Berlin is reviewing a Berlin stolen login credentials leak after a new batch of material from an August cyberattack appeared online. The city said the release includes login credentials, but has not identified the systems they may reach or said whether the credentials remain usable, according to The Record.
That distinction is doing a lot of work. Berlin has confirmed that data was taken and that it received an extortion demand. It has not publicly named an attacker or verified claims about the quantity and contents of stolen material.
What does Berlin know about the published login credentials?
Very little publicly so far. The city said the newly released material contains credentials, while leaving their access scope and validity unresolved. Berlin's urban development ministry has tightened security measures put in place after the earlier disclosure. Officials said some applications may have restricted access temporarily as a result, The Record reported.
The incident concerns departments responsible for urban development and housing, and for transport, mobility, climate protection and the environment. Their systems were detached from Berlin's broader government network on Aug. 14. The departments continued operating, though some staff lost their regular email and internet access and some services were disrupted, according to The Record.
What data may have been exposed?
Berlin's data-protection authority has confirmed that the published material includes personal information on public employees. It said data on Berlin residents may also be involved and that its review is still underway because of the volume of files, The Record reported.
The regulator listed possible categories including names, home addresses, birth dates, bank details, email addresses, phone numbers, correspondence with agencies and copies of documents submitted to the administration. That is a list of potential exposure, not a finding that every category belongs to every affected person.
How is Berlin responding?
Berlin has established an additional task force to examine the material and identify affected people. Reuters reported that a central crisis unit will handle review, verification and impact assessment, as well as efforts to support and notify affected residents and businesses. The city said notification will follow German and European data-protection rules.
Officials reported an initial data leak between Aug. 7 and 12, before the two departmental networks were shut down on Aug. 14, according to the BBC. Reuters reported that stolen data was released on Sept. 5 after an auction advertised by the ransomware group Rhysida ended.
Rhysida has claimed responsibility and said it stole 5.79 terabytes of material. Berlin has not verified that figure, the group's description of the files, or the group's role in the attack. Mayor Kai Wegner has said Berlin will not pay the extortion demand, The Record reported.
Berlin Interior Senator Iris Spranger has said authorities found no evidence that election systems were affected, according to The Record. The city is due to hold an election on Sept. 20.
This story draws on original reporting from The Record.