Back to Home Berlin Tightens Cyber Defenses After New Credential Leak Technology

Berlin Tightens Cyber Defenses After New Credential Leak

Published on September 6, 2026 0 views

Berlin authorities tightened safeguards on Sunday after attackers released another package of data stolen in a cyberattack on the German capital's government network. The Berlin Senate Chancellery said the new publication, issued overnight into September 6, included access credentials, turning an already vast data breach into a more immediate risk to administrative systems.

The Senate department responsible for urban development, building and housing reviewed measures introduced after the first release and strengthened some of them as a precaution, the official notice said. Authorities warned that the additional controls could cause short-term restrictions for users of specialist applications operated by the affected department, and said those users would be informed.

The latest disclosure follows an intrusion that Tagesschau reported took place unnoticed from August 7 to August 12 and affected the building and transport departments. Administrators detected the attack on August 14 and disclosed it three days later. Investigators are still establishing the entry route and full scope, so officials have not publicly assigned the breach to a particular security failure.

The ransomware group Rhysida claimed responsibility and said it stole about 5.7 terabytes of material. Tagesschau reported that the cache comprised roughly 1.44 million files and that the group demanded 30 bitcoin, then worth about 2 million euros. Berlin declined to pay, and the attackers began publishing data on the dark web after their September 4 deadline expired.

Authorities and news organizations say a complete inventory remains difficult because of the volume. Tagesschau reported that material reviewed so far includes employee personal information and emergency-planning documents, while Euronews said Rhysida claimed the cache also contained personnel records, payment records, confidential files, passwords and credentials. Those detailed claims remain under investigation, and the precise number of affected people has not been confirmed.

Berlin is assessing the released files with state and federal security bodies and has said identified victims will be contacted according to risk. Germany's federal cybersecurity office has warned that exposed information could enable follow-on phishing, fraud or threats involving critical infrastructure. The new credential release means containment, password protection and continued forensic analysis remain the immediate priorities while officials determine whether the attackers possess more data.

Sources: Berlin Senate Chancellery, Tagesschau, Euronews

Comments