Berlin's municipal government fell victim to a cyberattack that resulted in the theft and public disclosure of what authorities describe as a "considerable amount of data." The breach compromised personal information held by public-sector workers and possibly Berlin residents, according to official confirmation.
The intrusion targeted two Senate departments between 7 and 12 August: the Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Climate Protection and the Environment. The sheer volume of exposed material has prevented authorities from fully reviewing what was taken.
Potentially compromised data encompasses names, residential addresses and birth dates, plus records of communications with both departments. Depending on individuals' interactions with these agencies, the breach could also include banking information, email addresses, phone numbers and copies of submitted documents.
Systems Disconnected from Government Network
On 14 August, Berlin disconnected the compromised systems from its broader government network, according to reporting by The Record. Both affected Senate departments remained operational, though some staff lost routine access to email and internet services.
Berlin's response involved coordination among the State Criminal Police Office, the two affected Senate departments, the State Data Protection Authority, the State Plenipotentiary for Information Security and additional security agencies.
Kai Wegner, Governing Mayor of Berlin, characterised the attack as "a serious crime against the state." He stated: "The LKA and the Senate administrations concerned are now working hard to evaluate the stolen data. We will inform, advise and support the affected employees and Berliners as quickly as possible." Wegner added that Berlin maintained close coordination with federal security authorities.
Rhysida Claims 5.79TB Dataset
The Rhysida ransomware group took credit for the attack in August, claiming to have obtained 5.79TB of data containing tens of thousands of contracts, emails, passwords and other classified material, according to The Record. Berlin authorities have not verified these assertions.
While Berlin confirmed receipt of an extortion demand, the city has neither publicly attributed the attack to Rhysida nor validated the group's description of what was stolen. Reporting by Berlin.de indicated the ransom demand started at 30 bitcoin, valued at approximately €2 million at that time.
Berlin has announced it will not comply with the extortion demand. Florian Hauer, Chief Digital Officer for the State of Berlin, said: "The State of Berlin will not give in to blackmail. The safety of the State of Berlin's staff and the people of Berlin is our top priority." Hauer noted that authorities were strengthening protections across the state network.
Secondary Fraud Threats Emerge
The public disclosure of stolen data creates dangers beyond the initial breach, particularly given the exposure of personal and financial details. These can be weaponised for follow-on attacks.
Berlin has instructed potentially affected individuals to update passwords for administrative and online accounts and review transaction histories on bank and credit-card statements.
Officials have also cautioned residents to watch for phishing campaigns, avoid clicking links in unexpected messages and ignore communications from unrecognised or questionable sources. Authorities stressed that victims should not pay anyone attempting extortion and should instead contact police.
For cases involving misuse of bank access, payment cards, mobile numbers or electronic IDs, authorities recommend using Germany's 116 116 blocking service and filing a police report. Documentation of suspicious activity is also advised.
The guidance underscores how breaches of government records can create downstream opportunities for criminals. Names, contact details, correspondence records and contextual information can lend credibility to fraudulent schemes.
BSI Flags Separate Multi-stage Attack Pattern
Germany's Federal Office for Information Security (BSI) issued a separate alert after learning on 26 August of a compromise affecting a state institution's network. Subsequent examination revealed patterns matching the multi-stage TerminalFix attacks recently documented by Microsoft.
The BSI noted that reports it received indicated attackers had attempted to deploy ransomware and harvest data as part of double-extortion schemes, in which victims face threats of data publication alongside encryption demands.
The BSI statement should not be interpreted as attributing the Berlin Senate attack to TerminalFix based on currently available information. The agency's warning concerns a separately identified compromise of a state institution.
Berlin authorities have also stressed that no evidence suggests election systems were compromised or election-related information was stolen, and that the electoral environment remains secure.
Investigation Continues as Data Volume Complicates Assessment
Berlin's immediate priority is determining the full scope of exposed information. Authorities have confirmed that employee personal data and potentially citizen information was published, but the quantity of material has prevented complete evaluation.
This creates a significant gap between what Berlin has verified and what Rhysida claims to have taken. The confirmed breach is substantial enough to warrant coordination across Berlin's police, data-protection, information-security and government bodies, along with public warnings to potentially affected individuals. However, claims regarding the 5.79TB dataset and its specific contents remain attributable to Rhysida rather than to confirmed investigative findings.
For Berlin, the incident now extends well beyond restoring compromised systems. The city must identify what was disclosed, notify and assist those affected, and curtail the secondary fraud opportunities created by already-exposed information.



