Summary
- Berlin has confirmed data left systems during the August cyberattack, with personal or other non-public information potentially involved.
- The city has rejected an extortion demand while criminal investigators, prosecutors, and federal security agencies investigate the alleged perpetrators.
- Officials say there is currently no evidence that election data was compromised, while forensic work across the state network continues.
Berlin has confirmed that data was taken during the cyberattack on its state administration network, adding an extortion attempt to an incident that had already forced government departments to disconnect systems.
Forensic investigations found that data had left systems operated by the Senate Department for Mobility, Transport, Climate Protection and the Environment. Officials are still examining the scope and content of the information and say personal data or other non-public material may be involved.
Berlin believes the data outflow occurred between 7 and 12 August. The affected Senate departments were disconnected from the state network on 14 August as officials moved to contain the incident. Cyber Insider reported on the disruption earlier in August, when the extent of the compromise remained unclear.
The latest findings establish that the incident went beyond disruption. Governing Mayor Kai Wegner said Berlin is being blackmailed and that the Senate will not meet the attackers’ demands. The State Criminal Police Office, public prosecutor’s office, and federal security agencies are investigating the alleged perpetrators.
Berlin has not publicly attributed the attack to a named group. Nor has it disclosed the quantity of data taken, the initial access route, or the terms of the extortion demand. Those points remain unresolved while investigators establish which systems and information were reached.
The State Data Protection Commissioner and Germany’s Federal Office for Information Security are being kept informed, reflecting the regulatory consequences that can follow when a compromise of government infrastructure also creates potential personal-data exposure.
The attack has also raised questions because it comes ahead of elections to Berlin’s House of Representatives. Interior Senator Iris Spranger said officials currently have no evidence that election data was compromised and that the election environment is considered secure.
Administrative and electoral infrastructure should not be treated as interchangeable. Compromise elsewhere in a government estate does not demonstrate access to election systems, and Berlin’s current findings do not support that conclusion.
The city’s ICT emergency response team remains active while forensic analysis and review of the state network continue. That work now has to establish both the technical boundaries of the intrusion and whether information taken during the incident creates further obligations to affected people or organisations.
Large public administrations can be particularly difficult environments to investigate because technology, suppliers, data holdings, and operational responsibilities are distributed across departments. Disconnecting affected systems can reduce further exposure, but restoration has to proceed while investigators are still establishing what an attacker reached and whether access persists elsewhere.
The extortion attempt adds a separate governance decision. Refusing payment does not recover information already taken or guarantee that it will not later be released, but public bodies also face legal, political, and precedent-setting consequences if they transfer money to criminal groups whose identities and affiliations may not yet be established.
Berlin’s response is therefore moving beyond initial containment into a longer assessment of confidentiality, recovery, notification, and accountability. The extent of that work will depend heavily on what investigators establish about the information removed from the affected departments.
Three points that were unclear when the incident first emerged are now established: data left government systems, the attackers have made an extortion demand, and the Senate says it will not pay. Attribution, the full scale of the data loss, and the route into the network remain under investigation.





