Cyber attack on Berlin Senate administrations: Hackers publish stolen data after the ransom deadline has expired
Quick Look
- After a cyber attack on several Berlin Senate administrations from August 7th to 12th, hackers published stolen data after the ransom deadline of 30 Bitcoins (approximately two million euros) expired on Friday afternoon.
- The published documents include department-specific documents, political processes, internal administrative matters as well as confidential personnel documents such as certificates and ID cards.
- The Berlin administration will inform affected people depending on the risk and recommends filing criminal charges.
AI-generated summary
Why It Matters
It had been known for a week that hackers were blackmailing the state of Berlin and threatening to publish the stolen data unless a large sum of money was paid. The cyber attack became known on August 14th and affected the Senate departments for mobility, transport, climate protection and the environment as well as those for urban development, construction and housing.
The cyber attack became known on August 14th. The Senate departments for mobility, transport, climate protection and the environment as well as those for urban development, construction and housing were affected. The professional hackers apparently had unnoticed access to the internal computer systems for several days, from August 7th to 12th. Initially, the Senate claimed that only publicly accessible data had been leaked.
There is also confidential information about disciplinary proceedings
It had been known for a week that hackers were blackmailing the state of Berlin and threatening to publish the stolen data unless a large sum of money was paid. The stolen data was offered for sale on their dark web site. Amount required: 30 Bitcoins, which is around two million euros at the current rate. Berlin's Governing Mayor Kai Wegner (CDU) declared that the state of Berlin would not allow itself to be blackmailed. The hackers' deadline expired on Friday afternoon.
The data that has now been published comes from all possible departments of the affected Senate administrations. These include departmental documents, documents on political processes and internal administrative matters. From the human resources area, the documents include certificates or scanned ID cards. The hackers also published confidential documents on disciplinary proceedings, titled “Confidential Personnel Matter!”
Similar to this case, Rhysida has attacked organizations and companies dozens of times in recent years, stealing data and either getting paid for it or publishing it on the dark web. The USA was often affected, but sensitive data from a property management company in Stuttgart has already been published, albeit to a much lesser extent than in Berlin.
The Berlin administration wants to inform people who appear in the leaked data, depending on their risk assessment. It is said that those affected are called upon to file a criminal complaint with the police. It is currently assumed that the “Berlin State Network”, i.e. the authorities’ computer network, is no longer infiltrated.
Correction note: An earlier version of this article incorrectly stated that data from the Stuttgart city administration had been published on the hacker site. However, it was inaccurately titled data from a Stuttgart property management company.



