
After the state of Berlin rejected ransom demands from a hacker group, 5.8 terabytes of data were published on the dark web, including potentially security-relevant information.
AI-generated summary
Hackers gained access to the Berlin state network between August 7th and 12th. The Rhyside group demanded a 30 Bitcoin ransom, which was rejected by the Senate.
The state of Berlin did not give in to blackmail attempts by a criminal hacker group - now large amounts of data are online. This is not just a problem for those directly affected.
After the hacker attack on the Berlin state network, the blackmailers carried out their threat. Berlin. The blackmailers have carried out their threat: three weeks after the serious hacker attack on the Berlin administration, the hackers published large amounts of data. The big concern is that the sensitive information could now be exploited by criminals. What is known and what risks there are.
What happened?
From August 7th to 12th, hackers gained unnoticed access to parts of the Berlin state network and skimmed large amounts of data. The Senate departments for construction and transport were affected. The administration didn't notice the attack until August 14th - and made it public three days later. Only gradually did it emerge what treasure trove of data the criminals had stolen: 1.44 million files with a size of 5.8 terabytes. One terabyte is equivalent to around 1,000 gigabytes.
The hacker group Rhyside demanded a ransom of 30 Bitcoin - the equivalent of around two million euros. The Senate did not give in to this. After their ultimatum expired, the hackers published the data on the dark web on Friday. This refers to a part of the Internet that cannot be found in the traditional way - for example through the usual search engines. According to the Federal Office for Information Security (BSI), communication there is encrypted and the authors of content and those who access it want to remain as anonymous as possible.
What kind of data is it?
A comprehensive overview is still difficult at this point - it is not easy to sift through the huge amounts of data. According to information from the Chaos Computer Club, this includes personal data from administrative employees - personnel matters, references, emergency plans.
The âTagesspiegelâ reports that the hackers also published content that was relevant to the security of the Federal Republic and the capital. According to the information, this concerns data from facilities that are particularly worthy of protection, such as thermal power plants, tank farms, emergency power systems and substations. The hackers are also said to have leaked secret data about prisons, waterworks and defense companies, the Bundeswehr and the Berlin interior administration that affect defense.
Jochim Selzer, spokesman for the Chaos Computer Club, said he looked at some documents and found sensitive information about the state of the water supply in Berlin. The IT expert Manuel Atug does not want to view the documents on the Darknet himself for ethical reasons. However, he learned from reputable sources that the newspaper's information was correct, at least in the case of information about civil defense and defense companies. He is the founder and spokesman for AG Kritis, an independent working group that deals with critical infrastructures.
How are the authorities reacting now?
You are trying to get an overview of the published data. âThe security authorities are currently carrying out an intensive data check,â the Berlin Senate announced on Friday evening. âIT forensic experts commissioned by the State of Berlin are also intensively investigating the published data.â âThe appropriate measures would be derived from thisâ - what that actually means remained unclear. However, the country announced that if individual affected people were identified, they would be informed âon a risk-based basis and in accordance with legal requirementsâ.
Upon request, the Federal Ministry of the Interior announced that federal authorities were also supporting the state of Berlin in the evaluation - namely the Federal Office for Information Security, the Federal Criminal Police Office and the Office for the Protection of the Constitution. A spokesman for the federal government said that, based on current knowledge, federal data systems were not affected.
A spokeswoman for the operational command of the Bundeswehr referred to the ongoing evaluation by the responsible security authorities and announced that after analyzing potential security risks, appropriate measures would be initiated to maintain military security. âThere is a continuous comparison of information between the authorities involved, including via the National Cyber ââDefense Center.â
What are the dangers of publishing?
If it is confirmed that the data contains security-relevant information, it could theoretically be exploited by foreign powers or terrorists for their own purposes. Information about critical infrastructures, companies and organizations could increase the threat level, depending on the sensitivity of the data, warns the BSI.
With regard to personal data, Jochim Selzer from the Chaos Computer Club points out the risk of identity theft. âThe more I know about a person, the more accurately I can identify myself as that person, and the more accurately I can assess what I need to know about that person, for example in order to be able to order something on their behalf.â
The BSI also points out an increased threat from targeted phishing attacks following the data leak. People who have been in contact with affected people or institutions should therefore pay particular attention.
Why is there criticism?
The IT expert Atug accuses the state of Berlin of having acted âgrossly negligentlyâ and of not complying with secrecy regulations. There are very strict and precise regulations as well as several security levels for the storage and processing of secret documents. Apparently these were not applied sufficiently.
The police union in Berlin was dismayed by the events. âHe has once again clearly shown Berlinâs politics that people have been sleeping around here for years,â said GdP state deputy Thorsten Schleheider. âIt cannot be the case that highly sensitive data has been stolen here for days and that the only reaction seems to be to instruct employees to change their passwords.â That shows a certain helplessness.
Can the incident have an impact on the Berlin election?
The Berlin House of Representatives will be re-elected on September 20th. State returning officer Stephan Bröchler told âBildâ: âAs things stand, the election environment is still not affected. So neither the preparation, nor the actual election day, nor the process up to the publication of the provisional results.â
The BSI fundamentally warned that there was a risk of so-called hack & leak operations in the political sphere, especially before elections. Stolen documents, emails or the like are published at a time that is convenient for the attacker and may be placed in the wrong context. However, according to the BSI, it is not suspected that the criminal hackers have a political intention in this specific case. It is assumed that the crime was âexclusively financially motivatedâ.
AI outlook â possibilities, not facts
Identified affected parties will be informed about the data leak.
Very likely · Within weeks
Federal authorities such as BSI, BKA and BfV are supporting the investigation into the cyber attack on Berlin's Senate administrations, in which the hacker group Rhysida demanded a ransom of two million euros in Bitcoin and threatened to publish data. Governing Mayor Kai Wegner confirmed attempted blackmail and isolated networks, refused payment and highlighted daily cyberattacks on state networks across Germany.
Three weeks after a hacker attack on the Berlin administration, criminals published 1.44 million files with a size of 5.8 terabytes on the darknet. This affects, among other things, personal data of employees as well as security-relevant information on critical infrastructures such as thermal power plants, waterworks and defense companies. The authorities are currently carrying out an intensive data check and warn of possible misuse through identity theft or phishing attacks.

Following a cyber attack on Berlin's Senate administrations, hackers have published sensitive data after the state of Berlin rejected a ransom demand of 30 Bitcoins. Internal documents, personnel data and confidential documents are affected.
Twelve homemade explosive devices were found on high-voltage lines in East Saxony. The police were able to defuse the sentences; There was no damage to the power supply. Investigators are now examining connections with similar incidents in other federal states.
After a cyber attack on the Berlin administration in which 5.8 terabytes of data was stolen, the BSI, BKA and BfV are supporting the Berlin authorities. The hacker group Rhysida had demanded a ransom that the Senate did not pay.
In East Saxony, twelve homemade explosive devices were discovered on high-voltage lines and defused by the State Criminal Police Office. The police are investigating connections with similar incidents in Brandenburg and North Rhine-Westphalia.