A hacker group called Rhysida released nearly six terabytes of Berlin state‑administration data, including personal and defense‑related information, to the dark web.
A hacker collective known as Rhysida has dumped nearly six terabytes of highly sensitive data from Berlin’s state administration onto the dark web, exposing personal records, government communications and defense‑related information.
Scope of the breach
The leaked files encompass a wide array of documents, ranging from civil servant payroll lists and citizen identification numbers to classified defense procurement contracts. Security analysts say the volume and variety of the data suggest the attackers had prolonged access to internal networks.
How the attack unfolded
According to the Berlin Senate’s IT security office, the intrusion was detected after unusual traffic patterns were observed on a legacy server used for inter‑agency communications. By the time the breach was confirmed, the attackers had already exfiltrated the data and posted it on multiple dark‑web marketplaces.
Rhysida, which has previously targeted European governmental bodies, claimed responsibility in a brief statement posted on a hacking forum, boasting about the “unprecedented scale” of the leak.
Potential repercussions
Experts warn that the exposed information could be leveraged for identity theft, blackmail of public officials, and espionage against Germany’s defense sector. The breach also raises concerns about the resilience of Germany’s critical infrastructure against sophisticated cyber‑crime groups.
- Identity theft risk for millions of residents
- Compromised procurement contracts may aid foreign intelligence
- Potential blackmail of officials with defense‑related documents
Response from authorities
Berlin’s interior ministry has launched a full forensic investigation and is working with federal law‑enforcement agencies to trace the source of the intrusion. A public advisory urging citizens to monitor their financial accounts and change passwords was issued immediately after the breach was confirmed.
The German Federal Office for Information Security (BSI) has pledged additional resources to bolster the cybersecurity posture of state institutions, emphasizing the need for rapid patching of legacy systems.
We are treating this as a national security incident and will pursue all legal avenues to hold the perpetrators accountable, said Berlin’s Senator for the Interior.