
Category
Security Kultur
Topic
Hacking & Democracy
Audience
The public & schools
Reading time
approx. 7 minutes
At the end of August 2026, we’ll be hosting a hacking workshop at the Democracy Days in Halle and Wismar. In front of school classes in Years 10 and 11, we’ll demonstrate how attacks on web applications work, whilst posing a question that may seem surprising at first glance: what does hacking actually have to do with democracy? The short answer is: more than most people think.
What hacking has to do with democracy
Democracies today run on software. Elections, public administration, hospitals, the electricity grid and the platforms on which we get our news and engage in debate – everything depends on digital systems. If this software is insecure, democracy itself becomes vulnerable. Secure systems are therefore not merely a technical topic, but a prerequisite for a functioning, open society.
Added to this is a mindset. Hackers do not simply take a system at its word, but verify things for themselves. It is precisely this attitude – not trusting blindly, but questioning and reviewing – that lies at the heart of media literacy and the formation of informed opinions. Whether it’s a login screen or a viral post, the pattern is the same.
Key idea: IT security research – what many simply call ‘hacking’ – can strengthen democracy. It makes the claims of powerful actors verifiable and uncovers vulnerabilities before they are exploited.
When hackers protect democracy
The controversy surrounding electronic voting machines serves as a case study. In the mid-2000s, electronic voting devices were introduced in Germany. The Chaos Computer Club, together with Dutch activists, demonstrated that these devices could be manipulated. In 2009, the Federal Constitutional Court ruled that their use was unconstitutional. The key principle is this: every citizen must be able to review the essential stages of an election for themselves, without specialist knowledge. A ‘black box’ cannot achieve this. Since then, elections have once again been conducted using pen and paper.
The situation is similar with the so-called ‘state Trojan’. In 2011, the Chaos Computer Club was leaked a genuine piece of surveillance software from a public authority and analysed it in detail. The result: the software was capable of far more than permitted – such as remotely controlling the camera, microphone and keyboard, and loading arbitrary code – and also contained serious security vulnerabilities that third parties could have exploited. The CCC’s analysis sparked a wide-ranging debate that eventually reached the Federal Constitutional Court. The point is not that the hackers won, but that they made an unlawful practice verifiable in the first place.
When hacking becomes a weapon against democracy
The same techniques can also be turned against democracy. In 2015, attackers breached the IT systems of the German Bundestag. Among those affected were the parliamentary office of the then Chancellor and around a dozen other offices; more than 16 gigabytes of data were leaked. The breach was carried out via rigged emails sent to MPs. The attack is attributed to the group APT28, which is believed to be linked to a Russian intelligence service.
Another front is targeted disinformation. In the so-called ‘lookalike’ campaign, deceptively authentic copies of reputable news sites were created to stir up public sentiment through fabricated articles and hundreds of thousands of fake accounts. At its core, this is the same trick used in a classic web attack: something looks trustworthy, but it isn’t. Those who have learnt to look beyond the façade and verify the source themselves are less likely to fall for it.
Our own research: vulnerabilities in public systems
At Mint Secure, we put this commitment to acting in the public interest into practice through our own IT security research. In line with the principle of responsible disclosure, we first report vulnerabilities to those responsible and give them time to rectify the issues before we make our findings public. Here is a selection of systems in which we have uncovered risks:
-
- Data protection and security risks in the infrastructure of the payment card for refugees
- Security issues in the BAMF’s Delegated User Management (DeBeV) system
- Typo- and Bitsquatting relating to bund.de domains
- A Path Traversal vulnerability in reconnaissance devices for video and audio surveillance
- Data protection and IT security relating to the e-passport photo infrastructure
- Data protection and security issues in the Yoti age verification app
Much of this affects people who are unable to defend themselves effectively, or infrastructure on which the state and the public rely. This is precisely where independent security research is particularly important.
Research as a contribution to a resilient society
For us, ethical hacking also involves sharing knowledge. In the past, Mint Secure employees have given presentations at events including the Chaos Communication Congress, the GPN and the Chaos Computer Club’s Easterhegg. At the Tincon youth conference, we ran workshops on hacking, IT security and privacy in 2025 and 2026. The hacking workshops at the Democracy Days in Halle and Wismar fit perfectly into this framework: making IT security accessible to everyone.
How Mint Secure makes a contribution
🔬
security research
We identify unknown vulnerabilities and report them responsibly before they cause any harm.
🎤
Talks & Live-Hacking
We make attacks visible and explain them in an accessible way, from school classes to specialist conferences.
🛡️
Penetration Testing
We test systems from an attacker’s perspective so that vulnerabilities can be patched whilst there is still time.
🤝
Awareness & Consulting
We empower organisations and individuals to recognise digital risks for themselves.
Are you planning an event? We organise Live-Hacking demonstrations, talks and workshops for schools, businesses and conferences. Get in touch.
Don’t just take the system at its word – check for yourself. This approach protects both computers and democracy in equal measure.
Mint Secure GmbH

