< Back to situation

[REVISION HISTORY]

Berlin administration cyberattack and data breach

Updated 8 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-08 08:49 UTC → 2026-09-08 12:27 UTC · added removed

The Berlin state administration was targeted by a major cyberattack involving the Rhysida ransomware group. Following a breach occurring between August 7 and August 12, 2026, the group demanded a ransom of 30 bitcoins, valued at approximately 2 million euros, threatening to release stolen data. Berlin Mayor Kai Wegner and Interior Senator Iris Spranger stated that the city would not pay the extortion demand. Following the refusal to pay, the Rhysida group published approximately 5.8 terabytes of stolen data, comprising 1.44 million files, onto the Darknet. The breach specifically targeted the Senate Departments for Building and Transport. Transport after hackers gained access to the Berliner Landesnetz. The compromised information includes personal records such as medical files, employment contracts, and scanned passports, as well as administrative employee data like employment certificates and emergency plans. Furthermore, the leak includes sensitive information regarding critical infrastructure, such as power plants, water supply, and emergency energy systems. There are also concerns that the leak The dataset reportedly contains documents related to civil protection, defense, vulnerability assessments for Berlin’s water supply and the Bundeswehr. plans for chemical, biological, radiological, and nuclear (CBRN) threat scenarios. While officials stated that no data classified for national security was compromised, experts and political leaders have warned that the breach poses a threat. The dataset reportedly contains vulnerability assessments for Berlin’s water supply and plans for chemical, biological, radiological, and nuclear (CBRN) threat scenarios. Green Party official Konstantin von Notz described the event as a ‘real data super-disaster’, while Roderich Kiesewetter warned that the leaked data could be exploited by terrorists or foreign states for sabotage. In response, the Senate Department for Urban Development, Building, and Housing has moved to tighten security measures. Investigations are being led by the BSI, BKA, and BfV. Recent criticisms from the Chaos Computer Club have highlighted failures in crisis management, alleging that a delay in disconnecting affected systems allowed attackers were able a seven-day window to continue testing systems even after initial leaks were detected. extracting data.

Versions

  1. 2026-09-08 12:27 UTC Berlin administration cyberattack and data breach
  2. 2026-09-08 08:49 UTC Berlin administration cyberattack and data breach
  3. 2026-09-07 22:47 UTC Berlin administration cyberattack and data breach
  4. 2026-09-07 11:42 UTC Berlin administration cyberattack and data breach
  5. 2026-09-07 05:02 UTC Berlin administration cyberattack and data breach
  6. 2026-09-06 18:02 UTC Berlin administration cyberattack and data breach
  7. 2026-09-06 18:00 UTC Berlin administration cyberattack and data breach
  8. 2026-09-06 14:59 UTC Berlin administration cyberattack and data breach
  9. 2026-09-06 13:55 UTC Berlin administration cyberattack and data breach

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.