Berlin Disconnects State Ministries After Security Breach
Two Berlin state ministries were disconnected from the government IT network due to a security breach, impacting public services and forcing communication via older methods.

Berlin has disconnected two of its state ministries from the city's government IT network following the discovery of a security breach. The ministries affected are responsible for urban development and mobility, transport, climate protection, and the environment. As a precautionary measure, both departments were isolated from government networks starting Friday, according to a statement from the Berlin Senate Chancellery on Monday.
Authorities have not yet disclosed the identity of the perpetrators, the method of intrusion, or whether any data was compromised. The exact timing of the breach also remains unclear. "The security of the state network is the top priority," the Senate Chancellery stated, adding that "for investigative reasons, no further specific information about the scope or background can currently be provided." The investigation into the incident is actively ongoing.
German public broadcaster RBB, citing government sources, reported that the attackers allegedly exploited a vulnerability within the IT systems of one of the affected ministries. The city's state-owned IT service provider, ITDZ Berlin, was reportedly not impacted by the breach. The two disconnected ministries, which share some IT infrastructure, operate their segment of the state network independently of ITDZ Berlin.
The disconnection has significantly disrupted the daily operations of the ministries. Employees are cut off from their usual IT systems, including email and internet access, forcing them to rely on telephone, text messages, and fax for communication. This operational shift highlights the reliance on digital infrastructure and the challenges posed by its sudden unavailability.
The impact extends beyond internal operations, affecting some public services. Reports indicate that applications for housing benefits and assistance related to education and participation cannot be processed at certain district offices due to their dependence on systems managed by the affected urban development ministry. This disruption underscores the critical role these IT systems play in delivering essential public services.
Officials have not provided an estimated timeline for when the ministries will be reconnected to the state network. The duration of the disconnection will likely depend on the thoroughness of the investigation and the remediation efforts required to secure the affected systems. The incident serves as a stark reminder of the persistent cybersecurity threats facing government networks and the potential consequences of even seemingly isolated breaches.
This event highlights the ongoing challenges governments face in maintaining robust cybersecurity defenses against sophisticated threats. The reliance on interconnected systems, while enabling efficiency, also creates potential single points of failure. The response from Berlin authorities, prioritizing isolation and investigation, reflects standard incident response protocols for such security events.
The Rhysida ransomware group has claimed responsibility for the breach, adding an entry to its leak site on August 28th that alleges the exfiltration of 5.79 terabytes of data and personal information on over 12,000 individuals. While Berlin has refused to pay any ransom, the group's claimed data volume and the inclusion of personal information on a significant number of individuals highlight the potential severity of the incident, even as the city continues its forensic examination and investigation with federal authorities.
The Rhysida ransomware gang has claimed responsibility for the breach, listing approximately 1.44 million files totaling 5.79 TB on its data leak site. The gang's detailed breakdown includes sensitive categories such as financial records, contracts, government documents, and even vulnerability assessments of Berlin's water supply. Rhysida is reportedly demanding 30 bitcoin, equivalent to around 2 million euros, for the stolen data.