# National security risk: Berlin data leak causes major repercussions

> Source: <https://www.heise.de/en/news/National-security-risk-Berlin-data-leak-causes-major-repercussions-11444364.html>
> Published: 2026-09-07 23:05:27+00:00

# National security risk: Berlin data leak causes major repercussions

After the darknet leak, districts argue about Crowdstrike’s forensics software. The data protection officer warns and issues guidelines for those affected.

The recent cyberattack on the Berlin state network has escalated into a security debacle. The allegedly Russian-speaking ransomware group Rhysida extorted the state for 30 Bitcoin (around two million euros). After the deadline expired, the group published a data package of approximately 5.7 terabytes with around 1.44 million files in the darknet. Among the leaked data are personnel files, contracts, and passwords of administrative employees, as well as information about citizens. However, the outflow of highly sensitive security documents is likely to be even more alarming.

The leak includes emergency and protection concepts for civil defense, documents on barracks, and detailed plans for critical infrastructures such as water and heating plants, transformer substations, emergency power systems, and armaments factories. Even blueprints of correctional facilities are now publicly accessible.

The Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and Environment are primarily affected. They operate their own IT structures and are not directly managed by the central IT service center (ITDZ).

### National Dimension

Since confidential documents from the Bundeswehr and the federal government are also affected, federal authorities are now getting involved. The Bundeswehr’s Operational Command, the National Cyber Defense Center, and the Federal Office for Information Security (BSI) are currently examining the security risks and have released initial analysis results.

Videos by heise

”This data outflow is of a serious magnitude and endangers our national security“, CDU defense politician Roderich Kiesewetter summarizes the extent to the Süddeutsche Zeitung. The fact that plans for total defense were circulating in the darknet and are openly available to opposing secret services is very serious. Anyone who wants to make total defense resilient must “imperatively raise digital defense and secret protection at all federal interfaces to the same high-security level”.

- **August 7 to 12, 2026** : Data was exfiltrated by unknown parties from the two Senate administrations for Urban Development, Building and Housing, and for Mobility, Transport, Climate Protection and Environment. The attack began long before this date.
- **August 14, 2026:** The two Senate administrations are isolated from the state network.
- **August 17, 2026:** The Senate Chancellery informs via press release about an "ICT incident in the state network Berlin". An emergency crisis team is set up, the BKA and LKA are investigating, and the BSI is informed.
- **August 21, 2026** : The two authorities remain disconnected from the state network. There are problems with transfer payments, including the inability to pay housing benefits to 50,000 eligible households in Berlin.
- **August 24, 2026** : All parts of the Senate administration are back online and, according to Governing Mayor Kai Wegner, "fundamentally operational".
- **August 27, 2026:** Florian Hauer, Berlin State Secretary for Digitalization, explains: "We currently assume that the attack could be contained." He cannot rule out that "personal or other non-public data are also affected."
- **August 28, 2026:** Security authorities meet with representatives of the state of Berlin for a crisis meeting. The attackers have stolen data and are demanding a ransom. Governing Mayor Kai Wegner states: "The state of Berlin will not be blackmailed." There is no information on the scope and content of the data. In the evening, Der Spiegel reports that the well-known ransomware group "Rhysida" is suspected to be behind it. On their darknet website, there is a verifiable demand for 30 Bitcoin (around 2 million euros), along with alleged excerpts from the data. The criminals promise, among other things, lists of plaintext passwords, judicial documents, and over 46,500 state contracts.
- **August 30, 2026:** CCC spokesman Joachim Selzer warns of possible identity theft and other fraud attempts. Citizens whose personal data may be included in the alleged dataset would also easily fall victim to extortion attempts.
- **September 1, 2026:** At a press conference, the Senate administration confirms that passwords have also been exfiltrated. Employees of the two administrations can therefore currently not work from home. All 12,000 systems of the state of Berlin are currently being checked "around the clock".
- **September 4, 2026:** The criminals publish around 1.44 million files in the darknet. These include personnel records, information on disciplinary proceedings, financial documents, and details about the critical infrastructure of the state of Berlin.
- **September 5, 2026:** The BSI warns of an "increased threat situation" for society.
- **September 6, 2026:** The state of Berlin establishes a "steering unit". Those affected by the leak are to be contacted by email and letter. Politicians and IT experts are shocked by the scope and content of the published data.

Meanwhile, tensions are arising in the remedial measures taken by Berlin’s politicians. The Senate Chancellery engaged the controversial US security company CrowdStrike for IT forensic investigation. However, the Lichtenberg district refuses to use the Falcon Agent software on its own servers. In an internal memo, it refers, according to rbb, to concerns about almost unlimited data access, possible disruptions to specialized applications, and remaining surveillance risks for service employees. Lichtenberg sees no signs of intrusion on its systems so far and is pushing for full assumption of responsibility and costs by the Senate.

### Citizen Tips and Concern about Patchwork

The Berlin Commissioner for Data Protection, Meike Kamp, and the security authorities advise potentially affected individuals to be vigilant. They recommend changing passwords, closely monitoring account activity, and being skeptical of phishing emails. In case of concrete threats or evidence of published personal data in the darknet, the police should be contacted immediately.

The Cyberintelligence Institute (CII) calls for a factual and forward-looking review. “It would be short-sighted to treat the incident solely as a Berlin problem,” emphasizes its scientific director Dennis-Kenji Kipker. A similar attack could have affected almost any other major German city with comparably serious consequences. This is also because the current cybersecurity architecture at the state and local level still resembles a patchwork with unclear responsibilities.

The CII therefore calls for a nationwide immediate action program for municipal cyber resilience to establish binding security standards, appoint independent information security officers, and deploy trained administrative teams across the board.

([wpl](mailto:wpl@heise.de))
