Data leak at Berlin authorities: What is known about the hacker attack
The hacker group Rhysida published sensitive administrative data on the darknet after refusing to pay ransoms.
Quick Look
- After a failed blackmail attempt, the hacker group Rhysida published sensitive data from Berlin authorities on the darknet.
- Contracts, personnel files and security-related documents are affected.
- Authorities and BSI warn of further risks.
AI-generated summary
Why It Matters
The hacker group Rhysida demanded a ransom of two million euros from the state of Berlin, which refused to pay. The attack took place on August 7 through two specific Senate offices.
Which sensitive data is affected?
These are documents from administrative operations, such as contracts, protocols, passwords. The data set also contains personal data such as addresses and telephone numbers or confidential personnel files: According to Tagesspiegel, rehabilitation documents, certificates or sick notes can be found there. The SZ also found application documents, email traffic and many working papers marked “confidential”. Security-relevant information such as emergency plans and secret communication channels are also said to have been leaked. But one thing is also clear: the data set is huge, and it will only become clear in the coming days what information is still contained in the published documents.
How do I find out if I am affected?
Anyone who has Darknet access can theoretically search the files, but this is very time-consuming and involves a certain amount of risk. The Berlin administration wants to inform people who appear in the leaked data, depending on their risk assessment. There is also a contact point for administrative employees. It is said that those affected are called upon to file a criminal complaint with the police. The Berlin data protection officer also recommends updating passwords for administrative and online services and monitoring account movements.
What happened to the data?
The hackers initially tried to extort the equivalent of around two million euros from the state of Berlin, but the state did not pay. This deadline expired on Friday afternoon. According to information from the Süddeutsche Zeitung, the data can since then be downloaded from the Rhysida group's darknet page.
Who is behind the hack?
The hacker group Rhysida claimed responsibility for the attack. In the past, it had attacked various public and private institutions, such as the British National Library and the Chilean military. The Federal Office for Security assumes that the hack was “exclusively financially motivated”.
How could the hackers get the data?
Investigations into the incident in Berlin are still ongoing. What is certain is that the attack took place on August 7th via the Senate Department for Mobility, Transport and Environment and the Senate Department for Building and Housing. Both authorities have their own IT and are not directly managed by the state's own IT service center. Some critics see the lack of consolidation of public IT as risky. The Berlin Senate Chancellery initially stated that only publicly accessible data was leaked in the attack. This later turned out to be wrong. The time of the attack was also only discovered late.
In the past, Rhysida had gained network access using phishing attacks. The attackers imitate websites or pose as trustworthy colleagues or official administrators in emails in order to obtain access data. Hackers can then use such compromised data to access systems and wipe them out unnoticed. The investigation still has to show whether exactly this was done in Berlin.
Is there still a risk of further attacks?
According to the state of Berlin, there is currently no evidence that the state network is still infiltrated. The network connects around 600 locations in Berlin, such as administrative buildings, fire stations and scientific institutions.
The Federal Office for Information Security (BSI) recognizes a fundamentally increased threat situation. “The BSI explicitly points out that the publication of stolen data can result in various risks for those affected and ultimately for society,” explained a spokesman. There is a risk of so-called hack & leak operations in the political sphere, especially before elections. Stolen documents, emails or the like are published at a time that is convenient for the attacker and may be placed in the wrong context.
How does Berlin react to the attack?
In Berlin they declared that they would not respond to attempts at blackmail. Accordingly, the country let the deadline pass on Friday afternoon. IT security experts welcomed this decision. Since passwords and access data were also published, access to the systems was also restricted, reports the Tagesspiegel. Employees of the affected administrations could no longer log in to internal programs from their home office via VPN, but had to be present in the office to do so.
Does the attack threaten the Berlin election on September 20th?
What to Watch
AI outlook — possibilities, not facts
Those affected will be informed about the data leak.
Likely · Within weeks
Open Questions
- What other sensitive information is included in the data set?
- How exactly did the hackers gain access?

