A Cyber Incident with Political Explosive Potential – Attack on Berlin’s Senate Administrations (Part 1)
In the middle of last month, more precisely between August 7 and 12, two Berlin Senate administrations were successfully targeted in a cyberattack: the Senate Department for Urban Development, Building and Housing, on the one hand, and the Senate Department for Mobility, Transport, Climate Protection and the Environment, on the other. At that point, however, it was not yet known that the incident was actually much more serious and that the first signs had already been detected in June.
This article is the first of two blog posts examining the concept of digital sovereignty.
If you have already looked into the attack on Berlin’s Senate administrations, I recommend taking a look at the second part of this series. There, we examine whether digital sovereignty can withstand a real-world crisis—or when it fails in the face of practical obstacles.
Chapter 1: Why Clear Crisis Communication Matters
For those of you lucky enough to have escaped the numerous media reports, social media posts and other updates on this topic, here is a brief overview of the current situation.
On August 14, the Berlin Senate Chancellery initially reported a possible security incident affecting two administrations. The initial statement said that the affected authorities had been promptly isolated from the state network and were still able to operate “without internet access.” In other words, the existing contingency plans were said to be functioning and effective.
Whether and to what extent this was actually the case only became clear over the following days and weeks. A brief disclaimer: the investigations have not yet been fully completed, so some information may have become more specific or changed by the time this article is published.
What we know at this point is that the ransomware group Rhysida has claimed responsibility for the attack. The group publicly stated that it had stolen approximately 5.9 terabytes, or 1.2 million datasets.
However, the information regarding the criticality of the exfiltrated data was less clear. Not least because the authorities had communicated at an early stage that only non-critical geospatial data had been leaked.
This turned out to be a mistake, as became apparent soon afterward. Various media outlets reported very different information in quick succession—perhaps partly fueled by the early all-clear. According to Golem, only data with the lowest security classification—“For Official Use Only” (NfD)—had been exfiltrated. Less than twenty minutes later, however, the Süddeutsche Zeitung reported that information affecting national security had been leaked, including information about military barracks, emergency power systems and critical infrastructure. The situation was considered serious enough for the Bundeswehr Operational Command, the National Cybersecurity Centre and the Federal Office for Information Security (BSI) to be tasked with assessing it.
There now appears to have been at least a partial all-clear on Monday. Apparently, no highly critical data had been exfiltrated. However, it still cannot be ruled out at this point that some of the leaked information concerns critical infrastructure. The volume of exfiltrated data is also so extensive that artificial intelligence is reportedly being considered in order to cluster and evaluate it in a meaningful way.
All of this is in addition to the leakage of “less important” data belonging to Berlin residents, such as personal details, email addresses and bank account information.
Chapter 2: An Autopsy in Public
The public examination of the incident that is now taking place could be viewed as a positive development. It is not unusual for the forensic analysis of an incident to reveal causes that can be traced back to shortcomings in an information security framework. The following findings have been made public so far:
Insufficient protective measures: BSI President Claudia Plattner stated that the sheer volume of leaked data already indicated that the protective measures in place had been inadequate. At the same time, she made it clear that this was not an issue affecting Berlin alone.
Manuel Atug, spokesperson for the KRITIS AG, goes one step further. According to him, it must also be considered that the storage and processing of classified information may not have been carried out adequately.
Poor data hygiene: According to the information currently available, access credentials were stored in plain text—even in documents with unimaginative names such as “Password.docx.”
Delayed detection of the attack: Between the initial attack on August 7 and its discovery on August 12, existing measures failed to document unauthorized access and trigger an alert. It was only the unusual behavior of a domain controller that prompted a closer investigation.
Slow response times: According to IT expert Joachim Selzer of the Chaos Computer Club, access points were not closed in time—particularly after they had already been publicly disclosed by the threat actor.
Faulty crisis communication: The initial statement that only non-critical data had been leaked was premature.
But how did the attackers actually gain access to the network? After some initial inconsistencies, there now appears to be a clear answer.
At first, it was suspected that an IT vulnerability at the state’s IT service provider, ITDZ, might have been responsible. The BSI has now announced that the attack was the result of a successful phishing campaign.
More specifically, it involved TerminalFix, a variant of the so-called ClickFix attack, in which a user is tricked into carrying out commands or granting permissions without realizing it. In this case, the user was induced to execute malicious code.
Another statement is also interesting in this context: Dr. Maria Borelli, a member of ITDZ’s executive board, reportedly warned during a digitalization committee meeting that security measures had been postponed and that outdated software was still in use. This becomes particularly noteworthy when considering that both the service provider and the Senate administration itself would be required to comply with the requirements of the NIS2 Directive, which came into force in Germany in December 2025 and is incorporated into German law through the BSI Act.
Chapter 3: Refused Ransom Payments and the Publication of Data
After Rhysida claimed responsibility for the cyberattack, the group also demanded a ransom shortly afterward. The threat was explicit: if the demanded 30 bitcoin—equivalent to approximately €2 million—were not paid, the group would begin publishing the stolen information.
The Berlin Senate refused to pay, and the data were subsequently published online.
Regardless of whether a successful ransom payment would actually have prevented publication—which is doubtful—this still constitutes a serious disaster.
While changing a password takes only seconds or minutes, the same does not apply to vulnerabilities in our critical infrastructure. If sensitive data has been lost, it may take months or even years to close security gaps and adapt emergency response plans.
Chapter 4: Interim Conclusion
This could once again be dismissed as a case of “public authorities being unable to cope with current cybersecurity risks,” but that would fail to reflect the full significance of the incident. The leaked data demonstrate that not only financial interests but even national security interests can be affected when state authorities fail to implement data security rigorously enough—particularly when, like companies, they are subject to current regulatory requirements under NIS2.
But the fact that public authorities often appear to be judged by a different standard will presumably be the subject of our second blog post.