Berlin hack leaks 1.44 million files, mixing personal records with possible infrastructure data
Around 1.44 million files totalling 5.8 TB were posted on the Darknet after a breach of Berlin’s administration. The dump contains scanned passports, employment contracts and, according to media reports, data on water supply and other critical‑infrastructure assets.

About 1.44 million files – roughly 5.8 terabytes of data – were uploaded to the Darknet after a breach of Berlin’s administration was made public on 17 August 2026. The dump mixes personal documents such as scanned passports and employment contracts with material that media analysts say could include details of the city’s water supply, heating plants and other critical‑infrastructure assets.
Scale of the leak
The German business daily Handelsblatt confirmed that “seit Freitag sind rund 1,44 Millionen Dateien mit einem Umfang von 5,8 Terabyte im Darknet veröffentlicht” (since Friday, early August 2026, about 1.44 million files amounting to 5.8 TB have been published on the Darknet). The same source described the incident as a “Daten‑Super‑GAU” – a data super‑disaster of “gravierendem Ausmaß” (grave magnitude).
| Metric | Value | Period | Source |
|---|---|---|---|
| Files leaked | 1.44 million files | since early August 2026 | Handelsblatt |
| Data volume | 5.8 TB | since early August 2026 | Handelsblatt |
| Ransom demand | 30 Bitcoin (~2 million €) | August 2026 | Handelsblatt |
What the dump contains
According to the same Handelsblatt report, the first wave of files appears to be dominated by personal data: scanned passports, employment contracts, job applications and medical certificates. These documents are clearly identifiable as belonging to individual citizens and public‑sector employees.
Other German outlets, notably Tagesspiegel, have added that the dump “sollten sich darunter zudem Daten zu Heizkraftwerken, Tanklagern, Notstromanlagen, Umspannwerken, Gefängnissen, Wasserwerken sowie Rüstungsunternehmen und der Bundeswehr befinden” (the files also contain data on heating plants, fuel tanks, backup power units, substations, prisons, water works, as well as defence companies and the Bundeswehr). While the exact scope of those items cannot be verified from the publicly available files, the claim is reported by the newspaper and therefore can be attributed to it.
Security experts quoted in the Handelsblatt article caution that the dump may include “hoch‑sensible Daten” (high‑sensitivity data) linked to civil‑protection and defence‑related entities. The experts do not enumerate the specific infrastructure categories, but they flag the potential for broader impact beyond personal privacy.
Timeline and response
The breach unfolded over a ten‑day window. The hacker group identified as Rhysida accessed parts of the Berlin Senate network between 7 August and 12 August 2026 without detection. Berlin’s IT security team discovered the intrusion on 14 August, and the administration announced the breach three days later, on 17 August, when the stolen files began appearing on the Darknet.
Federal security agencies, including the BSI, issued immediate warnings to public bodies and private firms about the exposure of personal data. The timing of the leak is notable because Berlin’s state election is scheduled for two weeks later, raising concerns about political fallout.
Ransom demand and attribution
Rhysida demanded a ransom of 30 Bitcoin, which the Handelsblatt article translates to roughly two million euros at the time of the attack. The group has not indicated whether the ransom was paid, and Berlin officials have not disclosed any negotiation details.
While the ransom demand is a concrete figure, the motives behind the leak remain unclear. The attackers have not publicly claimed a political agenda, and the release of the data appears to be a pressure tactic to extract payment.
Open questions and next steps
- How many of the allegedly infrastructure‑related files are authentic and actionable for malicious actors?
- What remediation steps will Berlin’s administration take to secure the affected systems and prevent further data loss?
- Will the federal authorities pursue legal action against the Rhysida group, and what resources will be allocated to trace the Bitcoin payments?
At present, the Berlin administration has not disclosed the total number of individuals whose personal documents were exposed, nor the exact categories of the alleged critical‑infrastructure data. Analysts will continue to monitor the Darknet for additional uploads that could clarify the scope of the breach.
For now, the leak stands as one of the largest publicly confirmed data dumps from a German municipal authority, underscoring the vulnerability of public‑sector networks to sophisticated ransomware‑style intrusions.
