law firm in Berlin, as she provided us with comprehensive consulting and representation throughout the proceedings. We would also like to thank the employees of the Federal Office for Information Security (BSI), who assisted with the coordination and contact with national CERTs and thus played a key role in ensuring that compromised systems could be taken offline.
Appendix 1: Timeline for the „Luxembourg case“ & report to the manufacturer
- End of 2024: Discovery of the critical security vulnerability & initial report to the manufacturer (info[at]infodraw.com) and setting of the standard 90-day deadline for the Coordinated Vulnerability Disclosure process
- Mid-January 2025: Follow-up enquiry and expansion of the email distribution list (including management and sales contacts), as no reply or confirmation had been received
- Mid-February 2025: Further reminder and enquiry, as no response had been received (contact made via other channels and direct messages)
- Mid-March 2025: Further reminder and enquiry, as no response had been received
- Early April 2025: Notification that the 90-day deadline for the Coordinated Vulnerability Disclosure procedure has expired and that CERTs and operators will be informed directly in due course
- Early April 2025: Internet-wide scan to identify affected IT systems and notification to operators
- 12 April 2025: Involvement of the BSI (Federal Office for Information Security), as systems were still accessible despite the planned disclosure and the BSI supports coordination between manufacturers and national CERTs under its CVD directive
- 16 April 2025: Report submitted to GovCERT Luxembourg (including a risk assessment, details of the security vulnerability and possible remedies)
- 16 April 2025: The affected system was taken offline and acknowledgement received from GovCERT.LU / Inclusion in the „Hall of Fame“ (govcert.lu/report/)
- 19 April 2025: Presentation at the Chaos Computer Club’s Easterhegg event in Hamburg / Publication of a blog post with details / Media reports on the topic
- 20 April 2025: Assignment of CVE-2025-43928 for the „Path Traversal“ vulnerability
- 24 April 2025: Initial contact by email from a criminal investigator in the Cybercrime Division of the Luxembourg Criminal Investigation Department, requesting a telephone call
- 28 April 2025: Telephone conversation with the detective from the Cybercrime Division of the Luxembourg Criminal Investigation Department and notification that a formal criminal investigation is being conducted in which the reporter is listed as a suspect
- May 2025: Consulting / application for access to case files / discussion regarding a possible interview / refusal to make a statement
- Early June 2025: The criminal investigation was discontinued
- Early September 2025: Publication of this article
How Mint Secure supports you
Responsible disclosure of vulnerabilities should not entail any legal risk. We draw on our experience from numerous Coordinated Vulnerability Disclosure (CVD) processes in our work:
Coordinated Vulnerability Disclosure
We support companies and public authorities in the professional coordination of vulnerability reports with manufacturers and CERTs.
Setting up reporting processes
We help establish clear Security.txt, bug bounty and reporting processes to ensure that reports of security vulnerabilities do not go unaddressed.
Penetration Testing
We test your systems for vulnerabilities in accordance with clearly defined, legally compliant test terms and conditions.
Conclusion
The „Luxembourg case“ is a prime example of how security researchers can find themselves subject to criminal investigations despite having reported issues to CERTs and manufacturers in an exemplary and responsible manner, whilst the software manufacturer actually responsible has still not provided a patch to this day.
As long as Germany and many European countries lack modern computer crime legislation with clear safeguards for white-hat hacking, responsible security research will continue to be subject to considerable legal uncertainty. A timely reform of the hacker clause is long overdue.
Mint Secure continues to advocate for a legally sound framework for security research and supports companies in dealing professionally with vulnerability reports. Talk to us.

