Berlin’s worst data leak just ended up on the dark web – of how secure is Germany’s IT-infrastructure, really?
In a never-seen-before data breach more than 1.44 million sensitive documents of Berlin’s administration have been put on the dark web. And that only just a few days before elections are held in the capital. Find out what we have to learn from this!
What happended?
Between August 7 and August 12 2026, hackers gained unnoticed access to the IT-systems of Berlin’s administration, as a forensic investigation later revealed. On August 14, the administration noticed the attack and three days later the Press and Information Office of the State in Berlin publicly confirmed the cyber attack and described it as an “extremely serious crime”, moreover, an attack on the state itself.
The Berlin data breach is not an isolated case nor will it be the last one in Germany as the country’s Federal Minister of Interior, Alexander Dobrindt, stated in June that Germany is a daily target of hybrid warfare with cyber attacks being “shadow wars of the 21st century”. This only further underlines that Germany’s digital infrastructure must be prepared and secured for the future. And the future is now.
The systems that have been targeted in the recent Berlin data breach primarily include the infrastructure of the Senate Department for Mobility, Transport, Climate Protection and the Environment as well as systems of the Senate Department for Urban Development, Construction and Housing. As a result of the attack, some of Berlin’s online systems were forced to even close down for a couple of days, leaving citizens unable to apply for “housing allowance” (Wohngeld), for example.
A hacker group called “Rhysida” claimed responsibility for the data breach and used it to blackmail the administration. The group put the 5.79 terabytes up for auction, starting with a price of 30 bitcoin (about $2.4 million). The Berlin government responded to the blackmailers by refusing to pay the ransom, stating that “the State of Berlin will not give in to blackmail.”
Just shortly after the countdown ended, as threatened by the hacker group, around 1.4 million sensitive documents and 5.7 terabytes of data were released on the dark web.
Note: One terabyte equals 1000 gigabytes.
The stolen and leaked data
The stolen and leaked data contains 1.44 million documents and 5.79 terabytes of data.
The stolen data includes deeply personal data of around 5.000 civil servants of Berlin’s administration such as scanned passports, job contracts, sick notes, sensitive payroll documentation and fine records.
Moreover, the 5.7 terabytes of leaked data include information about internal reports from parliamentary committees and critical infrastructure intelligence – including vulnerability assessments for Berlin’s water supply systems. Even information about the construction project of the “Bundeskanzleramt” is among the leaked data.
And if that’s not enough, the hackers managed to steal emails, phone numbers and even plain passwords that have been labeled as classified information, leading to all of the 12000 digital systems of the State of Berlin being reviewed again to harden them against potential follow-up attacks.
In other words, not only is this data breach a sign that the IT security measurements of Berlin’s digital infrastructure are not strong enough, but it also holds the potential of threatening the public safety. Moreover, the leak of sensitive personal data also increases the risk of identity theft.
If you’re not sure whether your account has been hacked, follow our guide to learn how you can tell if your acount has been hacked.
The hacker group
A hacker group named “Rhysida” claimed responsibility for the cyber attack and first emerged in 2023. The group has become a well-known ransomware operation and is linked to various hacking attacks against public and private organisations with more than 300 violations being attributed to it. Among the most well-known victims of this hacking group are the British Library and Insomniac Games.
The timing
Although the investigators so far assume a solely financial interest in the hacking attack and not a political one, the timing of the attack has a certain aftertaste. Because just in a few days Berlin elects its new House of Representatives (Abgeordnetenhaus) on September 20. However, officials state that the systems of the election have not been breached and are secure.
Cyber attacks shortly before an election are not unusual as there is a higher risk of those so-called “hack-and-leak” operations during which stolen documents are published as the timing may be advantageous. Hence, the BSI warns for potential phishing attacks, especially now.
Related: Find more information about how you can prevent email phishing attacks.
What now?
The recent data leak of Berlin’s administration was a shock. An attack of this size on Germany’s administration is unprecedented. But if this attack has once again made one thing clear to us, then it is this: the threat on our digital infrastructure is real. And not only is it real but the threat is now and not in some unknown time in the future.
Security experts have warned for a long time about serious security gaps in Berlin’s IT infrastructure. Especially, communities and municipalities are prone to cyber attacks but unfortunately often lack the budget of hiring enough qualified IT-security personnel to properly secure their systems. In addition to this, the response of a German administration to this leak cannot and must not be to close down its systems for a couple of days and ask its staff to please change their password.
Luckily, the answer to the question “What now?” may be simpler than many would believe Digital sovereignty. The German state is for far too long dependent on non-European services, especially on MS365 in its administrations. And what kind of security risks this dependency on Microsoft can contain has showed us the case of the Chief Prosecutor of the International Criminal Court in Den Haag when its Microsoft mail account was suspended after Trump ordered the tech giant to do so.
As of now, the state of Germany is not digitally sovereign, however some federal states have taken first steps and, thus, proven that if there is enough political will, it is possible to become independent from Big Tech. Because to continue using US-American Big Tech companies for its digital infrastructure means that a lot of sensitive data is stored on US servers - and the US CLOUD Act allows US authorities to request data from American companies whether the data is stored in the US or abroad.
Final thoughts
The Berlin data leak is an unprecedented attack on the IT infrastructure of Germany’s capital and causes serious security risks, not only for individuals, but also for the public security. However, if we can take something positive from this then it is this: the time to properly invest in the security of Germany’s digital infrastructure is now. Moreover, some federal states in Germany have already proven that it is possible to become digitally sovereign. If there’s enough political will, there’s a way.
Together, we can build a brighter future!