Berlin administration faces political fallout after hackers leak 5.8 terabytes of city data
The Rhysida ransomware group released 1.44 million administrative files on the darknet after the Berlin Senate refused a 30-Bitcoin ransom demand, prompting calls for resignations ahead of state elections.
Infiltration and extortion demand
Between 7 August and 12 August 2026, cybercriminals penetrated the Berlin state administrative network, exfiltrating 5.8 terabytes across 1.44 million files. The intrusion affected the Senate Department for Urban Development and Building as well as the Senate Department for Transport. Officials detected the breach on 14 August and announced it publicly three days later, temporarily disconnecting both affected departments from the central IT network for about a week. The ransomware group Rhysida, previously known as Vice Society, demanded a ransom of 30 Bitcoins, valued at approximately two million euros. After the Berlin Senate refused to pay the ransom, the group published the stolen data on the darknet on Friday afternoon, followed by a second data release on Sunday evening.
| Aug 7 | Hackers infiltrate Berlin state administrative network |
|---|---|
| Aug 14 | Berlin officials discover unauthorised network activity |
| Aug 17 | Administration discloses breach and disconnects two departments |
| Sep 4 15:35 | Rhysida publishes first leak of 1.44 million files on darknet |
| Sep 6 | Hackers release a second data package on darknet |
| Sep 7 | State Secretary Florian Hauer briefs the parliamentary interior committee |
Scope and security assessment of leaked records
State Secretary for Digital Affairs Florian Hauer briefed the Berlin parliamentary interior committee on 7 September 2026 regarding the ongoing review of the breach. He noted that the volume of exfiltrated material substantially exceeded initial estimates.
What was actually exfiltrated, we have only known for certain since Friday at 3:35 p.m. Until Friday, the information we had was the index that the perpetrators had posted on the darknet.
Initial Senate assessments had estimated the compromise at a maximum of 215,000 records before the full 1.44 million files appeared online. Hauer stated that the stolen files carry at most the lowest confidentiality classification, designated as restricted for official use (VS-NfD). He reported that references to the Military Counterintelligence Service (MAD) involved routine parking permits rather than sensitive defense intelligence. However, reports indicated the published archives include personal employee details, emergency plans, contracts, and municipal infrastructure files concerning power plants, substations, and water utilities.
| files | |
|---|---|
| Initial Senate estimate | 215000 |
| Files leaked on darknet | 1440000 |
Political fallout before state elections
The disclosure occurred two weeks prior to the scheduled Berlin state parliament elections, generating immediate political friction. Berlin's Free Democratic Party (FDP) demanded the resignations of Governing Mayor Kai Wegner and Interior Senator Iris Spranger, asserting that the administration failed to maintain basic IT safeguards. FDP lead candidate Christoph Meyer called for a formal parliamentary committee of inquiry into administrative handling. The Left Party and the Greens submitted a motion for an urgent debate on administrative IT security failures at Thursday's parliamentary session. Berlin Economics Senator Franziska Giffey publicly urged Wegner to take active charge of the response.
Then you have to be there in a crisis.
Technical scrutiny and crisis management critique
The State Criminal Police Office (LKA) and cybersecurity specialists are reviewing the files using artificial intelligence to catalog confidential materials. Officials stated that downloading and indexing the complete 5.8 terabytes will take several days, while comprehensive analysis will extend over weeks. Chaos Computer Club spokesperson Joachim Selzer criticized the administration's technical reaction, pointing out that credentials published in preliminary leaks remained valid on municipal systems days after disclosure.
What we need now, above all, is maximum transparency in the investigation. That means standing up in public and explaining exactly what went wrong.
Hauer acknowledged that upcoming audits will likely expose structural IT deficits that developed over several years, requiring dedicated funding allocations in the state budget to harden administrative infrastructure.
Sources
- Ransomware-Gruppe Rhysida: Wer steckt hinter der Erpressung und dem Datenleck
Süddeutsche Zeitung · Sep 7 - Hackerangriff auf Berlin: Kritik am Krisenmanagement nach Hackerangriff in Berlin
ZEIT ONLINE · Sep 7 - Zwei Wochen vor Berlin-Wahl 2026: Fragen und Antworten zu dem Hackerangriff
Frankfurter Allgemeine · Sep 7 - Hackerangriff auf die Berliner Verwaltung: Sichtung gestohlener Daten wird noch Wochen dauern
Der Tagesspiegel · Sep 7 - Keine hochsensiblen Daten dabei: Berliner Senat gibt nach Hackerangriff Entwarnung
N-tv · Sep 7 - Berlin & Brandenburg: Experten kritisieren Krisenmanagement bei IT-Leak in Berlin
N-tv · Sep 7 - Experte nach Berliner Hacker-Angriff: Prüfen Sie unbekannte Mails und Anrufe besonders kritisch
Focus · Sep 7 - Hackerangriff auf Berliner Verwaltung: Hacker erbeuteten wohl keine hochsensiblen Daten in Berlin
ZEIT ONLINE · Sep 7