A ransomware operation against the Berlin state administration has escalated into one of the largest public-sector data breaches in recent German history. On Friday the criminal group Rhysida released 1.44 million files totalling 5.8 terabytes on the Darknet, roughly two weeks before voters head to the polls for the Abgeordnetenhaus election.
The gang had infiltrated the network in mid-August, extracted the data without detection and demanded 30 bitcoin, approximately two million euro, for its return. The Senate, led by the CDU's Kai Wegner in coalition with the SPD, refused to pay. The publication followed.
What the leak contains
According to reporting by the Tagesspiegel and confirmed by independent experts, the dump mixes routine personal records with material classified under Germany's secret-protection regime. Jochim Selzer, spokesperson for the Chaos Computer Club, examined a sample and found unredacted scanned passports, employment contracts, job applications and sick notes. He also located sensitive technical data on Berlin's water supply.
Beyond personal data, the leak reportedly includes documents on heating plants, fuel storage facilities, emergency power systems, substations, prisons, waterworks, arms manufacturers, Bundeswehr sites and the interior administration's defence-related holdings. A federal government spokesman acknowledged the publication and said authorities are continuously cross-referencing information to assess military-security risks, adding that federal data systems are not believed to be affected.
Warnings ignored for years
Manuel Atug, founder of the critical-infrastructure working group AG Kritis, has been among the sharpest critics. He told the Deutsche Presse-Agentur that Berlin acted with 'gross negligence' and deliberately disregarded secret-protection requirements. Atug appeared before the capital's interior committee as an expert witness in 2023 and again in 2025, warning each time that the city's cybersecurity processes were desolate and that neglect would have severe consequences. 'Exactly that has now occurred,' he said.
The secret-protection regulations (Geheimschutzvorgaben) mandate strict handling procedures for classified material, including graded security levels, access controls and encryption. Atug's contention is that these rules existed but were not applied to the systems Rhysida compromised.
Political fallout before the election
With the Abgeordnetenhaus election scheduled for 22 September, opposition parties have seized on the breach. The Left's lead candidate Elif Eralp called it a 'stark government failure by the CDU' and demanded the Senate declare a 'Großschadenslage', a major-damage situation that would unlock emergency powers and resources. The AfD's Kristin Brinker demanded immediate and comprehensive clarification. The Greens' Werner Graf criticised the absence of any visible plan to protect and warn affected individuals or to reorganise security. 'The week passed without recognisable precautions. That is a scandal,' he said.
SPD mayoral candidate Steffen Krach advocated a massive expansion of IT security and cyber defence. The FDP's Christoph Meyer went further, calling for the resignations of Wegner and Interior Senator Iris Spranger. 'In this Senate everyone seems to cling to their office while grave errors remain without consequence,' Meyer said.
The ransomware group and its methods
Rhysida operates as a ransomware-as-a-service outfit, known for targeting healthcare, education and government sectors across Europe and the Americas. The group typically uses phishing and valid credential abuse to gain initial access, then moves laterally before exfiltrating data and deploying encryption. The 30-bitcoin demand fits their established pattern of calibrating ransoms to the victim's perceived ability to pay. Berlin's refusal to pay aligns with the German government's longstanding policy against rewarding extortion, though the decision inevitably triggers publication.
Technical challenges in assessing the damage
Selzer noted that the Darknet site organises the material into three sub-pages, each with a navigable file tree. The sheer volume, 5.8 terabytes, makes systematic review extremely difficult; simple keyword searches are impractical. This means the full scope of exposed secrets, particularly regarding critical infrastructure and defence installations, may not be known for weeks. Atug, citing ethical reasons, has declined to view the data himself but says reliable sources confirm the Tagesspiegel's reporting on civil-protection and arms-industry documents.
People mentioned
-
Manuel Atug
-
Kai Wegner
-
Jochim Selzer
Organisations
Senate of Berlin · AG Kritis · Chaos Computer Club · Rhysida · Bundeswehr · Federal Government of Germany