Decoding the world of cybersecurity

Berlin breach knocks ministries off network

Two Berlin Senate administrations remain isolated from the state network after a cyberattack disrupted communications and triggered a criminal investigation.

Berlin breach knocks ministries off network
Summary
  • Berlin isolated two Senate administrations after forensic work identified a breach of the state network.
  • Internet, external email, and remote-working capability were disrupted, while any data loss remains unclear.
  • Berlin police, prosecutors, the BSI, and a state crisis team are involved in the investigation and recovery.

A cyberattack on the Berlin state government has forced two Senate administrations off the city’s network, disrupting communications and remote work while investigators establish the extent of the intrusion.

The affected bodies are the Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Environment and Climate Protection. Both were isolated from the Berlin state network after forensic work identified a security breach.

The precaution has had an immediate operational cost. Staff have been left without normal external email and internet access, while home working has also been affected. German reporting quoted one employee describing the administration as effectively unable to work normally without those connections.

Berlin authorities have not established publicly how the attackers gained access, who was responsible, or whether sensitive information was removed. Reports that some information may have left the environment have not been accompanied by a detailed official account of what data were involved.

The Berlin State Criminal Police Office and public prosecutors are investigating, and Germany’s Federal Office for Information Security, the BSI, has been brought into the response. A crisis team led by the state’s information-security representative has also been established.

Containment transfers risk into operations

Disconnecting departments from shared infrastructure is one of the clearest ways to restrict an attacker while the scope of an intrusion remains uncertain. It also exposes how heavily routine government work depends on shared connectivity, identities, applications, and communications.

The two affected administrations cover transport, housing, construction, environmental policy, climate, and urban development. An extended loss of normal network access can therefore slow internal coordination, planning, procurement, case handling, communications with external organisations, and other administrative work even where individual public-facing systems remain available.

The incident illustrates a recurring resilience problem in highly connected public infrastructure. Segmentation can prevent an uncertain compromise from spreading, but effective recovery requires more than switching connectivity back on. Investigators need confidence that affected systems and accounts have been identified, persistence has been removed, and connections can be restored without reopening an attacker’s path through the environment.

That process becomes harder when many departments depend on common infrastructure. A shared government network offers operational and administrative efficiencies, but a security incident can force authorities to choose between continued connectivity and aggressive containment across more than one organisation.

Berlin has so far avoided attributing the intrusion. That restraint is important while forensic work remains incomplete, particularly given Germany’s wider concern about state-linked cyber and hybrid activity. A politically plausible attacker is not the same as a technically established one.

No timetable has been given for restoring full connectivity. Until the affected administrations return to normal service, the incident is as much a continuity problem as a technical investigation: containment has limited one form of risk while creating another for day-to-day government operations.

×