During the closed-door part of the same session, however, the Senate Chancellery learned of possible further data losses. Two days later, Hauer publicly acknowledged that personal and non-public data could also have been affected.
On 7 September, Hauer told Berlin’s Interior Committee that only classified material at the lowest level of classification, VS-NfD, was affected, not material of greater importance to national security.
The review of more than 1.2 million files is still under way and could take weeks, according to the Chaos Computer Club, Europe’s largest hacker association. Until it is complete, there can be no definitive assessment of exactly what data was stolen.
Medical Records, Passwords and Emergency Plans
The data examined so far reaches deep into the private lives of both employees of Berlin’s administration and city residents. Personnel files currently exposed on the dark web include rehabilitation records, sick notes, medical certificates, accident reports, vaccination and PCR records and a scan of a disability ID card. There are also identity cards, children’s birth certificates, private telephone numbers, bank details, payslips, police clearance certificates, written workplace warnings and disciplinary files.
In the filenames of 10,556 personnel records, Tagesspiegel found around 1,100 distinct full names. Its analysis also identified around 1,300 health records, 4,300 job application files and 121,475 individual emails. The haul includes 198 large email archives, some bearing the names of current or former members of government. One was stored in a folder labeled “private”.
The published material also includes tens of thousands of files relating to fine proceedings, lawsuits and legal opinions involving the city of Berlin.
The exposure of information about critical infrastructure is also alarming. After far-left terrorists attacked the city’s power grid at the start of the year, causing power outages lasting several days in freezing temperatures, sensitive details of potential vulnerabilities are now available on the dark web.
The material lists combined heat and power plants, fuel depots, emergency power systems, substations, waterworks, hospitals, prisons and defense contractors that are meant to be protected in a crisis or in wartime. It also contains the city’s entire administrative structure and emergency plans, including facilities’ operating hours, risk assessments, security arrangements and the private telephone numbers of emergency coordinators. One presentation identifies waterworks where contaminants could cause particularly severe damage because filtering capacity is inadequate.
Taken together, the material reads like an invitation to attack, complete with an instruction manual.
Login credentials were also stored unencrypted. Files bore names such as “Passwort.txt” or “Zugangsdaten” and contained credentials for electronic building applications and a payment service provider. It is unclear whether all of them were still valid. Experts reported, however, that some of the published passwords could still be used to access systems days later.
One Wrong Click, Six Days of Undetected Access
The sequence of events now appears clear. The attack began with a classic phishing email. An employee at the transport department clicked the link it contained. From 7 to 12 August, the attackers copied data from internal servers. It was not until a central server malfunctioned on 13 August that the intrusion came to light. Until then, apparently no security software had detected either their presence or the data transfers. The two departments were not disconnected from Berlin’s state network until 14 August.
The mistaken click alone, however, does not explain the sheer volume of data stolen. According to an employee, the affected departments had neither mandatory password managers nor two-factor authentication nor any system for flagging unusual copying activity. Parts of the administration still operate on outdated networks because they do not meet the minimum requirements to migrate to the central IT service provider. IT expert Manuel Atug, who had already warned of security flaws in 2023 and 2025, described the handling of sensitive data as gross negligence.
On 28 August, Rhysida demanded 30 Bitcoin, then worth around €2m ($2.3m). Berlin did not pay, but still had no clear picture of the scale of the theft. Four employees were reviewing the documents largely by hand. The order to change all system passwords was not issued until 1 September, more than two weeks after the attack came to light.
The Federal Criminal Police Office, the domestic intelligence service, the Federal Office for Information Security and the Bundeswehr are now helping to assess the damage and restore data security.
Governing Mayor Kai Wegner is therefore facing intense criticism for the second time this year over his handling of a serious crisis in the city. When Berlin was hit in January by the largest far-left attack on its infrastructure, he played tennis instead of going to City Hall. When Rhysida released the stolen data, Wegner and Interior Senator Iris Spranger, who is responsible for security, attended a Women’s Basketball World Cup game and posed for photographs. A city spokeswoman said both had been kept informed throughout.
Attending the basketball game makes for bad optics, but it is not even Wegner’s biggest problem. The more politically explosive issue is that his government projected certainty in public while journalists and criminals already knew more about the stolen data than the authorities themselves – or at least more than the authorities were prepared to admit.