A cyberattack on Berlin's state administration has escalated into one of the most serious data breaches in Germany's recent history. The hacker group Rhysida has released nearly six terabytes of data on the dark web, comprising 1,439,893 files. Among them are highly sensitive documents that could have implications for national security.
The leaked material includes a folder titled "AG CBRN-Rahmenplanung," which refers to planning for chemical, biological, radiological, and nuclear threats. This suggests that detailed scenarios for potential attacks or emergencies are now publicly accessible, potentially visible to terrorists or foreign intelligence services. The exposure of such information has alarmed security experts and officials.
Investigative journalist Lars Winkelsdorf, who has been monitoring the breach, described the attack on the social media platform X as "of a magnitude that threatens the state." He noted that the files include LKA (State Criminal Police Office) documents related to ongoing investigations, as well as plans concerning national defense. These range from the federal government's secret communication channels in the event of a catastrophe to emergency plans developed by government agencies and details about defense-related companies.
The breach also compromises the personal data of numerous state civil servants. Birth certificates, absence lists, telephone numbers, and home addresses have been exposed, raising concerns about privacy and potential harassment or targeting of public employees.
The Rhysida group had threatened to release the data unless a ransom of 30 Bitcoin (approximately €2 million) was paid. They set a countdown that expired on Friday afternoon. The Berlin Senate had already stated that it would not yield to such blackmail, a position consistent with its stated principles.
The lack of immediate response from Berlin's administration and political leadership has drawn criticism. As of now, there has been no official statement detailing the extent of the breach or the steps being taken to mitigate its consequences. This silence is troubling given the scale of the leak and the sensitivity of the information involved.
National security implications
The publication of CBRN-related planning documents is particularly worrying. These plans are designed to prepare for chemical, biological, radiological, and nuclear threats, and their exposure could compromise Germany's preparedness. Security analysts warn that the information could be exploited by malicious actors to anticipate or counter emergency measures.
This incident comes amid heightened concerns about cyber threats from state-sponsored actors. Berlin has recently accused Moscow of a drone attack on Leipzig airport, and tensions with Russia remain high. The leak may also be linked to broader geopolitical tensions, though no direct attribution has been made.
The breach also highlights the vulnerability of public administrations across Europe. Similar attacks have targeted other institutions, and the response to such incidents is often slow and inadequate. The European Union has been working on strengthening cybersecurity measures, but this case underscores the urgency of implementing robust protections.
For the affected civil servants, the exposure of personal data could have long-term consequences, including identity theft and personal safety risks. The lack of immediate support from the authorities adds to their distress.
As the situation develops, it is clear that the full impact of this leak is yet to be assessed. The Berlin Senate must act swiftly to address the breach, support those affected, and reassure the public that measures are being taken to prevent future incidents. The incident also serves as a stark reminder of the growing threat posed by cybercriminals and the need for constant vigilance.


