Millions of files leaked: Berlin cyberattack may have wider consequences than initially thought
Translated from German and summarized by DistantNews. Read the original for the full story.
At a glance
- Hackers published about 1.44 million files totaling 5.8 terabytes after gaining access to parts of Berlin’s state network in August.
- The leaked material initially appeared to include personal records, but media reports and IT experts warned that sensitive information linked to civil protection and defense companies may also be exposed.
- The Rhysida group demanded about 2 million euros in Bitcoin; Berlin did not pay, and the hackers released the data after their deadline.
The leak from a cyberattack on parts of Berlin’s administration may reach far beyond personal records, with concerns growing that the stolen files include information relevant to Germany’s national security and critical infrastructure.
About 1.44 million files, totaling 5.8 terabytes, have been published on the dark web since Friday. The material initially appeared to include scanned passports, employment contracts, job applications, and sick notes. Media reports and IT experts have warned that the files may also contain highly sensitive information involving civil protection and defense companies.
real data super-disaster
Green Party parliamentary deputy leader Konstantin von Notz called the incident a “real data super-disaster” in an interview with Handelsblatt. He said that if investigators find that protective measures were deliberately ignored and the required safeguards for classified information were not maintained, personnel consequences would be unavoidable. Von Notz also accused the federal government of “massive failures” and said it bore direct responsibility.
If it turns out that protective mechanisms were deliberately not observed and the urgently necessary safeguards for classified information were not ensured, personnel consequences would also be unavoidable.
CDU foreign policy lawmaker Roderich Kiesewetter told the Süddeutsche Zeitung that “this data leak is of grave proportions and endangers our national security.” He said the case could become the most serious publicly known state-level IT security incident in Germany, with potentially significant financial consequences.
The Rhysida hacking group entered parts of Berlin’s state network undetected between Aug. 7 and Aug. 12. Authorities detected the attack on Aug. 14 and made it public three days later. The group demanded 30 Bitcoin, worth about 2 million euros. The Senate refused to pay, and the hackers released the data after their ultimatum expired. A full assessment remains difficult because of the volume of material, while Chaos Computer Club spokesman Jochim Selzer said the files cannot simply be searched with the computer shortcut Ctrl+F.
This data leak is of grave proportions and endangers our national security.
Originally published by Die Zeit in German. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.