Berlin faces one of the largest data breaches to affect its administration. After the authorities refused to pay a ransom of around 2 million euros, the cybercrime group Rhysida published on the dark web about 1.44 million files representing nearly 5.8 terabytes of data. Initial analyses reveal not only personal information concerning public officials, but also documents related to critical infrastructure, to defense and to the expansion of the Federal Chancellery.
The exact scale of the breach remains under evaluation. German authorities have set up a central incident response unit tasked with sifting through the files, identifying the most sensitive data, and gradually informing individuals, companies and institutions affected.
The Essentials
1.44 million files: the hackers published on the dark web nearly 5.8 terabytes of data stolen from the Berlin administration.
Ransom refused: the Rhysida group demanded around 30 bitcoins, approximately 2 million euros.
Sensitive data: identity documents, payroll records, banking information, personnel files, and administrative documents are among the identified files.
Infrastructure affected: some documents pertain to energy installations, water supply, prisons and other sensitive sites.
German Chancellery: more than 550 files are believed to relate to the expansion project of the federal government’s headquarters.
5.8 terabytes of data stolen in a matter of days
According to the findings now established, the attackers gained access to certain parts of the Berlin state IT network between 7 and 12 August 2026, without being immediately detected.
Two administrations were mainly affected: the one in charge of urban planning, construction and housing, and the one responsible for mobility, transport, climate and the environment.
The attack was detected on 14 August. The two administrations were then isolated from the Berlin network as a security measure. The incident was made public only three days later. They were reconnected to the network on 23 August, after several days of investigations and security measures.
Rhysida subsequently claimed to have stolen about 5.7 to 5.8 terabytes of data. The group put the files up for auction with a minimum bid set at 30 bitcoins, roughly 2 million euros according to Berlin authorities.
Berlin’s Governing Mayor Kai Wegner, and Interior Senator Iris Spranger had publicly announced that the capital would not bow to blackmail.
After the ultimatum expired on September 4, the data were made accessible on the dark web.
Personnel files, identity documents and payroll records
The contents of the breach are only beginning to be identified.
According to early checks by Rundfunk Berlin-Brandenburg (rbb), the published files include notably elements of personnel files, digitized identity documents, payroll records, work certificates and contractual documents.
The Chaos Computer Club, whose experts examined part of the data, also notes information related to individual personnel matters and emergency plans of several administrations.
This information can pose a direct risk to those concerned. Identity data linked to professional, administrative or financial information can be used for identity theft attempts or highly credible frauds.
Power plants, fuel depots and electrical substations
The breach takes on another dimension with documents concerning sensitive infrastructure.
According to information reported by the German press, the published data would contain information about sites requiring special protection, notably power plants, fuel depots, backup electricity installations and electrical substations.
Documents concerning prisons, water distribution installations and defense-sector companies would also be part of the published set.
Data related to the Bundeswehr and to the Berlin Interior Administration, particularly on defense-related matters, would also have been exposed.
At this stage, these details come from the examination of the files by several media outlets and experts. German authorities have not yet publicly validated the entire list nor determined the sensitivity level of each document.
More than 550 files relating to the expansion of the chancellery
Among the most sensitive elements identified would also be documents concerning the expansion project of the federal chancellery in Berlin.
According to reports in the German press, more than 550 files would be related to this project.
They would include notably expert reports, plans and administrative positions, some originating from the Berlin criminal police.
The possible presence of technical or security-related information linked to a major government building explains why federal authorities are now directly participating in the analysis of the breach.
The federal government has indicated that it is checking its own systems. As of now, those systems would not appear to be directly compromised by the cyber intrusion.
Sensitive information on water supply
The Chaos Computer Club also claims to have identified in the published files sensitive information regarding the state of Berlin’s water supply.
The exact nature of these details has not been made public, which helps prevent further elements that could pose risks from being disseminated.
The German Federal Office for Information Security (BSI) warns that a leak concerning critical infrastructures can go far beyond personal data protection. If the sensitive documents identified are authentic and still operationally relevant, they could theoretically interest criminal groups, terrorist organizations, or foreign services.
What the published files would contain
• Digitized identity documents and personal data of public officials.
• Payroll records, banking information and HR-related documents.
• Emergency plans and internal procedures of several administrations.
• Information related to power plants, fuel depots and electrical substations.
• Documents concerning prisons, water supply installations and defense sector companies.
• Information related to the Bundeswehr and to certain security-related files.
• More than 550 files related to the expansion of the federal chancellery, including expert reports, plans and administrative documents.
Citizens and businesses could also be affected
The breach does not appear to be limited to civil servants.
Even before the publication of the files, the Berlin government warned that the stolen data could include personal information about administrative staff, but also citizens and businesses who interacted with the relevant services.
Authorities now plan to contact those identified as analysis progresses, prioritizing cases with the highest risk.
Berlin urges individuals who discover that their data has been exposed or used for fraud or identity theft to file a police report.
Increased risk of phishing and identity theft
Beyond privacy concerns, the immediate risk for individuals lies in the fraudulent use of the data.
The BSI warns of a possible rise in targeted phishing campaigns. Perpetrators may have enough real information about their victims to craft emails, phone calls or payment requests far more convincing than typical fraud attempts.
The Chaos Computer Club also highlights the risk of identity theft: the more precise information a criminal possesses about a person, the more likely they are to impersonate them to a bank, an administration, or a service provider.
Why Berlin refused to pay: Mayor Kai Wegner defended the refusal to give in to blackmail, noting that no payment could guarantee the destruction of the stolen data. Even after paying a ransom, attackers could keep copies or resell them later.
The cyberattack had already disrupted housing benefits
The attack had concrete consequences even before the data was published.
The shutdown of the two Berlin administrations on the network had disrupted the processing of housing benefit applications and payments, as well as certain services of the German education and participation program for children and adolescents.
In some districts, the road maintenance and green spaces offices could no longer process driving permits, requests for special occupancy of public space or exemptions to traffic regulations.
In Reinickendorf, the backlog of unresolved cases even led the housing assistance service to limit its operations from August 25 to September 4 to address delays.
A central unit created in Berlin
Since the publication of the files, the Berlin Senate Chancellery has created a central coordination unit led by Florian Hauer, head of the city-state’s digital transformation.
It brings together Berlin’s criminal police, the two affected administrations, the Berlin Data Protection Authority, IT security leads, and other security agencies.
Its task is to prioritize identifying files that could threaten people, sensitive infrastructures, or public institutions, and then take the necessary measures.
Berlin describes the attack as a “very serious crime” and an attack against the Land itself.
Rhysida, a group already known to authorities
Rhysida is not an unknown actor.
German authorities regard it as a cybercriminal group primarily motivated by money. Its modus operandi relies on mass data theft, followed by a ransom demand and the threat to publish the files if refused.
The group had notably claimed the cyberattack against the British Library in London in October 2023. This attack led to data exfiltration, destruction or encryption of a significant portion of the library’s IT systems and a prolonged disruption of many library services.
The British Library confirmed that a portion of the stolen personal information was later published on the dark web.
Why this breach can remain dangerous for a long time
Identity theft: a copy of an identity document linked to an address, an employer or banking data can facilitate certain frauds.
Targeted phishing: attackers can use real personal information to make fake emails, calls or payment requests far more credible.
Social engineering: knowing a civil servant’s role, department or colleagues enables highly personalized scam attempts.
Data that cannot be retrieved: once published and copied on the dark web, the files can continue to circulate even if the original hackers’ site disappears.
A breach two weeks before Berlin’s elections
The disclosure comes in a sensitive political context: the Berlin regional parliamentary elections are due to take place on September 20, 2026.
The BSI notes that so-called “hack and leak” operations can also be used in a political context: authentic stolen documents can be published at a time chosen by the attackers, or mixed with misleading interpretations.
At this stage, however, the Berlin electoral administration assures that the IT environment directly connected to organizing the vote is not affected, whether in the preparation, the voting process itself, or the publication of provisional results.
The urgency now is elsewhere: to determine, among 1.44 million files and nearly 5,800 gigabytes of data, which still pose an operational risk, which citizens have had their personal information exposed, and what measures must be taken to protect the infrastructures and institutions mentioned in the documents.
Adel Khelifi