Hacker attack on Berlin administration: 1.44 million files published on the darknet
The extent of the data leak could go far beyond personal data and affect critical infrastructure.
Quick Look
- After a hacker attack on the Berlin administration, 1.44 million files were published on the darknet.
- Experts warn of serious consequences for national security and critical infrastructure, as sensitive data could also be affected.
AI-generated summary
Why It Matters
Hackers from the Rhysida group penetrated the Berlin national network between August 7th and 12th. The demand for a 2 million euro ransom was rejected by the Senate.
Around 1.44 million files from the Berlin administration have been on the dark web since Friday. The extent could be much more far-reaching than expected. Why politicians and experts express harsh criticism.
Berlin. There is talk of a “real data meltdown”, of a data outflow of “serious proportions”: the hacker attack on parts of the Berlin administration could have much more far-reaching consequences than initially known, far beyond the capital. Since Friday, around 1.44 million files with a size of 5.8 terabytes have been published on the dark web. One terabyte is equivalent to around 1,000 gigabytes.
Initially, only personal data seemed to be affected: scanned passports, employment contracts, application documents, sick notes. However, according to several media reports and the assessment of IT experts, highly sensitive data that is relevant to the protection of critical infrastructure and the security of the federal and state governments could also have been leaked. This involves, for example, civil defense or defense companies.
Green parliamentary group deputy Konstantin von Notz spoke of a “real data disaster” in the “Handelsblatt”. “If it turns out that protective mechanisms were deliberately not adhered to and the urgently needed secret protection was not guaranteed, personnel consequences would also be unavoidable,” the Green politician told the newspaper.
“The federal government is directly responsible.”
He accuses the federal government of “massive failures”. In his opinion, it could be the most serious IT security case known to date at the state level - with potentially significant financial consequences, says von Notz: "The latest case in Berlin will cost taxpayers millions. The federal government is directly partly to blame."
CDU foreign politician Roderich Kiesewetter told the “Süddeutsche Zeitung”: “This data outflow is of serious proportions and endangers our national security.”
Hackers demanded the equivalent of around two million euros
From August 7th to 12th, the hackers gained unnoticed access to parts of the Berlin state network and skimmed off data. The Senate Departments for Building and Transport were affected. The administration noticed the attack on August 14 and made it public three days later. The hacker group Rhysida demanded 30 Bitcoin, which is the equivalent of around two million euros. The Senate did not pay and the perpetrators published the data after their ultimatum expired. An Interior Ministry spokesman said the group was considered and was acting for financial reasons.
A complete overview of the leaked data is currently hardly possible due to the enormous amount. In addition, you cannot simply search for certain terms using CTRL+F, explained Jochim Selzer, spokesman for the Chaos Computer Club. According to his research, the files contain not only personal data but also sensitive information about Berlin's water supply. According to the “Tagesspiegel”, this also includes data on thermal power plants, tank farms, emergency power systems, substations, prisons, waterworks as well as defense companies and the Bundeswehr.
IT expert accuses Berlin of gross negligence
Those affected are at risk of identity theft and targeted phishing attacks, as the Federal Office for Information Security (BSI) informs. Security-relevant information could also be misused by foreign powers or terrorists. The BSI warns that information on critical infrastructures, companies and organizations could increase the threat level, depending on their sensitivity.
The IT expert Manuel Atug accuses the state of Berlin of serious failings. “The state of Berlin acted with gross negligence and intentionally failed to comply with secrecy regulations,” he told the German Press Agency. “I’m really shocked and speechless about this.” Atug said he was invited as an expert to the Berlin Interior Committee in 2023 and 2025 and had already pointed out glaring security gaps back then.
Those affected should be contacted by letter or email
In Berlin, an additional control unit now coordinates the viewing and evaluation of the data. According to the Federal Ministry of the Interior, the Federal Office for Information Security (BSI), the Federal Criminal Police Office (BKA) and the Federal Office for the Protection of the Constitution (BfV) are also involved in the investigation. All findings would be compiled and shared in the Joint Cyber Defense Center.
According to the Senate Chancellery, affected citizens, employees and companies should be contacted and advised on a risk-based basis by letter or email.
The Senate Chancellery initially did not provide any specific information about exactly which data was published. Forensic investigations and investigations are ongoing. The Bundeswehr announced that it would initiate measures to protect military security after analyzing possible security risks.
The Berlin state government also says it has increased security measures. In two weeks a new House of Representatives will be elected in Berlin. As things stand, the election environment is not affected, said state returning officer Stephan Bröchler.
What to Watch
AI outlook — possibilities, not facts
Investigations by BKA and BfV to investigate the data leak.
Very likely · Within weeks
Open Questions
- Which specific sensitive data is affected exactly?
- How high are the actual financial losses?



