Zero Day Room
Live
Defence

Berlin Data Leak

Berlin investigates a new data leak after hackers published stolen login credentials, following a cyberattack discovered in mid-August that compromised two

Berlin investigates a new data leak after hackers published stolen login credentials, following a cyberattack discovered...

Berlin authorities are investigating a new data leak after hackers published login credentials and other information over the weekend, following a cyberattack discovered in mid-August that compromised two Berlin ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment. The latest release includes login credentials, but the authorities have not disclosed what systems they could be used to access or whether they were still valid.

Investigation and Response

The city's urban development ministry has strengthened security measures introduced after an earlier data leak, which officials said could temporarily limit access to some of its applications. Berlin's data protection authority said the attackers stole a large amount of data from the two affected ministries and later published it online. Officials are still reviewing the stolen files due to the volume of data involved.

Impact and Potential Consequences

The regulator confirmed that the leak includes personal information about public employees and said data belonging to Berlin residents may have been exposed. Potentially compromised information includes names, addresses, dates of birth, bank information, email addresses, telephone numbers, correspondence with government agencies, and copies of documents submitted to the administration. Berlin has created an additional task force to review the leaked material and determine who may be affected.

Attribution and Ransom Demand

The Rhysida ransomware group claimed responsibility for the breach, saying it had stolen 5.79 terabytes of data, including tens of thousands of contracts, emails, passwords, and classified information. Berlin has confirmed that data was stolen and that it received an extortion demand, but officials have not publicly attributed the attack to Rhysida or verified the hackers' claims about the amount or contents of the stolen material. According to the source, The Record, Berlin's Governing Mayor Kai Wegner said the city would not pay the attackers, stating that 'a very serious crime has been committed against the State of Berlin'.

Warning from Federal Office for Information Security

Germany's Federal Office for Information Security, or BSI, warned about a cyberattack campaign linked to the same financially motivated hackers behind Rhysida. The agency said the campaign resembles the so-called TerminalFix attacks and involves malware known as LoremIpsumLoader, or AxolotLoader. The BSI linked this malware to the same financially motivated cybercriminal group associated with Rhysida, which has operated since 2023 and targeted governments, hospitals, schools, and companies around the world.

Topics

#Defence

Related coverage

More from Defence