Berlin says the attackers have published a second package, including login credentials

Tech and AI

Berlin says the attackers have published a second package, including login credentials

By Staff Writer  |  8 September 2026

The red brick clock tower and arcaded upper storeys of Berlin's Red City Hall, with the concrete television tower rising behind it against a pale sky

The city state refused to pay, the first tranche of stolen files went online, and in the early hours of Sunday a second one followed. The federal security office has now linked the intrusion to a campaign that starts with a fake verification page.

Berlin's press and information office issued a short release on Sunday 6 September 2026. In the night from Saturday to Sunday, it said, the perpetrators of the cyberattack on the Berlin state network published a further data package, and its contents include access credentials. The Senate Department for Urban Development, Building and Housing, one of the two departments compromised, reviewed the measures it had introduced after the first publication and tightened some of them as a precaution the same day. Users of its specialist applications were warned of short term restrictions.

The release did not say which systems the credentials belong to or whether they still work, and the state has not publicly attributed the attack to any group. The affected systems were cut off from the wider government network on 14 August, when the intrusion into the urban development department and the department for mobility, transport, climate protection and environment was discovered.

What the state has set up

A day earlier, on Saturday 5 September, the Senate Chancellery had announced a central steering unit under the state's chief digital officer, Florian Hauer, to coordinate the sifting, checking and assessment of the leaked data and to support the two departments in informing and advising affected residents and businesses. The state criminal police, the two departments, the state data protection authority, the state commissioner for information security and other security agencies sit inside it.

The same release describes a risk-based order of work. Where the analysis turns up material affecting security-critical authorities or institutions, the departments contact them at once. Individuals identified in the files are to be informed under the General Data Protection Regulation and the Berlin data protection law, and that applies to people named in the documents as well as to staff.

A very serious crime has been committed against the State of Berlin. The state criminal police and the affected Senate departments are now evaluating the stolen data under high pressure. We will inform, advise and support the affected employees and Berliners as quickly as possible.

Kai Wegner, Governing Mayor of Berlin

The release also asks the public to check what circulates on social networks carefully and not to pass on reports that cannot currently be verified, on the ground that the security of the state depends on it. That is a reference to claims made by the group that has said it carried out the attack, which the state has neither confirmed nor attributed.

The federal warning

On Friday 4 September the Federal Office for Information Security published a security warning, graded at criticality two, headed German institutions compromised through the TerminalFix campaign. It says the office was informed in August of the compromise of a state institution's network, that the subsequent analysis matches the multi-stage attack pattern a large software vendor had recently described under that name, and that reports received indicate the attackers attempted to install ransomware and to exfiltrate data in order to extort victims afterwards with the threat of publication. The warning does not name Berlin.

The pattern the warning describes begins with a compromised website showing a fake verification page that talks the visitor into running a command on their own machine. No exploit is needed. The user does the work.

The independent report of 7 September adds two facts the state releases do not. Berlin's data protection authority confirmed on Friday that the leak includes personal information about public employees and that data belonging to residents may also be exposed, including names, addresses, dates of birth, bank details, email addresses, telephone numbers, correspondence with agencies and copies of documents submitted to the administration. And the breach comes a fortnight before the city's election on 20 September, on which the interior senator has previously said no evidence had been found of data stolen from election systems.

What it means for anyone doing business with the department

The compromised department is the one that handles building, planning and housing for the capital. Its release says plainly that anyone who submitted documents to the administration may find copies of them in the published files. A firm that has applied for a permit, tendered for state work or corresponded with the department on a project should assume its correspondence is in scope until told otherwise, and should treat any message that arrives quoting that correspondence, or asking for credentials, as the next stage of the same attack.