Skip to main content
Scam Checker
Back to all scam alerts and blog posts

Berlin government data leak: what is confirmed

By Published Updated
  • scam alert
  • cyber incident
  • data breach
  • berlin
  • global

Confirmed incident; scope still under investigation. Scam Checker first covered this story on 5 September 2026 (UTC). That is our coverage date, not the start of the incident. This article was corrected on 6 September 2026 to distinguish Berlin's official statements from reporting and attacker claims.

Berlin's state government has confirmed a security incident involving its government network and the publication of stolen data. Its statements of 3 and 4 September 2026 describe the investigation, the affected departments and how people identified as affected will be contacted. The existence of the incident is established; the full contents and impact of the leaked data remain under examination.

What Berlin has confirmed

The Berlin Senate Chancellery's 3 September statement identifies two affected departments: Mobility, Transport, Climate Protection and the Environment; and Urban Development, Building and Housing. It describes work with Berlin's criminal police, public prosecutors, Germany's Federal Office for Information Security and other authorities.

That statement says a group using the name Rhysida claimed responsibility and claimed to hold about 5.7 terabytes of stolen data. Those are attributed attacker claims, not an independently verified inventory. Berlin said the alleged perpetrators were attempting extortion and had offered the data for auction. The statement also said there was then no evidence that the state network remained infiltrated, while forensic investigations continued. That assessment is dated; it is not a guarantee about every system or account.

The 4 September official update confirms that authorities and commissioned forensic specialists were examining the published data. It explains that relevant Senate departments will notify identified affected people according to risk and legal requirements. It does not provide a final count of affected people or a complete account of the leaked material.

What the news reports add

A Reuters report carried by The Straits Times, dated 5 September in its Berlin dateline, describes the government's crisis response after the data publication. The publisher displays 6 September in its local publication time. This is reporting about a development in an existing incident, not evidence that the attack began on 5 September.

The three headlines originally listed here were carried by Global Banking & Finance Review, The Straits Times and The News. All drew on the same Reuters reporting. They are one reporting origin, not three independent confirmations. This correction relies on Berlin's named official statements for what the government has established, with Reuters clearly attributed for its reporting.

Steps for people who may be affected

Start with Berlin's official information and the relevant department's notification process. A news headline cannot establish whether your personal information is included. Nor does a missing notification prove that you are unaffected while data analysis is continuing.

The 4 September statement advises people who discover, or have concrete indications, that their data has been published or used for fraud or identity misuse to report it to police. It links Berlin's online police reporting service and says a local police station is another route. It also identifies Berlin's data-protection authority as a source of support. Use those official routes rather than a phone number supplied in an unsolicited message.

Watch for messages exploiting the story

A real incident can be used as the subject of an unrelated impersonation attempt. The following are general precautions; this article has not established that these follow-up scams occurred in the Berlin case.

  • Verify unexpected contact independently. Open the relevant authority's website yourself and use its published contact details. A familiar logo or accurate information about you does not authenticate a caller.
  • Do not disclose passwords or one-time codes to someone claiming to investigate the leak. If credentials may be exposed, change them through the account's official website or app and enable multi-factor authentication where available.
  • Do not pay to remove your data because a message promises deletion or compensation. An unsolicited promise is not proof that the sender can control leaked information.
  • Keep suspicious messages as evidence. If you have shared payment details or sent money, contact your bank promptly through a trusted number and follow applicable police reporting advice.
  • Do not install a supposed repair tool because of this headline. A government data leak does not, by itself, show that your device is infected or needs a software patch.

You can check a suspicious message for warning signs. A low-signal result does not guarantee legitimacy or determine whether your data was included in this incident. If you have already clicked, paid or shared sensitive information, use the recovery checklist alongside the official advice relevant to your situation.

Correction and sources

The original version treated recent RSS coverage as an early, potentially unconfirmed incident and did not link Berlin's available statements. It also listed three versions of one Reuters report without explaining their common origin. This version corrects those distinctions while retaining the original publication date and URL. The date and scale of the underlying attack must not be inferred from this site's publication date.

External sources and references