NewsTradingSentimentCalendarCommunityBriefing
World

Berlin Cyberattack Exposes 1.4 Million Files

By Geopolitics Desk · 2026-09-10 · 2 min read
A fiber-optic cable network connecting municipal buildings
Illustration: Tradingbird

A ransomware group published stolen municipal data after Berlin refused to pay a two-million-euro demand, raising concerns about infrastructure security.

A cybercrime group has published approximately 1.4 million records belonging to the Berlin state government on the dark web. The data, which includes employee files, official correspondence, and scanned identification documents, was stolen by the hacker collective Rhysida. The group initially demanded a ransom of 30 bitcoins, valued at roughly two million euros, but released the files after Berlin’s governing mayor, Kai Wegner, stated that the state would not succumb to blackmail.

According to Deutsche Welle, the breach occurred between August 7 and 14, with the intrusion going undetected until early September. The attack targeted two major departments, including the Department of Transportation, through a phishing email opened by an employee. This incident highlights the vulnerability of Germany’s public data networks, as the compromised information extends beyond personal details to sensitive infrastructure data such as power plants and water treatment facilities.

Infrastructure Data Exposed

The scope of the leak reveals significant risks to critical municipal systems. In addition to the personal data of employees and residents, the dataset reportedly contains information on combi-heat and power plants, fuel storage, emergency power supplies, and prisons. Experts warn that this combination of personal and infrastructure data creates a heightened risk for social engineering attacks. The Chaos Computer Club noted that detailed personal profiles allow attackers to impersonate individuals more effectively, potentially facilitating fraudulent orders or further breaches.

Criticism of Security Measures

The Berlin Senate’s initial response, which involved instructing employees to change their passwords, has drawn sharp criticism. Thorsten Schleheider, vice-chairman of the Berlin police union, argued that the city’s data has been inadequately protected for years. He described it as unthinkable that sensitive information was compromised for days with minimal corrective action. The criticism underscores a growing concern that reactive measures like password resets are insufficient against sophisticated cyber threats, particularly when staff training and network security protocols are perceived as weak.

Coordinated Response Efforts

In response to the breach, the Berlin government has established a coordination office involving all administrative agencies. The city has also engaged with federal bodies, including the Federal Office for Information Security, to manage the fallout. Mayor Wegner stated that the administration is committed to informing and supporting affected employees and residents as quickly as possible. The incident serves as a stark reminder of the ongoing challenges in securing public infrastructure against criminal cyber actors.

Based on reporting by Deutsche Welle, compiled by the Tradingbird desk.

Read next

More in World

More from the World desk

All desk stories