VYPR
breachPublished Sep 7, 2026· 1 source

Berlin Investigates Second Data Leak After Hackers Publish Stolen Login Credentials

Berlin is investigating a second data leak after hackers published stolen login credentials and other sensitive information online, following a mid-August breach of city government networks.

German authorities are investigating another significant data breach after hackers published stolen login credentials and other sensitive information from Berlin's government network over the weekend. This latest incident follows a cyberattack discovered in mid-August that compromised two key Berlin ministries: those responsible for urban development and housing, and for transport, mobility, climate protection, and the environment.

The newly released data reportedly includes login credentials, though city officials have not yet specified which systems these credentials could access or if they remain valid. Authorities have not yet attributed the attack to a specific threat actor. The urban development ministry has since enhanced its security measures, which were initially bolstered after the earlier data leak, though these efforts may temporarily restrict access to some applications.

Berlin's data protection authority confirmed on Friday that the attackers had exfiltrated a substantial volume of data from the two affected ministries before publishing it online. The sheer amount of data involved means officials are still in the process of reviewing the stolen files. The regulator indicated that the leak contains personal information pertaining to public employees and potentially also exposes data belonging to Berlin residents.

Potentially compromised information includes names, addresses, dates of birth, bank details, email addresses, telephone numbers, correspondence with government agencies, and copies of documents submitted to the administration. In response, Berlin has established an additional task force dedicated to meticulously reviewing the leaked material and identifying all individuals who may have been affected by this exposure.

"A very serious crime has been committed against the State of Berlin," stated Governing Mayor Kai Wegner on Saturday, emphasizing that authorities are actively working to identify and provide assistance to those whose information has been compromised. The city has firmly stated its refusal to pay any ransom demands. "The State of Berlin will not be blackmailed," echoed Berlin Chief Digital Officer Florian Hauer.

The Rhysida ransomware group claimed responsibility for the breach in late August, asserting that it had stolen approximately 5.79 terabytes of data, including tens of thousands of contracts, emails, passwords, and classified documents. While Berlin has confirmed that data was indeed stolen and that an extortion demand was received, officials have not publicly confirmed Rhysida's claims regarding the quantity or specific contents of the stolen material.

The affected systems were disconnected from Berlin's broader government network on August 14th. Although both ministries continued their operations, the disruption led to temporary limitations in email and internet access for some employees and affected public services reliant on these systems. Germany's Federal Office for Information Security (BSI) issued a separate warning on Friday about a cyberattack campaign potentially linked to the same financially motivated threat actors behind Rhysida, noting similarities to Microsoft's documented TerminalFix attacks.

The BSI described a campaign involving malware known as LoremIpsumLoader, or AxolotLoader, which it associates with the Rhysida-linked cybercriminal group. These attacks typically involve compromising websites and presenting fake CAPTCHA pages to trick visitors into executing malicious commands. The agency noted that attackers aim to steal data and deploy ransomware, using the threat of data publication as leverage. The BSI stated that current findings point to financially motivated cybercriminals, with no established links to state-sponsored or politically motivated actors. Rhysida has been active since 2023, targeting various sectors including governments, hospitals, and companies globally. The BSI highlighted that government and public administration organizations are among the top five sectors targeted by Rhysida, with data ultimately being published in 92% of cases where victims are named on the group's leak site.

Synthesized by Vypr AI