A cybercriminal group has dumped 1.4 million files stolen from Berlin's city government onto the dark web after the Senate refused a ransom demand of 30 bitcoins, worth roughly €2 million at current rates. The breach, which went largely unnoticed during the Saxony-Anhalt state election on 6 September, exposes personal data of employees and citizens alongside technical details of critical infrastructure serving the capital's four million residents.
How the attackers got in
Rhysida, a ransomware operation believed to originate in eastern Europe, gained a foothold between 7 and 14 August when an employee at the Berlin Transportation Authority opened a malicious attachment in a phishing email. That single click gave the group access to the state government's secure fibre-optic network, which connects roughly 600 locations from municipal offices to senate departments. The intrusion went undetected for weeks.
Since emerging in 2023, Rhysida has claimed nearly 280 attacks worldwide, predominantly targeting public institutions in the United States. The Berlin operation marks one of its most high-profile European intrusions to date. The group's modus operandi is consistent: initial access via phishing or vulnerable remote services, lateral movement, data exfiltration, then a ransom demand with a threat to publish.
What the data contains
The leaked dataset spans two major departments, Public Works and Transportation, and includes employee files, official correspondence, pay slips and scanned identity documents. More alarmingly, it also covers technical specifications for combined heat and power plants, fuel storage facilities, emergency power systems, prisons and water treatment plants. Jochim Selzer of the Chaos Computer Club told the Frankfurter Allgemeine that even on the hard-to-access dark web, such granular personal and infrastructure data enables convincing impersonation and targeted fraud.
Political fallout and institutional response
Governing Mayor Kai Wegner announced on 5 September that Berlin would not negotiate. "The State of Berlin will not give in to blackmail," he said. The data appeared online shortly after. The Senate has since instructed all employees to change passwords, established a cross-agency coordination office and engaged the Federal Office for Information Security (BSI) in Bonn.
That password reset order triggered sharp criticism from Thorsten Schleheider, vice-chairman of Berlin's police union. He argued that the breach reveals years of systemic underinvestment in cyber defences and that many staff have never received adequate security awareness training. "It is unthinkable that highly sensitive data was compromised for days, and the only action taken appears to be instructing employees to change their passwords," he said.
Election security held, but wider questions remain
State Election Commissioner Stephan Bröchler moved quickly to reassure voters. He told the Bild tabloid that all systems and processes for the Berlin state parliamentary election on 20 September remain unaffected, including preparations, election day operations and the publication of preliminary results. The isolation of election infrastructure from the compromised administrative network appears to have held.
The stolen files also contain details of the controversial expansion of the Federal Chancellery in central Berlin, indirectly implicating Chancellor Friedrich Merz's office. While the Chancellery itself was not breached, the presence of federal project data on a city government network underscores the interconnectedness of administrative systems across levels of government.
What happens next
The coordination office must now identify every individual whose data appears in the leak, notify them under GDPR obligations and assess the infrastructure exposure. The BSI will conduct a forensic review of the intrusion timeline and lateral movement. Meanwhile, Rhysida's publication of the data removes any leverage for future negotiation but creates a permanent resource for fraudsters. The Senate's next budget cycle will be the real test of whether Schleheider's criticism translates into sustained investment in segmentation, monitoring and mandatory staff training, or whether the password reset remains the only visible response.
People mentioned
-
Thorsten Schleheider
-
Stephan Bröchler
Organisations
Berlin Senate · Rhysida · Federal Office for Information Security · Chaos Computer Club · Berlin Police Union · Berlin Transportation Authority