ON
← Back to feed
BSI declares first attack vector on Berlin authorities
Germany🏛️ PoliticsCenter13 hr. ago

BSI declares first attack vector on Berlin authorities

The Federal Office for Information Security (BSI) has warned about a new cyberattack campaign named 'TerminalFix' targeting Berlin's administrative departments. The attack, linked to the cybercriminal group Rhysida, led to significant data leaks and disrupted critical services. The breach began in mid-August 2026 and affected two Senate administrations responsible for urban development, construction, mobility, environment, and climate protection. On August 14th, these agencies were disconnected from the state network, causing issues such as the inability to pay housing benefits to 50,000 households. By August 24th, all systems were restored, but authorities confirmed data had been stolen, though details remained undisclosed. On August 28th, the Berlin government rejected ransom demands, while reports suggested the attackers might have accessed sensitive documents including over 46,500 contracts. Experts warn of potential identity theft and fraud.

Advertisement

Go to the primary sources (12)

The official sources this coverage is built on. Read them directly to bypass framing.

12 reports

Der Spiegel logoDer SpiegelIndependentCenterFactual 95Objective 90yesterday
Berlin: Hacker group Rhysida releases another data package from Leak

A further data package from a large-scale hacking attack on Berlin's Senate administration was published overnight on Sunday. The Senate announced this after initial stolen information was released on Friday. Additional measures were implemented to strengthen security in some aspects, which could temporarily restrict certain professional procedures in the building administration. Users were informed about these changes, though specific details remained undisclosed. The hacker group Rhysida gained access to parts of Berlin’s state network between August 7th and 12th, targeting the Senate departments for Construction and Transport. The breach was discovered on August 14th and made public three days later. The hackers demanded two million euros in Bitcoin ransom, but the city refused to pay. By the deadline on Friday, approximately 1.4 million files were available for download.

Bias read (Center): The article presents factual developments related to a cybersecurity incident involving government institutions without overtly favoring any political stance. It reports on the actions taken by the Senate, the hacker group's demands, and the outcome without expressing judgment or ideological leaning

Why factuality (95): The article accurately reports the leak from the Berlin Senate administration by Rhysida, including the timeline of events, the response measures taken by the Senate, and the nature of the data stolen. It aligns closely with the primary source document and does not introduce any unverified details.

Why objectivity (90): The article maintains a neutral tone throughout, presenting facts without overt bias or emotional language. It avoids taking sides and sticks to reporting what was stated by officials.

Deutsche Welle (Deutsch) logoDeutsche Welle (Deutsch)State / PublicCenterFactual 90Objective 952 days ago
BSI sees threats after cyber attack on Berlin administration

The Federal Office for Information Security (BSI) has warned of increased risks following a cyberattack on Berlin's administration, which resulted in stolen data being published online. The BSI highlighted potential dangers such as targeted phishing attacks and possible 'hack-and-leak' operations, especially ahead of upcoming elections on September 20. However, the BSI does not believe the hackers had political motives, stating the attack was likely financially motivated. The hacker group Rhysida had previously demanded a ransom of 30 Bitcoin (around two million euros), but Berlin refused to pay. As a result, the group released 5.8 terabytes of data into the dark web, including personal records, disciplinary actions, salary calculations, confidential documents from federal committees, and vulnerabilities in Berlin’s water supply system. It remains unclear whether claims about access to login credentials and passwords are accurate.

Bias read (Center): The article presents information from the BSI and Berlin officials without overtly favoring any political side. It discusses cybersecurity threats and their implications for both individuals and society, while noting the lack of evidence for political motives behind the attack. The tone is neutral,

Why factuality (90): The article accurately reports the concerns raised by the BSI regarding phishing risks and the potential for hack-and-leak operations. It also correctly states that the attack appears to be financially motivated rather than politically driven, aligning with the primary source.

Why objectivity (95): The article presents information objectively, citing statements from the BSI and quoting officials without editorializing or showing bias. The tone remains professional and balanced.

heise online logoheise onlineIndependentCenterFactual 85Objective 806 days ago
Berlin: Passwords leaked and 12,000 systems scanned

The Berlin Senate confirmed that passwords for several specialized systems were leaked during a cyberattack targeting two of its departments, which began at least mid-August. The attack led to the exposure of clear-text password lists stored in Office files, along with thousands of contracts, legal documents related to ongoing cases, and scanned ID cards. The ransomware group 'Rhysida' claimed responsibility and posted screenshots on their dark web site, demanding 30 Bitcoins (approximately €2 million) as ransom. Although the affected departments were disconnected from the state network in early August, they were reconnected by late August, with officials stating the attack had been contained. However, concerns remain about potential exposure of personal or non-public data.

Bias read (Center): The article presents factual information about a cyberattack on Berlin's government agencies, including confirmation from the Senate spokesperson and details provided by the ransomware group. It does not exhibit overtly biased language, one-sided sourcing, or editorializing that would indicate a sla

Why factuality (85): The article reports on a cyberattack on Berlin's Senate departments, citing statements from the Senate spokesperson Christine Richter and confirming details from the ransomware group 'Rhysida' regarding stolen passwords and data. It aligns with the primary source document by providing specific dates

Why objectivity (80): The tone remains neutral, focusing on reporting facts and official statements. However, there is a slight emphasis on the severity of the breach and the potential risks, which could be seen as slightly more alarmist than purely objective.

heise online logoheise onlineIndependentCenterFactual 85Objective 809 days ago
30 Bitcoin or Leak Ransomware gang blackmailed by Berlin

A cyberattack on Berlin's Senate administration, attributed to the ransomware group 'Rhysida,' has resulted in the theft of over 5.8 terabytes of data. The attackers have demanded 30 Bitcoins (approximately two million euros) in exchange for not releasing the stolen information. According to reports, the group has previously targeted institutions such as the British National Library and the city of Stuttgart using similar tactics. Berlin has refused to pay the ransom, stating it will not yield to extortion. The leaked data reportedly includes contracts, legal documents, login credentials, and sensitive information related to critical infrastructure and emergency plans. The exact nature and sensitivity of the data remain unclear, but authorities have confirmed the breach and are investigating the incident.

Bias read (Center): The article presents the situation objectively, citing multiple sources including the Spiegel and official statements from Berlin's leadership. It does not favor either side in the dispute between the hackers and the city, nor does it exhibit biased language or selective reporting. The framing is un

Why factuality (85): The article accurately reflects the situation as described by the Spiegel, including the threat of data leaks and the involvement of Rhysida. It cites the Spiegel as a source and presents the information in line with the primary document, maintaining consistency with other reports.

Why objectivity (80): The article maintains a neutral tone, focusing on the facts without injecting personal opinion or emotional language. It avoids taking sides in the dispute between the city and the hackers.

Die Zeit logoDie ZeitIndependentCenterFactual 80Objective 759 days ago
Hacker attack on Berlin administration: Berlin Senate office silent on extortion by hackers

Hackers have allegedly extorted the city of Berlin by threatening to release stolen data, demanding 30 bitcoins (approximately two million euros). The Berlin Senate has remained silent on the specifics of the hackers' demands, the nature of the data compromised, and the identity of the perpetrators. According to a report by *Spiegel*, the hacker group Rhysida, known for previous attacks, is suspected of being behind the breach. The attackers reportedly accessed sensitive information, including data from administrative procedures and passwords, though the extent of the breach remains unconfirmed by authorities. Following a special session of the Senate, Mayor Kai Wegner (CDU) and Interior Senator Iris Spranger (SPD) confirmed the cyberattack but provided no further details, emphasizing that Berlin would not yield to extortion.

Bias read (Center): The article presents factual information about a cyberattack on Berlin's administration without overtly favoring any political side. It reports on the situation neutrally, citing official statements and third-party sources like *Spiegel* without apparent ideological framing.

Why factuality (80): This article provides detailed information about the cyberattack, including the involvement of the Rhysida group and the amount demanded. It references the Spiegel report and includes quotes from officials, supporting its factual basis. However, it mentions the Spiegel's report as a source without p

Why objectivity (75): The tone is slightly more critical towards the government’s response, suggesting that they are withholding information. This could be seen as a subtle editorial stance rather than purely objective reporting.

Tagesschau (ARD) logoTagesschau (ARD)State / PublicCenterFactual 80Objective 7510 days ago
Hackers demand ransom after attack on Berlin state network

On August 28, 2026, Berlin confirmed that it had received a ransom demand following a cyberattack on the city’s state network. The attack reportedly began at least a week earlier, with data leakage starting as early as August 7, a week before the breach was discovered. The attackers are believed to be known to the Senate, according to informed sources. Berlin’s Governing Mayor Kai Wegner stated that the city would not pay the ransom and emphasized that the attack constituted a serious criminal act. The incident has triggered investigations by the State Criminal Police Office and the Berlin Public Prosecutor’s Office, working closely with federal security agencies. While some parts of the network were isolated for security reasons, the Senate assured that critical election-related systems remained fully secure. The attack is described as the largest cyber incident experienced by the city to date.

Bias read (Center): The article presents factual information about a cyberattack on Berlin's state network, including confirmation of a ransom demand, the timeline of the breach, and responses from officials. It does not exhibit overtly biased language, one-sided sourcing, or omissions that would indicate a clear lean.

Why factuality (80): This article is primarily promotional content for the Spiegel subscription service, though it contains relevant information about the cyberattack and the ransom demand. It aligns with the Spiegel's reporting and supports the factual claims made in the primary source.

Why objectivity (75): While the article itself is promotional, the content related to the cyberattack is presented neutrally. However, the overall tone leans slightly toward promoting the Spiegel brand, which may affect perceived objectivity.

Frankfurter Allgemeine (FAZ) logoFrankfurter Allgemeine (FAZ)Independent🔒CenterFactual 75Objective 808 days ago
Data theft: What Berlin politicians say about blackmail by hackers

The article discusses a cybersecurity incident in Berlin where hackers, identified as the group Rhysida, have threatened to release sensitive data unless the city pays a ransom of 30 Bitcoins (approximately two million euros). The attack, which occurred on August 14, involved stolen data including over 80,000 traffic violation records, more than 46,500 contracts, and nearly 6,000 login files. Berlin's governing mayor, Kai Wegner (CDU), confirmed the breach but did not disclose specific details about the data or the ransom demand. Political leaders across parties generally support refusing to pay, though there is some debate over whether the city should improve its IT security. The issue has sparked discussions about past neglect of cybersecurity funding.

Bias read (Center): While the article covers a politically sensitive cybersecurity issue, it presents information without overt ideological slant. It reports on both the technical aspects of the hack and the political responses, emphasizing the lack of consensus on the matter while noting the general alignment among政党.

Why factuality (75): The article reports on a cybersecurity incident involving Berlin officials being extorted by hackers, citing statements from Mayor Kai Wegner and mentions a potential ransom demand of 30 Bitcoin. It references a report from 'Der Spiegel' about threats in the dark web. However, it does not reference

Why objectivity (80): The article presents the situation neutrally, reporting on political reactions and the mayor’s stance without taking sides. It includes quotes from officials and media, maintaining a balanced tone. There is no evident bias or emotional language, though it focuses on the political implications of the

Die Zeit logoDie ZeitIndependentCenterFactual 70Objective 859 days ago
IT security: Berlin Senate Chancellery: No comment on the blackmailers

On August 29, 2026, Berlin’s Governing Mayor Kai Wegner (CDU) and Interior Senator Iris Spranger (SPD) informed the public about a cyber extortion attempt targeting the city’s administration. The attack, which was revealed on August 14, involved hackers gaining access to sensitive data including records of petty offenses and passwords. While the perpetrators demanded 30 Bitcoin (approximately €2 million), the authorities have not disclosed specific details about the stolen data or the identity of the attackers. The city has maintained silence on these matters due to ongoing investigations, citing 'investigative tactical reasons.' Although initial reports suggested only publicly accessible data had been compromised, the Senate later admitted this was not accurate. The group responsible for the attack, Rhysida, is known for using malware in ransomware campaigns.

Bias read (Center): The article presents information about a cybercrime affecting public administration without overtly criticizing or praising any political faction. It reports on the actions of officials and the nature of the cyberattack without taking a clear ideological stance. The framing remains neutral, focusing

Why factuality (70): The article confirms the ransom demand and the involvement of the hackers, but lacks specific details about the nature of the data involved or the exact timeline. It relies on reports from other media outlets like the rbb, which may introduce some uncertainty.

Why objectivity (85): The article remains largely neutral, focusing on the confirmation of the ransom demand and the official response. There is no evident bias or emotional language used.

Handelsblatt logoHandelsblattIndependent🔒CenterFactual: no official source document/info detectedObjective 702 days ago
Data super-GAU in Berlin what the consequences are now

The article titled 'Daten-Super-GAU in Berlin – welche Folgen jetzt drohen' by Handelsblatt discusses a major data security incident in Berlin, referred to as a 'data super-disaster.' The incident involves unauthorized access to sensitive personal data, raising concerns about cybersecurity vulnerabilities in public administration. Authorities are investigating the breach, which has led to calls for stricter data protection measures. The article highlights potential legal consequences for those responsible and emphasizes the need for improved digital infrastructure to prevent future breaches.

Bias read (Center): The article presents the data breach as a serious issue without overtly criticizing or praising specific political actors. It focuses on the technical and administrative implications of the incident rather than taking a partisan stance. While the article underscores the importance of cybersecurity,它

Why factuality: no official source document/info detected

Why objectivity (70): The article uses somewhat alarmist language with phrases like 'Daten-Super-GAU,' which could influence reader perception. While it doesn't clearly favor one side, the tone leans toward emphasizing the gravity of the situation.

Frankfurter Allgemeine (FAZ) logoFrankfurter Allgemeine (FAZ)Independent🔒Center13 hr. ago
Hackers attack in Berlin: damage analysis will take 'a few more weeks'

A hacker attack on two Berlin Senate administrations has caused significant disruption, with IT technicians still working to fully assess the damage. Over 1.2 million files totaling 5.7 terabytes were stolen and later published in the dark web. The download process is taking several days due to limited bandwidth, as the data was stored on poorly connected servers. Experts plan to use artificial intelligence to prioritize sensitive files before manual review by staff. While some data includes personal employee information and critical infrastructure plans, officials currently do not believe national defense capabilities are at risk. The attack is attributed to the hacking collective Rhysida, which is suspected of having Russian ties based on sophisticated tactics, though no direct attacks on Russian entities have been reported.

Bias read (Center): The article presents factual information about the cyberattack without overtly favoring any political stance. It reports on the technical aspects of the breach, the involvement of cybersecurity experts, and the attribution to a hacking group without clear ideological slant. While there is mention of

heise online logoheise onlineIndependentCenter16 hr. ago
National security at risk: Berlin data leak makes waves

A major cyberattack on Berlin's municipal network has exposed sensitive data, raising national security concerns. The attack, attributed to a Russian-speaking ransomware group called Rhysida, resulted in the leakage of approximately 1.44 million files, including personal records, contracts, passwords, and highly sensitive documents related to civil defense plans, military infrastructure, and critical utilities. The breach affected two Senate departments responsible for urban development and mobility, which operate their own IT systems. Federal agencies, including the National Cyber Defense Center and the Federal Office for Security in Information Technology (BSI), have begun assessing the risks. A CDU politician described the incident as a serious threat to national security, emphasizing the need for heightened cybersecurity measures across federal interfaces.

Bias read (Center): The article presents a balanced account of the cyberattack's impact on both local and national levels, citing official sources such as the BSI and federal agencies. While there is concern over national security, the tone remains objective, avoiding overt ideological framing. The emphasis is on the事实

heise online logoheise onlineIndependentCenter17 hr. ago
BSI declares first attack vector on Berlin authorities

The Federal Office for Information Security (BSI) has warned about a new cyberattack campaign named 'TerminalFix' targeting Berlin's administrative departments. The attack, linked to the cybercriminal group Rhysida, led to significant data leaks and disrupted critical services. The breach began in mid-August 2026 and affected two Senate administrations responsible for urban development, construction, mobility, environment, and climate protection. On August 14th, these agencies were disconnected from the state network, causing issues such as the inability to pay housing benefits to 50,000 households. By August 24th, all systems were restored, but authorities confirmed data had been stolen, though details remained undisclosed. On August 28th, the Berlin government rejected ransom demands, while reports suggested the attackers might have accessed sensitive documents including over 46,500 contracts. Experts warn of potential identity theft and fraud.

Bias read (Center): The article presents a factual account of a cybersecurity incident involving government institutions without overtly favoring any political stance. It provides balanced reporting by citing official sources like the BSI and Microsoft, and includes quotes from multiple officials without taking sides.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories