Berlin Cyberattack Exposes 5.8 Terabytes of Government Data After a Single Click
Berlin is dealing with one of the most serious cyber incidents in the history of its state administration after hackers gained access to parts of the government network and extracted an estimated 5.8 terabytes of data. The attackers, identified by authorities and reporting as the Rhysida ransomware group, demanded about €2 million in cryptocurrency and threatened to release the stolen information if Berlin refused to pay. The state government rejected the demand, and large quantities of the stolen data were subsequently published online.
According to Berlin authorities, the main data theft occurred between August 7 and August 12, while the intrusion was discovered on August 14. Two Senate administrations — those responsible for mobility, transport, climate protection and the environment, and for urban development, construction and housing — were affected and were disconnected from the state network as a precaution. Authorities have said the investigation is continuing and that the full contents and consequences of the stolen data are still being assessed.
The attackers claimed to have stolen approximately 5.79 terabytes of information, including a large number of files containing contracts, emails, telephone numbers and passwords. German reporting has put the total at roughly 1.44 million files. The data was eventually published after Berlin refused to meet the ransom demand, raising concerns about possible identity theft, phishing and other forms of fraud targeting people whose information may have been exposed.
The suspected method of entry has drawn particular attention because it illustrates how sophisticated cyberattacks can begin with a relatively simple form of social engineering. Reports indicate that an employee was tricked into interacting with a malicious link in a phishing message, with the incident reportedly involving a technique associated with the so-called ClickFix method. ClickFix attacks typically attempt to persuade a victim to perform seemingly routine actions on their computer, while those actions can instead help attackers establish access. However, the precise forensic reconstruction of the Berlin intrusion remains subject to investigation, so the initial-access method should not be treated as conclusively established.
The incident also raised questions about why the attackers were able to remain inside the network and copy such a large quantity of information before they were detected. Berlin's government has acknowledged that the investigation is examining the causes of the breach and the security weaknesses that allowed it to develop. Authorities have also said that further security measures and structural improvements to the state's IT infrastructure are being planned.
Berlin's decision not to pay the ransom has become another central issue in the aftermath. Officials argued that the state would not give in to blackmail, even though refusing payment carried the risk that the stolen information would be released. That risk ultimately materialised when the attackers published the data. Whether paying would have prevented the publication is impossible to establish, as there is no guarantee that criminals who receive a ransom will permanently delete stolen information or refrain from demanding additional payments.
Authorities have stressed that the breach did not result in the theft or publication of information classified at the highest security levels. Berlin's State Secretary for Digital Affairs, Florian Hauer, said that only data at the lowest classification level had been affected, although the examination of more than 1.2 million files was still ongoing. The government has nevertheless warned that personal information belonging to employees, citizens and businesses may have been included in the stolen material.
The attack highlights a broader challenge facing governments and other large organisations: cybersecurity failures do not necessarily begin with highly sophisticated technical exploits. A convincing message, a deceptive website or a seemingly harmless instruction can sometimes provide attackers with the opening they need. Once inside, however, the scale of the damage can depend on network architecture, monitoring, access controls and how quickly unusual activity is detected.
For Berlin, the immediate priority is now determining exactly what information was taken, identifying people who may be affected and strengthening the systems that allowed the attackers to operate undetected. The incident is also likely to fuel a wider debate over whether government networks are adequately protected against increasingly organised cybercrime and whether refusing ransom demands remains the best strategy when critical public information is at risk.




