Hacker attack on Berlin's national network: 5.8 terabytes of data stolen
Quick Look
- From August 7th to 12th, hackers penetrated the Berlin state network unnoticed and stole 1.44 million files with a size of 5.8 terabytes.
- The Rhysida group demanded a ransom of 30 Bitcoin, which the state government did not pay.
- After the ultimatum expired, the data was published on the dark web.
AI-generated summary
Why It Matters
The Rhysida hacker group has been active since mid-2021 and is known for financially motivated attacks, including a similar attack on the city of Stuttgart. The incident occurred in the context of increasing cyber threats against government institutions and critical infrastructure.
What happened?
From August 7th to 12th, hackers initially gained unnoticed access to parts of the Berlin state network and skimmed off large amounts of data. The Senate departments for construction and transport were affected. The administration noticed the attack on August 14th - and made it public three days later.
Only gradually did it become clear what amount of data the criminals had stolen: 1.44 million files with a size of 5.8 terabytes, i.e. around 5,800 gigabytes.
The criminals demanded a ransom of 30 Bitcoin - the equivalent of around two million euros. But the Berlin state government did not give in to this. After their ultimatum expired on September 4th, the hackers published the data on the dark web, i.e. in a part of the Internet that cannot be found in the traditional way such as search engines.
Communication on the Darknet is encrypted; the authors of content and those who access it want to remain as anonymous as possible.
Who are the hackers?
The group Rhysida (the name comes from a genus of centipedes), which is believed to be responsible for the leak, is known to the security authorities and has been active since mid-2021. IT security expert Bianca Kastl, who is a member of the Chaos Computer Club, told rbb that Rhysida, for example, had already attacked and blackmailed the city of Stuttgart - with a pattern similar to that now in Berlin.
According to the Federal Ministry of the Interior, the group is generally considered to be financially motivated. The Federal Office for Information Security (BSI) does not suspect a political intention in the current case in Berlin, but rather a financial one.
A comprehensive overview is currently difficult because it takes time to sift through the huge amounts of data. According to information from the Chaos Computer Club, this involves, among other things, personal data of administrative employees, such as personnel matters, job references or emergency plans.
The Tagesspiegel reports that the hackers also published content that is relevant to the security of the Federal Republic and the capital, for example data from facilities that are particularly worthy of protection such as thermal power plants, tank farms, emergency power systems and substations. The hackers are also said to have leaked secret data about prisons, waterworks and defense companies as well as the Bundeswehr and the Berlin interior administration that affect defense.
Der Spiegel also reports, with reference to its own research, that numerous federal issues are affected. The data includes more than 550 files on the expansion of the Chancellery, including reports, plans and statements, for example from the State Criminal Police Office.
The Chaos Computer Club says it looked at some documents and found sensitive information about the state of the water supply in Berlin.
How are the authorities reacting?
You are trying to get an overview of the published data. According to a spokesman, the federal government is “carrying out an intensive review of its own data systems”. The spokesman said that these were not affected "according to current knowledge" - that was before the research by Spiegel and Tagesspiegel was published. Berlin's Governing Mayor Kai Wegner (CDU) told the Bild newspaper that the city's authorities are currently checking what information has been leaked in order to quickly inform those who may be affected.
A spokeswoman for the operational command of the Bundeswehr referred to the ongoing evaluation by the security authorities and announced that after analyzing potential security risks, measures would be initiated to maintain military security. There is “a continuous comparison of information between the authorities involved, including via the National Cyber Defense Center”.
What are the dangers of publishing?
If it is confirmed that the data contains security-relevant information, it could theoretically be exploited by foreign powers or terrorists for their own purposes. The BSI warns that information about critical infrastructures, companies and organizations could increase the threat level.
With regard to personal data, Jochim Selzer from the Chaos Computer Club points out the risk of identity theft. "The more I know about a person, the more accurately I can identify myself as that person, and the more accurately I can assess what I need to know about that person, for example in order to be able to order something on their behalf."
The BSI also points out an increased threat from targeted phishing attacks following the data leak. People who have been in contact with affected people or institutions should be particularly careful.
The Federal Office also warned of the danger of so-called hack & leak operations for the political sphere, especially before elections. Stolen documents, emails or the like are published at a time that is convenient for the attacker and may be placed in the wrong context.
The Berlin House of Representatives will be re-elected on September 20th. State returning officer Stephan Bröchler told Bild that as things currently stand, the election environment is still not affected - i.e. neither the preparation, nor the actual election day, nor the process leading up to the publication of the provisional results.
Why is there criticism?
The IT expert Manuel Atug accuses the state of Berlin of having acted “grossly negligently” and of not complying with confidentiality requirements. There are very strict and precise regulations as well as several security levels for the storage and processing of secret documents. Apparently these were not applied sufficiently. Atug is the founder and spokesperson of AG Kritis, an independent working group that deals with critical infrastructures.
The police union in Berlin was dismayed: "He has once again clearly shown Berlin's politics that people have been sleeping around here for years," said GdP state deputy Thorsten Schleheider. “It cannot be the case that highly sensitive data was stolen here for days and that the only reaction seems to be to instruct employees to change their passwords.” That shows a certain helplessness.
What to Watch
AI outlook — possibilities, not facts
The authorities will have to identify and fix further security gaps in the Berlin state network.
Very likely · Within weeks
There will be an increase in phishing attacks on people who have been in contact with affected individuals or institutions.
Likely · Within days
The discussion about the security requirements for classified information in Berlin will become more intense.
Very likely · Within weeks
Open Questions
- Who exactly is behind the hacker group Rhysida?
- What specific steps are being taken to secure the leaked data and prevent misuse?
- How will the security of Berlin's state networks be improved in the long term?
- Is there evidence that foreign powers have already accessed the leaked data?



