Cybersecurity / Government Breach
Berlin’s 1.4M-File Leak Exposes Governments’ Vendor Blind Spot
By NeuralWired Staff | September 12, 2026
A ransomware crew called Rhysida just dumped 1.4 million files stolen from Berlin’s state government onto the dark web. Berlin refused to pay. The hackers published anyway. That part of the story is simple.
The part that should worry every CISO reading this from Toronto to Canberra is quieter: how Berlin’s own external IT vendors ended up sitting on unchecked access to government networks, and why that same failure keeps showing up in breach after breach across 2026. This Berlin cyberattack data leak isn’t really a phishing story. It’s a supply-chain story wearing a phishing story’s clothes.
In this article
The Berlin breach timeline, confirmed
Rhysida broke into networks belonging to two Berlin Senate departments, urban development and housing, plus mobility, transport, climate protection and the environment, sometime between August 7 and 12, 2026. Forensic investigators dated the exfiltration to that window after the fact. Berlin didn’t notice until August 14, when it disconnected the affected departments from the state network.
Twelve days later, Germany’s Federal Office for Information Security (BSI) was told a state institution had been compromised. By August 28, Rhysida’s ransom countdown had expired. The group listed “Berlin, Germany” on its leak site: 5.79 TB, roughly 1.44 million files, a demand of 30 Bitcoin, worth around 2 million euros. Governing Mayor Kai Wegner didn’t blink.
“The State of Berlin will not give in to blackmail.” Kai Wegner, Governing Mayor of Berlin, via OODAloopThe deadline lapsed on September 4 without payment. The next afternoon, Rhysida published the full dataset, 1,439,893 files, a number German public broadcaster Tagesschau independently corroborated. BSI raised its public threat level the same day. Two days later a second tranche appeared, this time containing login credentials tied to both ministries. Berlin has confirmed the release but hasn’t said whether those credentials still work.How they actually got in
Here’s where a lot of coverage has gotten sloppy, and where accuracy actually matters for anyone trying to defend against the next one. On September 5, BSI publicly attributed the initial entry to a technique it calls “TerminalFix,” a variant of the ClickFix social engineering pattern Microsoft first flagged back in February 2026.The mechanics are almost insultingly simple. A victim lands on a fake CAPTCHA page. The page instructs them to open Windows Terminal or PowerShell and paste in a command to “verify” they’re human. They do it. That command is the payload. No exploit, no zero-day, just a user doing exactly what an official-looking screen told them to do.Why this matters for the headline This was not a MOVEit-style software supply chain compromise. BSI’s technical notice describes a phishing and social-engineering vector aimed at end users, reported by heise online. Conflating that with “a vendor got Berlin hacked” is a real accuracy risk, and one worth flagging before the narrative hardens.The real story: Berlin’s vendor blind spot
So if phishing got Rhysida in the door, why is this a third-party story at all? Because the entry vector and the reason the blast radius exploded are two different questions, and Berlin answers the second one badly.German tabloid BILD ran an investigation on September 6 built on insider sources inside Berlin’s Senate and district administrations. It described Windows Exchange servers sitting in unlocked rooms, including one in a broom closet. HR staff, not IT staff, handling cybersecurity duties in some departments. Internal data routinely stored in unencrypted Word files. And, most relevant here, external IT service providers, with the state-owned ITDZ named specifically, holding what BILD characterized as effectively unchecked, direct write access into Senate networks.That’s not a hypothetical risk. It’s the same failure mode that shows up in a separate, earlier incident: in June 2025, a hack of an external service provider fully compromised site plans for Berlin’s water and electricity infrastructure. BILD has since suggested that hack may connect to a string of later incidents, a January power-grid disruption, a March 2026 attack on a Neukölln heating plant, a July 2026 outage at Berlin’s courts. That causal chain is currently single-sourced to BILD’s reporting and hasn’t been independently confirmed, so treat it as a lead worth watching rather than an established fact.Then there’s the twist that makes this a genuinely recursive supply-chain problem. Buried in Rhysida’s leaked dataset are roughly 46,500 supplier and third-party contracts. Berlin’s breach didn’t just expose Berlin. It handed attackers a fresh map of Berlin’s own vendor relationships, which is exactly the raw material used to target the next set of victims.“I cannot deny that.” Matthias Hundt, former State Secretary for Digital Affairs, Berlin, responding to BILD’s report of his own internal warning that Berlin’s networks were “wide open,” via UNITED24 MediaHundt was dismissed from his post before the breach became public, and he’s currently in a legal dispute with the state, so his motive for candor is worth reading with a raised eyebrow. But the underlying warning, that nobody had a clear inventory of which systems ran where, on what software, at what security level, is exactly the condition that lets a single phished credential turn into a 1.4-million-file dump.MOVEit and the pattern that won’t die
Berlin isn’t an outlier. It’s a data point in a trend that’s been accelerating for three years, and Verizon’s annual Data Breach Investigations Report has been tracking it precisely.
DBIR Edition Third-party involvement in breaches 2023 15% 2024/25 30% 2026 48% That jump from 30% to 48% is described as the largest single-year shift in the report’s history, per analysis summarized by Passwork. The reference case everyone in this field still cites is MOVEit. A SQL injection flaw in Progress Software’s file-transfer tool, exploited from May 2023 onward, ultimately touched more than 2,773 organizations and somewhere north of 93 million people, including U.S. federal agencies and multiple state governments. One vendor, hundreds of downstream victims. Berlin’s ITDZ arrangement is the same architecture with a different name.NeuralWired covered a fresh instance of this exact pattern the same week Berlin’s leak went public: the PaperCut vulnerability that hit 440 organizations. Different software, same root cause, one shared dependency compromised once, damage fans out everywhere it touches.What Rhysida claims it stole
Rhysida’s own categorization of the dataset, which is the attacker’s claim and not yet independently verified by Berlin, includes around 12,000 personnel files with passport scans and payroll data, more than 80,000 administrative fine proceedings, over 3,200 NDAs, roughly 6,000 passwords or credentials, 148 IBAN numbers, and a folder labeled for chemical, biological, radiological and nuclear threat-scenario planning.Read the headline number carefully Of the 1.44 million files claimed, about 124,823, roughly a quarter, are maps and geodata. File count and terabyte volume make for a dramatic headline, but they’re a poor proxy for actual harm. The genuinely sensitive subset, personnel records, credentials, CBRN planning documents, is a smaller and more serious slice of the total, according to reporting from Infosecurity Magazine.The never-pay calculus, and its cost
Refusing to pay ransomware demands is what CISA, the FBI, and BSI all recommend, and Berlin followed that guidance. But guidance and consequence-free are not the same thing. By refusing, Berlin converted a contained extortion attempt into a permanent, public archive of defense-adjacent material, now sitting on the dark web where any actor, hostile intelligence services included, can pull from it indefinitely. That tension rarely gets acknowledged in coverage that treats “never pay” as a clean win. It’s the right call. It’s also not a free one.Add to that a detail worth watching: security researcher Max Kilger, professor of practice at the University of Texas at San Antonio, has raised the possibility that the compromised Berlin systems may share network connections with broader German federal infrastructure, which would push this well past a municipal incident if confirmed, as reported by UNITED24 Media.Attribution to Russia is circulating in German reporting but remains, in the words of officials themselves, an internal suspicion rather than a formal finding. Berlin’s Senate Chancellery has not confirmed it. Treat any Russia claim you see elsewhere as unconfirmed until BSI says otherwise.What this means for your organization
If you run security for a government agency, a contractor to one, or any enterprise with vendor-integrated systems touching regulated data, Berlin isn’t a distant news story. It’s a checklist.
- Audit standing vendor access now. Not an annual questionnaire, an actual technical inventory of which external providers can write to production or citizen-data systems, and whether that access is scoped or just-in-time.
- Harden against TerminalFix-style ClickFix attacks. Restrict direct PowerShell and Windows Terminal invocation through Win+X, disable clipboard-triggered command execution where feasible, and train staff specifically against “paste this to verify you’re human” prompts.
- Assume vendor contract data is now attacker intelligence. If your organization has ever contracted with a Berlin state agency, the leaked supplier database is worth checking against your own exposure.
- Move toward zero-trust architecture for third-party connections, not as a buzzword but as credential vaulting, network segmentation, and continuous verification instead of standing trust.
- If you’re EU-based, map this against NIS2 and DORA obligations. An ITDZ-style unchecked-vendor-access failure is close to a textbook violation of both.
The average supply-chain breach now costs $4.91 million and takes 267 days to identify and contain, according to IBM’s Cost of a Data Breach research. That’s the number your board should be looking at, not the file count.
The supply chain attack angle that’s easy to miss
Our read: the industry keeps treating each of these incidents as a discrete news event, MOVEit, Berlin, whatever comes next, when they’re really the same structural gap recurring under different names. Ninety percent of organizations reported experiencing a third-party breach in the past year, per a ProcessUnity survey published in January 2026 (a vendor-sourced figure worth a methodology caveat, but directionally consistent with everything else in this piece). Germany specifically ranked fourth globally for ransomware targeting in the first half of 2026, with 176 claimed victims, per CybelAngel. Berlin was not unlucky. Berlin was next.Frequently asked questions
Who hacked Berlin’s government?
The Rhysida ransomware group claimed responsibility for the breach of Berlin’s state administration. Rhysida is a ransomware-as-a-service operation active since mid-2023 with reported technical overlap to the earlier Vice Society group. Germany’s BSI has not formally confirmed nation-state attribution as of September 2026.How many files were leaked in the Berlin data breach?
Rhysida published roughly 1,439,893 files totaling 5.79 terabytes on September 5, 2026, after a 2 million euro ransom demand went unpaid. German broadcaster Tagesschau corroborated the file count independently.Did Berlin pay the ransom?
No. Governing Mayor Kai Wegner said Berlin would not give in to blackmail. The city refused Rhysida’s 30 Bitcoin demand, and the group published the full stolen dataset once the September 4 deadline passed.How did the hackers get into Berlin’s network?
Germany’s BSI confirmed the attackers used “TerminalFix,” a ClickFix-style social engineering technique. Fake CAPTCHA pages trick users into manually running PowerShell commands through Windows Terminal, giving attackers an initial foothold without exploiting any software vulnerability.What is a third-party data breach?
A third-party data breach happens when an organization’s data is exposed through a vendor, contractor, or supplier’s systems rather than a direct compromise of the organization itself. Verizon’s 2026 DBIR found third parties involved in 48% of breaches analyzed, up from 30% the year prior.Is Rhysida a Russian hacking group?
That’s not formally confirmed. Some German reporting describes the Berlin attackers as internally suspected of Russian ties, but neither BSI nor Berlin’s Senate Chancellery has made that attribution official as of this writing.
Where this goes next
What you should take from Berlin isn’t that phishing is scary, you already knew that. It’s that the size of the disaster had almost nothing to do with how attackers got in, and everything to do with how much unmonitored, unscoped access was sitting there waiting once they did. That’s an infrastructure and governance failure, not a training failure, and it’s fixable in a way a zero-day isn’t.Watch three things over the next six to eighteen months: whether Kilger’s federal network-connection concern turns into a confirmed wider breach, whether the BILD-reported chain linking the June 2025 vendor hack to Berlin’s power, heating, and court disruptions gets independent verification, and whether the September 20 Berlin election, held weeks after this leak, produces any follow-on security questions despite officials’ current assurances. If Verizon’s third-party trend line keeps climbing the way it did this year, Berlin will not be the last government body writing this same story with a different city’s name on it.Want breach analysis like this before it hits your feed? Subscribe to The Neural Loop at neuralwired.com/newsletter.Related Posts
Scroll to Top


