Berlin Probes New Data Leak After Hackers Post Login Credentials
Berlin investigates a fresh data leak after hackers published stolen login credentials, following a Rhysida-linked breach of two city ministries that exposed employee personal...

Executive Summary
German authorities are investigating a second release of data stolen from Berlin's government network after hackers published login credentials and other information online over the weekend. The development follows a cyberattack discovered in mid-August that compromised two city ministries, with the Rhysida ransomware group claiming responsibility for stealing 5.79 terabytes of data. Berlin's data protection authority has confirmed the leak includes personal information about public employees and may also include data belonging to city residents.
Technical Analysis
Berlin's government said Sunday that the newly released data includes login credentials but did not specify which systems they could access or whether they remain valid. The authorities have not attributed this specific release to a threat actor. The initial breach, detected on Aug. 14, affected the ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment. Both ministries had their systems disconnected from the wider government network, causing temporary disruptions to email, internet access, and some public services.
The city's data protection regulator stated that the stolen files contain names, addresses, dates of birth, bank information, email addresses, telephone numbers, correspondence with government agencies, and copies of submitted documents. Officials are still reviewing the large volume of stolen material to determine who may be affected. Berlin has established an additional task force to analyze the leaked data and identify impacted individuals.
Rhysida claimed responsibility for the breach in late August, alleging it stole 5.79 terabytes of data, including tens of thousands of contracts, emails, passwords, and classified information. Berlin has confirmed data was stolen and that it received an extortion demand, but officials have not publicly verified Rhysida's claims regarding the volume or contents of the stolen data. Governing Mayor Kai Wegner stated last month that the city would not pay the attackers, a stance echoed by Chief Digital Officer Florian Hauer, who said, "The State of Berlin will not be blackmailed."
Separately, Germany's Federal Office for Information Security (BSI) warned Friday about a cyberattack campaign linked to the same financially motivated actors behind Rhysida. The BSI did not explicitly name Berlin as a victim but said it was informed in August about a compromise of a government institution. According to the BSI, the campaign resembles the "TerminalFix" attacks recently documented by Microsoft, where hackers compromise websites and display fake CAPTCHA pages that trick visitors into running malicious commands. The BSI linked the campaign to malware known as LoremIpsumLoader, or AxolotLoader, and noted that attackers attempted both data theft and ransomware installation. The agency stated that no connection to state-sponsored actors has been established.
Mitigations & Recommendations
Defenders in government and public administration should treat any credentials exposed in this incident as compromised. Berlin officials should enforce password resets for all potentially affected accounts and implement multi-factor authentication across all systems. Organizations should monitor for suspicious login attempts and review access logs for anomalies, particularly for accounts associated with the affected ministries. The BSI's warning about the fake CAPTCHA campaign underscores the need for user education on verifying website authenticity and avoiding manual execution of unknown commands. Given that stolen data is published in 92 percent of cases where victims appear on Rhysida's leak site, affected entities should assume public disclosure and prepare incident response and communication plans accordingly.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.
