That difference matters. A headline built around an exact multi-terabyte figure can imply a settled measurement and a completed assessment. Berlin’s own wording is more restrained: a group calling itself Rhysida says it possesses 5.7 TB of stolen data, while investigators continue to examine the content and scale of the outflow. Separate reporting described an auction involving 5.79 TB, and an initial online release of roughly 5.3 TB out of an alleged 5.8 TB, with about 1.4 million documents. Those figures may describe the attackers’ material and claims, but they are not a final government-verified accounting.
For residents, government employees, suppliers and IT teams, the practical story is therefore not only the apparent size of the leak. It is the possibility that published records and credentials can enable targeted fraud, phishing, account compromise and pressure against organisations while the scope is still being established.
What Berlin has confirmed
Berlin has confirmed an IKT security incident affecting its state network. In the course of forensic examinations, the state network was found to have been compromised. On August 14, 2026, Berlin isolated two Senate administrations from the state network for security reasons:
- Urban Development, Building and Housing
- Mobility, Transport, Climate Protection and Environment
Isolation was a containment action, not proof that every system in either portfolio had been accessed or that all their information had been removed. It does, however, show that officials viewed separation from the wider network as necessary during the incident.
Berlin later identified additional data outflow in the Mobility, Transport, Climate Protection and Environment portfolio. Officials placed that activity between August 7 and August 12—before the August 14 network isolation. The city said at that stage that both the content and the scale of the outflow remained under examination.
The sequence is significant for incident analysis. Containment can prevent further lateral movement or further loss, but it cannot reverse data copied before a system or departmental network is disconnected. The gap between the identified outflow window and the isolation date helps explain why Berlin’s work has shifted toward reviewing already-exposed data as well as securing the affected environment.
Berlin had activated an IKT emergency crisis staff by August 17. On August 28, it publicly rejected the extortion attempt, saying it would not allow itself to be extorted. That decision establishes the city’s public position, but it does not eliminate the operational consequences of a data-theft incident: attackers can publish material regardless of whether a victim pays.
Rhysida’s claim is not a completed forensic finding
On September 3, Berlin said that a group calling itself Rhysida had claimed responsibility and claimed possession of 5.7 TB of stolen data. The group offered the material for auction with a reported minimum bid of 30 bitcoin.
This is the appropriate level of certainty: Rhysida publicly claimed responsibility and claimed a volume; Berlin confirmed the claim was made. The dossier does not support presenting the group’s identity as conclusively established by public investigators, or its stated data volume and contents as independently verified.
That distinction is more than legalistic caution. Threat actors can accurately possess stolen material while overstating its quantity, completeness, sensitivity or currency. A large archive can include duplicates, outdated exports, public documents, system artefacts and files of widely varying significance. Conversely, even a small number of documents or valid credentials can create serious risk if they relate to people, security operations, financial processes or critical services.
As of September 7, Berlin had not publicly released a finished forensic inventory establishing that exactly 5.79 TB was exfiltrated and published, or that a precise number of files had been removed. Nor had it publicly authenticated the more detailed attacker-supplied descriptions of document categories, individual records or affected populations.
The right conclusion is neither that the attackers’ assertions are necessarily false nor that every published count is a confirmed fact. The evidence supports a confirmed theft-and-publication incident with an unresolved full scope.
Publication changed the response priority
Berlin confirmed on September 4 that stolen data had been published. State-contracted IT forensic specialists were examining the released material intensively. This marks a meaningful escalation: a contained network incident can be investigated inside a controlled environment, but a public release creates continuing exposure even after technical containment.
The city said it would identify and inform affected people on a risk basis, under the applicable data-protection rules. This is a commitment to notification after identification and assessment; it should not be read as confirmation that every potentially affected person had already been contacted.
Risk-based triage is a practical necessity when investigators face a potentially huge and unstructured archive. The first questions are likely to be whether the material contains personal data, whether it creates an immediate security issue, whether it contains usable authentication information, and whether specific public bodies, companies or individuals need urgent warning. Berlin said that if its assessment produced immediately relevant findings concerning security-critical authorities or institutions, the affected Senate administrations would contact them without delay.
On September 5, Berlin created an additional central steering unit in the Senate Chancellery, led by Chief Digital Officer Florian Hauer. This was not the beginning of the incident response; it was an added coordination structure after the existing crisis work and after the data publication. Its remit includes reviewing, verifying and assessing the outflow data, supporting notification and advice for affected citizens and companies, and ensuring that relevant state and federal bodies receive information about security-relevant findings.
The structure brings together the affected administrations, state criminal police, data-protection and information-security functions, and other security bodies. That cross-government arrangement reflects the problem created by a data leak: the technical question of what happened cannot be separated from legal notification duties, potential criminal investigation, service continuity and the protection of third parties.
Credentials make the September 6 release especially urgent
A further attacker data package was published overnight into September 6. Berlin said the package included access credentials.
Credentials deserve particular attention because their risk is different from that of an ordinary historical document. If valid and still usable, they can provide a path into email accounts, specialist applications or other systems. Even credentials that are old, revoked or restricted may still aid attackers by revealing usernames, naming conventions, departmental roles or likely password-reuse targets.
Berlin did not disclose the number of credentials, their validity, the systems to which they related, or whether they had been reused elsewhere. It would be incorrect to assume that published credentials automatically give attackers live access. But their inclusion reasonably explains the city’s additional precautions.
The Urban Development, Building and Housing administration reviewed and tightened protective measures following the release. Berlin cautioned that users of its specialist applications could face short-term restrictions. For affected organisations, that illustrates a familiar security trade-off: temporarily limiting access may disrupt ordinary work, but can be preferable to allowing a potentially exposed account or connection to remain available while it is assessed.
For Windows administrators and employees in organisations that exchange data with public authorities, the wider lesson is straightforward. Treat unexpected messages referencing this incident, attached documents, password-reset requests or supposed government notices with heightened skepticism. A confirmed data exposure can make phishing more convincing because criminals may be able to use real names, projects, contact details or administrative terminology. Verification through known official contact channels is safer than following links or phone numbers supplied in an unsolicited message.
Those with accounts that may intersect with affected services should follow any direct instructions from the responsible authority, including password changes or access restrictions. They should not assume that a lack of immediate contact means their data was definitely absent; Berlin’s notification process depends on what the ongoing review identifies.
Sensitive-infrastructure concerns require precision
Independent reporting said that the Chaos Computer Club reviewed documents containing sensitive information about the state of Berlin’s water supply. That is a serious concern because infrastructure-related records can have value beyond ordinary identity theft or commercial fraud.
Yet the available evidence does not support converting that report into a specific claim that verified water-supply vulnerability analyses, particular operational weaknesses or other narrowly described critical-infrastructure files were exposed. Nor does it establish that an operator was directly compromised or that services were disrupted.
This is an area where precision protects the public interest. Understating a credible exposure may reduce vigilance, but overstating unverified operational detail can spread fear and amplify the value of attacker messaging. Berlin’s stated plan—to prioritise risks and immediately contact security-critical bodies when relevant findings emerge—is the appropriate mechanism for converting an undifferentiated dump into actionable warnings.
Why service disruption may continue even without a new breach
Users often interpret limited access to a government application as evidence that a cyberattack is still actively spreading. That is possible in some incidents, but it is not the only explanation. Restrictions can also result from precautionary credential resets, removal of network connections, tightened access controls, forensic preservation or a decision to keep a service segmented until it has been reviewed.
Berlin’s warning of possible short-term restrictions to specialist applications in the Urban Development, Building and Housing administration should be viewed in that context. The immediate user consequence may be delayed transactions or altered workflows. The security consequence is that authorities are attempting to reduce the chance that data already released—especially credentials—can be used for follow-on access.
For departments and companies dependent on public-sector digital services, continuity planning should account for that possibility. Staff may need a verified fallback process for time-sensitive submissions, records requests or project coordination. Equally, no one should bypass controls by sending sensitive material to unverified addresses, personal mailboxes or improvised file-sharing services simply because a normal portal is unavailable.
The facts that remain open
Several central questions are still unresolved. There is no public completed inventory of the released dataset. The number of affected people, companies and third parties is not known. The categories of personal data involved for each affected group, and the number of notifications already issued, have not been publicly established.
It is also unknown whether the published access credentials remained valid, were reused, or had already been remediated before publication. Finally, while the group calling itself Rhysida has claimed responsibility, Berlin had not publicly made a definitive attribution or verified the group’s volume and content claims.
That uncertainty should shape how the incident is discussed. Berlin has confirmed enough to justify serious caution: a state-network compromise, identified data outflow, extortion, public release of stolen information, and a later release containing credentials. What remains unsettled is the full size, composition and downstream effect of the data.
The most useful measure of the response will not be whether every attacker claim is repeated, but whether the city can rapidly distinguish authentic high-risk material from noise, protect systems against credential-driven follow-on attacks, notify those who genuinely face risk, and keep essential public services functioning while the investigation continues.