Berlin Investigates New Data Breach as Hackers Publish Stolen Login Credentials from Government Network

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

German authorities are currently investigating a new data breach involving Berlin’s government network, following the publication of stolen login credentials and other sensitive information by hackers over the weekend. This incident comes on the heels of a cyberattack discovered in mid-August that had already compromised two ministries in the city, which oversee urban development and transport, among other responsibilities. According to reporting by The Record, the newly released data includes login credentials, although officials have not confirmed which systems they may access or their validity.

‘A very serious crime’

Berlin’s data protection authority reported that a significant amount of data was stolen from the affected ministries and subsequently published online. The review of the stolen files is ongoing due to the large volume of data involved. The regulator has indicated that the leak includes personal information about public employees, and there is a possibility that data belonging to Berlin residents has also been exposed. This potentially compromised information includes names, addresses, dates of birth, and other sensitive details.

No payment

The Rhysida ransomware group claimed responsibility for the earlier breach, asserting that they had stolen 5.79 terabytes of data, which includes contracts, emails, and classified information. While Berlin officials have confirmed that data was stolen and an extortion demand was received, they have not publicly attributed the attack to Rhysida or verified the specifics of the hackers’ claims. Berlin’s leadership has stated that they will not pay the attackers, emphasizing that the state will not be blackmailed.

Rhysida warning

In a related warning, Germany’s Federal Office for Information Security (BSI) has alerted about a cyberattack campaign linked to the same financially motivated hackers behind Rhysida. Although the BSI did not specifically identify Berlin as a victim, it noted that it had been informed about the compromise of a government institution. The BSI has indicated that the campaign involves malware known as LoremIpsumLoader, which is associated with the Rhysida group. The agency has confirmed that the campaign is being executed by cybercriminal actors, with no evidence linking it to state-sponsored entities.

The breach occurs just ahead of Berlin’s upcoming election on September 20, with officials stating that there is no evidence to suggest that election systems were compromised.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

ManageEngine to Highlight AI-Driven Cybersecurity Solutions at GISEC Global 2026 in Dubai

ManageEngine, a division of Zoho Corporation, is set to showcase its advanced cybersecurity solutions at GISEC Global 2026, scheduled for September 16-18 at the...

Toy Ghouls Unveils New Backdoors Utilizing HiveMQ and Element for C2 Communication

Introduction The cybersecurity landscape continues to evolve, with threat actors constantly adapting their tactics. One such group, known as Toy Ghouls (also referred to as...

North Korea commissions second Choe Hyon-class guided-missile destroyer

On Sunday, September 6, 2026, the North Korean Navy commissioned its second 5,000-ton Choe Hyon-class guided-missile destroyer, Kang Kon, in the eastern port city...

Spammers Adopt ASCII Smuggling Technique to Evade Email Filters Amid Surge in Malicious Activity

A clever technique known as ASCII smuggling, initially used to hide malicious prompts in AI attacks, has been repurposed by spammers to bypass email...