Photo by Ansgar Scheffold on Unsplash
Massive Data Leak from Berlin’s Landesnetz Affects Over 1.4 Million Files
Hackers have released about 1.4 million confidential files stolen from the Berlin state government’s network (Landesnetz) onto the Darknet. The data breach, made public in early September 2026, follows a cyberattack detected on August 14, 2026, where sensitive files including personnel records, timesheets, phone numbers, and confidential government documents were illegally accessed and subsequently leaked. The Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany’s Federal Office for Information Security, has warned of heightened risks following this leak, especially increased phishing attempts targeting those involved or connected to the compromised data [Source 1].
The hacker group Rhysida claimed responsibility for the intrusion and leak. They initially demanded a ransom of around two million euros, which the Berlin Senate rejected, maintaining a strict no-pay stance. After the ransom deadline expired on September 4, 2026, Rhysida published an enormous cache of data weighing approximately 5.8 terabytes, publicly accessible on the Darknet [Sources 3, 4, 6].
Details on the Nature and Scope of the Leaked Data
The released files reportedly include not only personnel records of over 5,000 employees but also sensitive administrative information such as penalty notices, payroll documents, materials from Bundesrat committees, and analyses of crucial infrastructure like the Berlin drinking water supply. Investigations led by Berlin’s Landeskriminalamt (State Criminal Police Office) and the BSI continue to assess the full scale and impact of the breach. The total data set reportedly comprises around 1.44 million individual documents [Sources 3, 4].
The Berlin Senate’s IT departments and several key offices were temporarily disconnected from the Landesnetz for about a week following the cyberattack to contain the damage. This disruption affected public services, including delays in applying for and disbursing housing benefits [Source 4].
Implications for Expats and International Residents in Berlin
For expats, international students, and foreign workers living in Berlin, the cyberattack represents a significant concern regarding personal data security. Those interacting with Berlin public institutions—whether for residency registration, social benefits, or employment—may have sensitive personal information leaked. The BSI emphasizes extra vigilance against potential phishing scams, which commonly follow such breaches to extract further sensitive information like passwords or email addresses [Source 1].
Affected individuals should monitor official communications closely, update passwords, and be wary of suspicious emails or calls purportedly from government agencies. While no direct instructions have been issued, maintaining cybersecurity hygiene and promptly reporting unusual activity could mitigate risks. Additionally, delays in administrative services may occur following ongoing investigations and security upgrades within the Berlin state network [Source 4].
This event, the largest IT security breach in Berlin’s history, underlines the importance of cybersecurity awareness for all residents engaging with public administration systems in Germany’s capital. Expats should familiarize themselves with local data protection advice and official announcements to safeguard their rights and personal information [Source 7].
Further updates and official guidance are expected as the analysis progresses. For more details on the Berlin cyberattack and its aftermath, see the original German reporting at Tagesschau.de [Source 1].