BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 7, 2026 · 4 min read · Original story

Berlin investigates new data leak after hackers publish stolen login credentials

Berlin investigates new data leak after hackers publish stolen login credentials
Berlin investigates new data leak after hackers publish stolen login credentials

German authorities are investigating another trove of data stolen from Berlin’s government network after hackers published login credentials and other information over the weekend.

The latest release follows a cyberattack discovered in mid-August that compromised two Berlin ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment.

Berlin’s government said Sunday that the newly released data includes login credentials but did not say what systems they could be used to access or whether they were still valid. The authorities have not attributed the attack to a specific threat actor.

The city’s urban development ministry has strengthened security measures introduced after an earlier data leak, which officials said could temporarily limit access to some of its applications.

'A very serious crime'

Berlin’s data protection authority said Friday that the attackers stole a large amount of data from the two affected ministries and later published it online.

Officials are still reviewing the stolen files because of the volume of data involved. The regulator confirmed that the leak includes personal information about public employees and said data belonging to Berlin residents also may have been exposed.

Potentially compromised information includes names, addresses, dates of birth, bank information, email addresses, telephone numbers, correspondence with government agencies and copies of documents submitted to the administration, according to the regulator.

Berlin has created an additional task force to review the leaked material and determine who may be affected.

“A very serious crime has been committed against the State of Berlin,” Governing Mayor Kai Wegner said Saturday, adding that authorities were working to identify and assist people whose information had been exposed.

No payment

The Rhysida ransomware group claimed responsibility for the breach in late August, saying it had stolen 5.79 terabytes of data, including tens of thousands of contracts, emails, passwords and classified information.

Berlin has confirmed that data was stolen and that it received an extortion demand, but officials have not publicly attributed the attack to Rhysida or verified the hackers’ claims about the amount or contents of the stolen material.

Wegner said last month that Berlin would not pay the attackers.

“The State of Berlin will not be blackmailed,” Berlin Chief Digital Officer Florian Hauer said separately.

The affected systems were disconnected from Berlin’s wider government network on Aug. 14. Both ministries continued operating, but the disruption left some employees without their normal email and internet access and temporarily affected public services that depend on their systems.

Rhysida warning

Germany’s Federal Office for Information Security, or BSI, separately warned Friday about a cyberattack campaign linked to the same financially motivated hackers behind Rhysida.

The agency did not explicitly identify Berlin as one of the victims but said it had been informed in August about the compromise of a government institution.

According to the BSI, the campaign resembles the so-called TerminalFix attacks recently documented by Microsoft. Hackers compromise websites and display fake CAPTCHA verification pages that trick visitors into manually running malicious commands on their computers.

The BSI said reports it received indicated that attackers attempted both to steal data and install ransomware, allowing them to pressure victims with the threat of publishing stolen information.

The agency said the campaign involved malware known as LoremIpsumLoader, or AxolotLoader, which it linked to the same financially motivated cybercriminal group associated with Rhysida.

“According to current findings, the campaign is being carried out by cybercriminal actors,” the BSI said. “So far, no connection to state-sponsored or politically motivated actors has been established.”

Rhysida has operated since 2023 and has targeted governments, hospitals, schools and companies around the world. According to the BSI, government and public administration organizations are among the five sectors most frequently appearing on the group’s leak site, although education and health care remain its primary targets.

The BSI said stolen information is ultimately published in 92 percent of cases in which victims are named on Rhysida’s leak site.

The Berlin breach comes shortly before the city’s Sept. 20 election. Berlin Interior Senator Iris Spranger previously said that authorities had found no evidence that data had been stolen from election systems and that the election environment was secure.

References in this story

  1. Berlin cuts two state ministries off government network after security breach therecord.media The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks…
  2. Nach dem IKT-Vorfall – Weiteres Datenpaket veröffentlicht - Berlin.de www.berlin.de
  3. Hinweise zum "Hackerangriff auf Berlin" - Berliner Beauftragte für Datenschutz und Informationsfreiheit www.datenschutz-berlin.de Internetseite der Berliner Beauftragten für Datenschutz und Informationsfreiheit
  4. Aktuelle Lage nach dem IKT-Vorfall – Zentrale Steuerungseinheit in der Senatskanzlei eingerichtet - Berlin.de www.berlin.de
  5. Berlin says it won’t pay ransom after hackers steal government data therecord.media Governing Mayor Kai Wegner said that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.
  6. Version 1.0: Deutsche Institutionen über TerminalFix-Kampagne kompromittiert www.bsi.bund.de
  7. TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Security Blog www.microsoft.com Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
  8. Hackerangriff auf Landesnetz: Arbeit mit Hochdruck an Lösungen www.berlin.de Ein Hackerangriff auf Teile der Berliner Verwaltung stellt diverse Behörden vor Herausforderungen. Der Senat informierte am Mittwoch über die aktuelle Lage und das weitere Vorgehen.
  9. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  10. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  11. Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine

Guides related to this story

← Back to all news