type: incident ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [incident, breach, government, ransomware, rhysida, germany] ยท confidence: high ยท affected_sectors: [government] ยท au_impact: false
Berlin Investigates New Data Leak After Hackers Publish Stolen Login Credentials
German authorities are investigating another trove of data stolen from Berlin's government network after hackers published stolen login credentials and other information, following a cyberattack discovered in mid-August that compromised two city ministries (urban development and housing; transport, mobility, climate and environment).
| Attribute | Detail |
|---|---|
| Data stolen | Large volume, incl. personal data of public employees and potentially Berlin residents (names, addresses, DOB, bank details, email, phone, correspondence, documents) |
| Response | Berlin will not pay; mayor called it a "very serious crime" |
| Context | Rhysida-attributed breach of ~5.79 TB; BSI warning about a TerminalFix-like campaign |
| Source | The Record โ Tier 2/4 |
The leak extends the mid-August Rhysida ransomware compromise of Berlin ministries. Berlin's data protection authority says a large volume of data was stolen and published. The piece is framed against the recurring Rhysida breach and a BSI warning that same week about a campaign resembling the TerminalFix pattern, with the same financially motivated cluster publishing data in most named-victim cases.
Related Pages
- Berlin Confirms Data Theft After Rhysida Attack Election Systems Ruled Safe โ the wider Rhysida Berlin breach