Berlin investigates new data leak after hackers publish stolen login credentials
German authorities are investigating another trove of data stolen from Berlin’s government network after hackers published login credentials and other information over the weekend.
The latest release follows a cyberattack discovered in mid-August that compromised two Berlin ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment.
Berlin’s government said Sunday that the newly released data includes login credentials but did not say what systems they could be used to access or whether they were still valid. The authorities have not attributed the attack to a specific threat actor.
The city’s urban development ministry has strengthened security measures introduced after an earlier data leak, which officials said could temporarily limit access to some of its applications.
'A very serious crime'
Berlin’s data protection authority said Friday that the attackers stole a large amount of data from the two affected ministries and later published it online.
Officials are still reviewing the stolen files because of the volume of data involved. The regulator confirmed that the leak includes personal information about public employees and said data belonging to Berlin residents also may have been exposed.
Potentially compromised information includes names, addresses, dates of birth, bank information, email addresses, telephone numbers, correspondence with government agencies and copies of documents submitted to the administration, according to the regulator.
Berlin has created an additional task force to review the leaked material and determine who may be affected.
“A very serious crime has been committed against the State of Berlin,” Governing Mayor Kai Wegner said Saturday, adding that authorities were working to identify and assist people whose information had been exposed.
No payment
The Rhysida ransomware group claimed responsibility for the breach in late August, saying it had stolen 5.79 terabytes of data, including tens of thousands of contracts, emails, passwords and classified information.
Berlin has confirmed that data was stolen and that it received an extortion demand, but officials have not publicly attributed the attack to Rhysida or verified the hackers’ claims about the amount or contents of the stolen material.
Wegner said last month that Berlin would not pay the attackers.
“The State of Berlin will not be blackmailed,” Berlin Chief Digital Officer Florian Hauer said separately.
The affected systems were disconnected from Berlin’s wider government network on Aug. 14. Both ministries continued operating, but the disruption left some employees without their normal email and internet access and temporarily affected public services that depend on their systems.
Rhysida warning
Germany’s Federal Office for Information Security, or BSI, separately warned Friday about a cyberattack campaign linked to the same financially motivated hackers behind Rhysida.
The agency did not explicitly identify Berlin as one of the victims but said it had been informed in August about the compromise of a government institution.
According to the BSI, the campaign resembles the so-called TerminalFix attacks recently documented by Microsoft. Hackers compromise websites and display fake CAPTCHA verification pages that trick visitors into manually running malicious commands on their computers.
The BSI said reports it received indicated that attackers attempted both to steal data and install ransomware, allowing them to pressure victims with the threat of publishing stolen information.
The agency said the campaign involved malware known as LoremIpsumLoader, or AxolotLoader, which it linked to the same financially motivated cybercriminal group associated with Rhysida.
“According to current findings, the campaign is being carried out by cybercriminal actors,” the BSI said. “So far, no connection to state-sponsored or politically motivated actors has been established.”
Rhysida has operated since 2023 and has targeted governments, hospitals, schools and companies around the world. According to the BSI, government and public administration organizations are among the five sectors most frequently appearing on the group’s leak site, although education and health care remain its primary targets.
The BSI said stolen information is ultimately published in 92 percent of cases in which victims are named on Rhysida’s leak site.
The Berlin breach comes shortly before the city’s Sept. 20 election. Berlin Interior Senator Iris Spranger previously said that authorities had found no evidence that data had been stolen from election systems and that the election environment was secure.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



