Berlin, September 5th, 2026 (The Berlin Spectator) – Weeks after cybercriminals struck the servers of two Berlin state administration departments, the promised extortion deadline has come and gone, and the stolen data is now circulating on the dark web. City authorities say they are working to identify individuals affected and to notify them directly, while security experts warn the fallout could stretch far beyond the capital’s own workforce.
The group behind the attack, known as Rhysida, had threatened to publish the material unless Berlin’s Senate paid a ransom of 30 Bitcoin, worth roughly two million euros at current exchange rates. The Senate said from the outset that it would not give in to the demand, and once the deadline passed on Friday afternoon at 3:35 p.m., the hackers made good on their threat.
A message posted to the group’s leak site read, in essence, that all files had been made publicly accessible and invited “data hunters” to browse. What followed was a release of roughly 5.26 terabytes spread across close to 1.44 million individual files, described by several outlets as the largest data theft in the history of Berlin’s state administration.
What Is In The Files
The scale of the leak has alarmed IT security professionals well beyond city hall. Joachim Selzer, spokesman for the Chaos Computer Club, was quoted by Germnan media. He stated, the entire dataset appeared to have been placed online for anyone to view. Among the material he identified were personnel files, references written for employees, building and construction records, emergency plans, job application documents, timesheets, records tied to staff reintegration programs, and works council files. He also noted a large volume of routine bureaucratic paperwork, the kind of small, easily overlooked detail that criminals can still exploit for identity theft.
Some of the exposed records go further than administrative housekeeping. Selzer pointed to a request for a new mobile phone that included the handling employee’s actual signature, material he said could prove useful to criminals looking to forge documents in someone else’s name. He expects any large-scale misuse of the data to unfold over the medium term simply because of its sheer volume, someone first has to sort through it.
More troubling still, later reporting from the Tagesspiegel found that the leak reaches into material classified for reasons of national and civil defense. Files reportedly include lists tied to Germany’s “Operation Plan Germany,” the Bundeswehr’s overarching framework for responding to crisis or war, along with an internal draft of a civil defense guide for Berlin from August 2025.
Also named are facilities considered essential to civil protection, among them heating plants, fuel depots, emergency power installations, and substations, plus assessments of vulnerabilities in Berlin’s drinking water supply. Some documents touch on arms manufacturers and on facilities covered by federal emissions law, reportedly including details such as emergency contact numbers, operating hours, and whether a site has security personnel on duty. According to the Tagesspiegel, officials within the affected departments had themselves noted in internal correspondence that no adequate digital safeguards existed for handling classified material of this kind, meaning some of this work still relies on paper records.
The trove reportedly also contains employee data listing real names and, in some cases, disability status, along with private emergency phone numbers, payroll records, disciplinary files, and banking details tied to senior officials in the two departments. Separately, files with names like “Passwort.docx” are said to contain login credentials stored in plain text, some using passwords security experts would consider weak by any standard.
Authorities Respond
City authorities say they are now working through the material systematically. According to a letter from the Senate Chancellery, IT forensic specialists are examining the published data under pressure, and where individual victims can be identified, the responsible Senate departments plan to notify them directly, following a risk-based approach in line with legal requirements. Berliners who learn independently that their data has surfaced online, or that it is being used for fraud or identity theft, have been advised to file a police report.
Florian Hauer, the city’s top IT official and state secretary for digital affairs, sent staff an internal warning cautioning them against contact attempts by the hackers or people posing as legitimate contacts, including messages that may be AI generated. He urged employees to remain extremely vigilant in the coming period and to double check the identity of anyone reaching out, whether the request appears to come from citizens, partner companies, government agencies, service providers, or supervisors. Staff who receive ransom demands or threats directly, he added, should under no circumstances respond, and should instead report the contact to police and the Senate Chancellery. A dedicated contact point has been set up for employees, along with access to an outside legal advisor for confidential or legally sensitive matters.
A Political Dimension, Too
Germany’s Federal Office for Information Security, known by its German acronym BSI, has weighed in as well, warning that the publication of stolen data of this kind creates risks both for those directly affected and for society more broadly. It flagged a heightened threat of targeted phishing attempts in the aftermath and noted that anyone in contact with affected individuals or institutions should be especially alert.
The timing has added a political layer to the story. Berlin is due to elect a new House of Representatives on September 20th, and the BSI pointed to the risk of so-called hack-and-leak operations, in which stolen material is released at a moment chosen to benefit the attacker, sometimes stripped of context or reframed to mislead. Even so, the agency said it currently sees no sign of a political motive behind this particular attack and believes it was driven purely by financial gain.
Reaction from Berlin’s political scene has been sharp. Tobias Schulze, who leads the Left Party’s parliamentary group, called the outcome about as unfavorable as it could be, since anyone with modest technical know-how can now access the material. He urged the Senate to move quickly to confirm which prior assumptions about the leak hold up, notify everyone affected, and offer the best support it can.
Green Party lead candidate Werner Graf said Berlin was right not to be extorted, but warned that the leaked passwords, account information, and personal details of tens of thousands of Berliners and state employees could fuel identity theft and targeted phishing campaigns. He called for concrete support for those affected, including a simple way for people to check whether their own data was part of the leak, alongside a joint awareness campaign involving the Senate, the data protection authority, consumer groups, and security agencies. Berlin’s police union was blunter still, with regional deputy chief Thorsten Schleheider saying the episode shows years of neglect and that simply telling staff to change their passwords amounts to a limited and somewhat helpless response.
Background
The intrusion, which came to light on August 14th, hit the Senate departments for construction and transport. Rhysida claims to have first gained undetected access to the networks between August 7th and 12th and to have made off with roughly 5.7 terabytes of data containing extensive personal information. The group put the material up for sale on a dark web auction site the previous Friday, complete with a countdown clock, before releasing it in full once the ransom deadline expired unpaid.
Investigators from Berlin’s state criminal police office and Germany’s Federal Office for Information Security remain involved in analyzing the incident and assessing the damage. Officials say they have so far found no evidence that the state’s network remains compromised, though forensic work is ongoing, including efforts to determine whether additional data may have been taken. and southern Europe, Germany and the United States in recent years. There is no evidence of ties to Russia or the Russian state, though such ties cannot be ruled out either, the Senate said.
