Summary
- Berlin has created a central coordination unit under its chief digital officer after stolen government data was published.
- Police, data protection, information security, and affected departments are jointly assessing the material and prioritising sensitive exposure.
- The incident has moved from network containment into a longer process of data analysis, notification, and public-sector accountability.
The State of Berlin has created a central coordination unit to manage the consequences of its recent cyberattack after stolen government data was published following an unsuccessful extortion attempt.
The unit, established in the Senate Chancellery under Berlin chief digital officer Florian Hauer, is coordinating the review and assessment of the exposed information. It brings together the Berlin State Criminal Police Office, the two affected Senate administrations, the state data protection authority, Berlin’s information security leadership, and other security bodies.
Berlin said the released files are being examined using a risk-based process, with priority given to information that could affect security-sensitive authorities or facilities, citizens, employees, businesses, and organisations that work with the state. Where the review identifies an immediate security concern, the relevant administration is expected to contact the affected body.
The response marks a substantial escalation from the initial incident covered by Cyber Insider in August, when Berlin confirmed that data had been stolen and that the attackers were attempting to extort the state.
A group calling itself Rhysida claimed responsibility and said it had taken 5.7 terabytes of information while demanding 30 bitcoin. Berlin itself presented those figures as claims made by the suspected attackers, and the size and complete contents of the stolen dataset have not been independently established.
By 5 September, however, the publication of stolen material was confirmed. IT forensic specialists and security authorities were examining both affected systems and the released data, while the Senate administrations prepared to notify identifiable individuals where required under the General Data Protection Regulation and Berlin data protection law.
The operational distinction is substantial. Restoring or securing affected infrastructure can end one phase of an incident without ending the exposure created by data theft. Once information has been released, the response shifts towards determining exactly what has escaped, who or what could be affected by its use, and whether particular records create security, fraud, identity, confidentiality, or operational risks.
That task is particularly difficult across a large public administration. Government systems can contain information spanning employees, citizens, contractors, public bodies, correspondence, procurement, and other administrative relationships. Two records taken from the same environment can carry very different consequences, which turns triage and notification into a data-governance problem as well as a forensic one.
Berlin’s decision to centralise the work also addresses the accountability problem created by cross-department incidents. Technical response can sit with security specialists, while decisions about affected people, law enforcement, regulatory duties, and security-sensitive information cross several organisations. Without central ownership, those processes can fragment precisely when speed and consistency are most important.
The incident also demonstrates the continuing leverage available to extortion groups after an organisation refuses payment. Rejecting a ransom does not remove the consequences of stolen data if attackers subsequently publish it, and organisations can remain occupied with notification, investigation, and risk assessment long after the original intrusion has been contained.
Berlin is working with the state criminal police, prosecutors, Germany’s Federal Office for Information Security, and other state and federal security bodies. Separate incident structures also remain active inside the affected departments.
The immediate task has therefore moved beyond establishing that information was taken. Berlin now has to determine what the released material contains, which exposures require intervention, and which people and organisations need to be informed while the criminal and forensic investigations continue.





