A ransomware gang has published 5.7 terabytes of sensitive data stolen from the Berlin state government network, exposing critical infrastructure plans and personal employee records. The leak appeared on the dark net this week after the attackers, identified as the Russian-speaking group Rhysida, saw their ransom deadline pass without payment. The breach represents one of the most significant compromises of German state-level data in recent years, triggering a federal security response.

The stolen package contains approximately 1.44 million files. While initial reports focused on administrative data, deeper analysis reveals detailed security concepts for civil defence and military installations. The exposure extends beyond bureaucratic inconvenience into the realm of physical security, with blueprints for prisons and substations now publicly accessible to hostile actors.

Critical infrastructure at risk

The most damaging element of the leak involves emergency and protection concepts for essential services. Documents cover water and heating power plants, electrical substations and backup power systems. In a modern city, these systems are interdependent. A failure in the heating grid can cascade into power shortages, and vice versa. Having the defensive plans for these nodes public allows adversaries to identify single points of failure.

Armaments facilities and military barracks are also included in the dataset. This crosses a threshold from local criminality to national security concern. The Bundeswehr, Germany's armed forces, has joined the investigation alongside the National Cyber Defence Centre and the Federal Office for Information Security (BSI). Their involvement signals that Berlin is no longer treating this as a municipal IT failure but as a potential act of hybrid warfare.

Federal authorities intervene

Under Germany's federal system, internal security is primarily a state responsibility. However, when classified defence papers are compromised, the federal government retains jurisdiction. The presence of confidential Bundeswehr documents within a state network suggests a level of data sharing or storage that may now face scrutiny. It raises questions about how military secrets were housed on a network vulnerable to ransomware.

Federal agencies are now conducting a joint investigation. This centralisation of response is unusual for a city-level breach but necessary given the scope. The BSI is assessing whether the vulnerability was technical or procedural. If the latter, remediation requires changing workflows across multiple departments, a process that often meets resistance from civil servants accustomed to legacy systems.

The CrowdStrike controversy

To investigate the breach, the Berlin Senate Chancellery engaged CrowdStrike, a US-based cybersecurity firm. This decision has sparked debate over digital sovereignty. Relying on American forensic tools to analyse a breach potentially linked to Russian actors introduces a third party into a sensitive national security incident. Critics argue that European states should develop indigenous capabilities for such high-stakes forensics.

CrowdStrike is a market leader, but its dominance creates dependency. If the forensic data itself is processed on US servers, it could theoretically be subject to American intelligence laws. For a breach involving German defence concepts, this creates a paradox where fixing the security hole might create another. The debate mirrors wider European concerns about reliance on non-EU technology providers for critical state functions.

Regulatory implications

The incident tests the European Union's cybersecurity framework. The NIS2 Directive, which member states are currently transposing into national law, imposes stricter reporting and security requirements on essential entities. Berlin's administration clearly falls into this category. Regulators will examine whether the state met the required due diligence standards before the attack. European cybersecurity strategy documents emphasise resilience, but implementation remains uneven across member states.

Meike Kamp, the Berlin Data Protection Commissioner, has advised affected employees and citizens to remain vigilant. Personal files, contracts and passwords were among the leaked materials. This creates immediate risks of identity theft and phishing attacks targeting state workers. The human cost of the breach will likely outlast the technical remediation, as leaked passwords can be used for years.

Next steps for Berlin

The immediate priority is containment. Berlin must assume all leaked credentials are compromised and force resets across the administration. However, the long-term challenge is architectural. The state network needs segmentation to ensure that a breach in administrative email does not expose defence blueprints. This requires investment that competes with other budgetary demands in a cash-strapped city.

Political accountability will follow. Opposition parties are likely to demand explanations for how such a volume of data was exfiltrated without detection. The use of US forensic tools will also face parliamentary scrutiny. For now, the focus remains on damage limitation, but the structural weaknesses exposed here are not unique to Berlin.

People mentioned

  • Meike Kamp

    Berlin Data Protection Commissioner, Berlin State Government

Organisations

CrowdStrike · Bundeswehr · National Cyber Defence Centre · Federal Office for Information Security