← All stories
● Covered by 4 sources · 7 reportsMedium impact5 negative2 neutral

Two Berlin State Ministries Disconnected from Government Network Following Security Breach

🔄 Updated 25d ago — new reporting from The Record
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two Berlin ministries disconnected from government IT network.
  • Breach affected urban development and mobility ministries.
  • Public services, including housing benefits, are disrupted.
  • Investigation into the incident is ongoing.
  • Berlin government is being extorted following the network compromise.
  • Berlin will not pay the hackers.
  • Attackers claim 5.79 terabytes of data and personal information on 12,076 individuals.
  • Data exfiltration occurred between August 7 and August 12, 2026.
  • The department first reported an outflow on August 7.
  • Rhysida ransomware group claimed responsibility for the attack.
  • Incident was discovered on August 14.
  • Network was shut down on August 14.
  • Attack was publicly claimed on August 28.
  • Kai Wergner is the Mayor of Berlin.
  • Rhysida ransomware has been active since mid-2023.
  • Attackers claim 1.44 million files were exfiltrated.
  • Stolen data includes 46,500 contracts.
  • Attackers advertised the dataset for auction with a starting price of 30 bitcoin.
  • Hackers published login credentials and other information over the weekend.
  • The newly released data includes personal information of public employees and potentially residents.
  • The urban development ministry strengthened security measures, temporarily limiting access to some applications.

Government Network Compromised

Two Berlin state ministries have been disconnected from the city government's IT network after a security breach was discovered. The affected ministries include those responsible for urban development, construction, housing, mobility, transport, climate protection, and the environment. This isolation began on Friday as a precautionary measure, according to the Berlin Senate Chancellery.

Investigation Underway

Authorities have not disclosed details regarding the perpetrators, the method of access, or whether data was exfiltrated. The timeline of the intrusion also remains unclear. The Senate Chancellery stated that further specific information cannot be provided due to ongoing investigative reasons, emphasizing that the security of the state network is a top priority.

Operational Disruptions

Despite the disconnection, both ministries remain operational. However, employees have lost access to their standard IT systems, including email and internet, and are now relying on telephones, text messages, and faxes for communication. The disruption has also impacted public services, with some district offices unable to process applications for housing benefits and education assistance due to their reliance on systems operated by the affected urban development ministry.

Independent IT Infrastructure

German public broadcaster RBB reported that the attackers allegedly exploited a vulnerability within the IT systems of one of the affected ministries. Berlin's state-owned IT service provider, ITDZ Berlin, was not impacted by the breach. The two affected ministries share some IT infrastructure and manage their portion of the state network independently of ITDZ.

Updates

🕒 2026-09-07 · new reporting from The Record
  • Hackers published login credentials and other information over the weekend.
  • The newly released data includes personal information of public employees and potentially residents.
  • The urban development ministry strengthened security measures, temporarily limiting access to some applications.
🕒 2026-08-31 · new reporting from BleepingComputer, The Record
  • Attack was publicly claimed on August 28.
  • Kai Wergner is the Mayor of Berlin.
  • Rhysida ransomware has been active since mid-2023.
  • Attackers claim 1.44 million files were exfiltrated.
  • Stolen data includes 46,500 contracts.
  • Attackers advertised the dataset for auction with a starting price of 30 bitcoin.
🕒 2026-08-31 · new reporting from SecurityWeek
  • Rhysida ransomware group claimed responsibility for the attack.
  • Incident was discovered on August 14.
  • Network was shut down on August 14.
🕒 2026-08-29 · new reporting from The Hacker News
  • Berlin government is being extorted following the network compromise.
  • Berlin will not pay the hackers.
  • Attackers claim 5.79 terabytes of data and personal information on 12,076 individuals.
  • Data exfiltration occurred between August 7 and August 12, 2026.
  • The department first reported an outflow on August 7.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Stadtwerke Landsberg, a municipal utility in Bavaria, reported a cyberattack that encrypted its central IT network, disrupting office systems but not essential services. The incident, which began on September 1, prompted the utility to disconnect systems and engage cybersecurity specialists, with an ongoing investigation into potential data access or theft. This event highlights the persistent ransomware threat to German critical infrastructure, as identified by the BSI.

German authorities are investigating a new data leak from Berlin's government network after hackers published login credentials and other information over the weekend. This incident follows a cyberattack in mid-August that compromised two Berlin ministries, and the newly released data includes personal information of public employees and potentially residents, raising concerns about data security for government systems.

The Berlin government announced it will not pay a ransom after hackers stole data from its network in mid-August. The Rhysida ransomware group claimed responsibility, stating they exfiltrated 5.79 terabytes of government data, including contracts, emails, and classified information, and put it up for auction.

Berlin's city administration confirmed a data theft following a Rhysida ransomware attack, with the attackers claiming to have exfiltrated 5.79 TB of sensitive data and threatening to publish it. The city stated it will not pay the ransom, and investigations are ongoing into the incident that impacts various government records and personal information.

Berlin announced it will not pay the ransom demanded by an extortion group that hacked its network and stole data earlier this month. The Rhysida ransomware group claimed responsibility for the attack, stating they exfiltrated over 5.7 terabytes of sensitive data, including personal information of 12,000 people. This incident highlights the ongoing challenge of ransomware attacks against government entities and the difficult decisions regarding ransom payments.

Berlin's state government confirmed it is being extorted following an August compromise of its administrative network and will not pay the hackers. Forensic analysis revealed further data exfiltration from the Department for Mobility, Transport, Climate Protection and Environment, with attackers claiming 5.79 terabytes of data and personal information on over 12,000 individuals.

Two Berlin state ministries, responsible for urban development and mobility, have been isolated from the city government's IT network due to a security breach. This incident has disrupted internal communications and some public services, highlighting vulnerabilities in government IT infrastructure.