According to the Chinese publication Sohu, about 1,4 million administrative files with a total volume of almost 6 TB ended up on the darknet after a cyberattack on Berlin's government bodies. The hacker group Rhysida, having not received a ransom of 30 bitcoins, published the stolen data publicly on 4 September.
According to a report based on official confirmations from Berlin authorities and media statistics, the attack affected the senate departments of transport, climate and the environment, as well as urban development, construction and housing. The main leak occurred between 7 and 12 August; on 14 August the systems were isolated. The data was extracted from employees' shared folders and personal directories, rather than from specialised professional databases.
The leak includes personnel materials, working time records, payroll statements, telephone numbers, addresses, birth certificates and scanned documents, as well as official correspondence, contracts and internal emergency instructions. Officials emphasise: this does not mean that the data of all Berlin residents has been compromised, and not everyone who has ever contacted these agencies is automatically at risk.
The analysis being conducted by the authorities continues; as of 10 September, no signs of compromise of the voting systems for the state parliament elections or of high-level national security data have been identified. The source notes that the main threat now is "spear phishing": attackers may use real names, addresses and details of enquiries to impersonate government officials or bankers.
The Sohu article provides specific recommendations: do not follow links in suspicious messages, do not disclose confirmation codes, enable two-factor authentication and verify any requests to change data directly on the official websites of the agencies. If fraud is detected, one should contact the police via the Internetwache or local stations, preserving all evidence.
Contacts for enquiries: Datenschutzvorfall@senmvku.berlin.de — for transport and climate matters; Datenschutzvorfall@SenStadt.berlin.de — for construction and housing matters; Cyberangriff@senatskanzlei.berlin.de — for all other cases. Due to the large volume of requests, responses may be delayed.
In essence, the leak exposes how vulnerable even "ordinary" official folders are in government structures, and pushes every resident to treat their own data more carefully.



