What Berlin’s 5.8-TB Ransomware Leak Actually Exposed About Water, Power and Critical Infrastructure

Berlin’s ransomware leak was more serious than a dump of routine government paperwork: reporting based on the stolen files found vulnerability, civil-defense and critical-infrastructure material, and Berlin later confirmed leaked access credentials. But no public evidence shows Rhysida breached the operational systems that actually run Berlin’s water or electrical grid.
Composite image of Berlin with documents spilling from a hacked server, plus scenes of a power substation, water facility, and control room.
Contents

The short answer: Berlin’s massive ransomware leak exposed more than routine government paperwork that happened to mention water, electricity and other critical infrastructure. Journalists who examined the published files found security-relevant material concerning infrastructure vulnerabilities, civil-defense priorities, consequences of facility failures and protective arrangements. Berlin has also officially confirmed that a later release contained access credentials.

But that does not mean the hackers took control of Berlin’s water system or power grid.

As of September 6, there is no public evidence that the attackers penetrated the operational technology that runs Berliner Wasserbetriebe, compromised Stromnetz Berlin’s grid-control systems, obtained SCADA or industrial-control access, or gained the ability to manipulate pumps, treatment systems, substations or electricity switching.

The evidence therefore lands between two misleading extremes. Calling these merely “documents about infrastructure” understates what was exposed. Saying “hackers breached Berlin’s water and power systems” goes well beyond what has been established.

The most defensible conclusion is this:

Berlin lost genuinely security-relevant intelligence about critical infrastructure. Some of that information could plausibly help an adversary understand vulnerabilities, protective priorities and emergency arrangements. But no evidence currently establishes operational control of the infrastructure itself.

What the evidence establishes

Claim Evidence status
A multi-terabyte collection of Berlin government data was stolen and published Established
Security-relevant information about water, energy and civil defense appears in the leak Strongly established by direct journalistic examination
Access credentials were published Officially confirmed
Some leaked material carried the VS-NfD government classification Strongly established
Rhysida penetrated a water utility’s operational network Not established
Rhysida penetrated Berlin’s electrical grid-control network Not established
SCADA/ICS credentials or operational-control access were obtained Not established
The complete secret Operationsplan Deutschland was stolen Not established
Berlin’s September 20 election systems were compromised No known compromise

What happened in the Berlin ransomware attack?

The incident affected two Berlin Senate administrations: the department responsible for urban development, building and housing, and the department responsible for mobility, transport, climate and environment.

Berlin announced the incident on August 17 after both administrations had already been isolated from the state network on August 14. Subsequent forensic work determined that data had been exfiltrated between August 7 and August 12. Berlin reconnected the two administrations on August 23 while the broader forensic investigation continued.

The scale emerged gradually.

On August 19, Governing Mayor Kai Wegner said that, based on the information available at the time, no sensitive data appeared to have been exfiltrated. A week later, Berlin acknowledged that additional data loss had been discovered and that personal or otherwise nonpublic information could be involved.

That early reassurance was therefore materially wrong. The available evidence supports premature confidence during an incomplete forensic investigation, however, more strongly than it supports an allegation that officials knowingly concealed the true scale.

On August 28, Berlin publicly acknowledged the extortion attempt. By September 3, the government said a group calling itself Rhysida had claimed responsibility, claimed possession of approximately 5.7 terabytes, and demanded a minimum of 30 bitcoin—roughly €2 million at the time. Berlin refused to pay.

The data was subsequently published. Berlin established a centralized unit to coordinate verification, risk assessment and notifications, and on September 6 confirmed that the attackers had released an additional package containing access credentials.

One important detail remains less certain: Tagesspiegel has reported, based on its reconstruction of the response, that the original compromise began after an employee clicked a phishing link. Berlin has not yet published a forensic report formally establishing the initial-access mechanism, so phishing should be treated as credible reporting rather than a confirmed official finding.

Was it really 5.8 TB and 1.44 million files?

Approximately—but the widely repeated numbers combine attacker claims, observed publication figures and later releases.

Berlin itself said Rhysida claimed to possess 5.7 TB. That was not presented as a final independently measured government total.

After the publication, Tagesspiegel reported directly observing an initial dataset of approximately 5.26 TB containing 1,439,893 file entries.

Its later systematic analysis found at least 755,121 files that were directly accessible. After removing obvious duplicates, the newspaper analyzed names and folder structures for 743,424 files and directories. It also noted that inaccessible archive files could contain many more individual documents and emails.

Berlin then confirmed another package on September 6.

The figures therefore are not necessarily contradictory:

Number What it means
5.7–5.8 TB Rhysida’s advertised/claimed scale of the theft
5.26 TB Initial published dataset directly observed by Tagesspiegel
1,439,893 File entries reported in that initial publication
755,121+ Files Tagesspiegel could directly access during its analysis
743,424 Files/directories analyzed after obvious duplicates were removed
Final total Still not independently reconciled after archives and later releases

Calling the incident the “5.8-TB Berlin leak” is reasonable shorthand. Saying Berlin has independently authenticated exactly 5.8 TB and every one of 1.44 million files would be too precise for the evidence available.

Did the leak really contain critical-infrastructure security information?

Yes.

This is where the evidence has moved beyond the early question of whether government documents simply mentioned utilities.

Tagesspiegel, whose journalists examined the published material, reported records dealing with facilities regarded as important to civil defense, including energy and emergency-power infrastructure. Other material described potential consequences if certain facilities became unavailable.

The newspaper also reported finding a 2025 presentation concerning vulnerabilities in Berlin’s water supply, alongside material concerning critical infrastructure, emergency contacts, operating information, potential hazards and protective arrangements.

Those categories matter.

A procurement contract mentioning a water utility is one thing. A vulnerability assessment, protection plan or internal description of the consequences of infrastructure failure is another.

For security reasons, this article does not reproduce the specific facility-level vulnerabilities described in the reporting. They are unnecessary to understanding what was compromised.

The evidence supports saying that at least part of the dataset contained security-relevant intelligence about critical infrastructure, not merely administrative references to it.

What remains uncertain is how much of that information is still current, accurate and practically actionable today.

How serious is that? An infrastructure-actionability test

A useful way to assess the breach is to separate different levels of infrastructure exposure:

Level Type of information or access Berlin evidence
0 Public references to utilities or infrastructure Yes
1 Internal contracts, correspondence and administrative records Yes
2 Vulnerability information, emergency planning, protection priorities and physical-security context Yes — strongly supported
3 Credentials potentially enabling follow-on system access Yes generally; infrastructure connection unknown
4 OT/SCADA credentials, industrial-control configurations or confirmed control-network access Not established
5 Demonstrated ability to manipulate water or electricity operations No evidence

The Berlin breach has clearly reached Level 2.

Berlin’s September 6 announcement also confirms generic Level-3 credential exposure, but there is not enough public information to connect those credentials to water, electricity or other operational infrastructure.

That distinction is crucial. Security intelligence can be damaging even if nobody can remotely operate a pump or substation with it.

Did the hackers actually breach Berlin’s water system?

There is no evidence that they did.

The leaked files came from Berlin government administrations. That is not the same thing as compromising the operational systems of Berliner Wasserbetriebe, the utility responsible for Berlin’s drinking water and wastewater systems.

Berliner Wasserbetriebe describes its drinking-water and wastewater operational technology as critical infrastructure subject to technical and organizational security controls, a sector-specific B3S security standard and auditing under Germany’s §8a BSIG framework. The utility also says the information-security management system covering its data-center operations and IT services is ISO 27001 certified.

Those statements come from the operator itself, so they should not be treated as proof that its security cannot fail. They do establish, however, that the operational environment running Berlin’s water system is a distinct regulated system, rather than simply another folder inside a Senate administrative network.

As of September 6, no authoritative public evidence establishes that Rhysida:

  • entered Berliner Wasserbetriebe’s OT environment;
  • obtained control-system credentials;
  • compromised water-treatment or pumping controls; or
  • gained the ability to change water operations.

What was exposed is still serious: government-held information describing vulnerabilities and emergency planning associated with the water supply.

But information about the water system is not the same thing as access to the water system.

Did Rhysida gain access to Berlin’s power grid?

Again, there is no public evidence of that.

Stromnetz Berlin operates the city’s electrical distribution grid. In a 2025 response published by the Berlin parliament, the company said its security architecture uses strict segmentation between office IT and operational technology, and that it operates attack-detection systems required under German law. The same response described external auditing of relevant cybersecurity controls.

Those are operator representations, even though they appear in an official parliamentary document, and should not be treated as independent proof that no compromise is possible.

But nothing currently published establishes that the Berlin Senate breach crossed into Stromnetz Berlin’s operational environment.

That leaves two propositions with very different evidentiary status:

Supported: attackers obtained security-relevant information concerning energy and critical infrastructure.

Unsupported: attackers obtained operational control of Berlin’s electrical grid.

A document describing why a power facility matters is not the same thing as the credentials or command access required to operate it.

What do the leaked access credentials change?

They make the breach more serious—but not in the way some headlines may imply.

Berlin officially confirmed on September 6 that the newest release included access credentials. The affected building and housing administration said it had consequently tightened protective measures and warned that some specialist applications could temporarily experience restrictions.

What Berlin has not publicly disclosed is just as important.

The government has not said whether those credentials were current or expired; whether they belonged to normal users, administrators, applications or machines; whether multi-factor authentication protected the affected systems; whether they had already been revoked; or whether any were associated with utilities or industrial-control environments.

Therefore:

“Access credentials were leaked” is verified.

But:

“Passwords to Berlin’s water or electrical control systems were leaked” is not established.

Credential exposure also creates a broader follow-on risk because authentic information about employees, agencies and systems can make phishing, impersonation and social-engineering attacks more convincing.

Berlin’s data-protection commissioner has warned affected people about risks including fraud, identity misuse and phishing.

Were “secret” German government documents leaked?

Yes—but the word secret requires precision.

Berlin’s official classified-information rules recognize four levels:

German classification General significance
STRENG GEHEIM Unauthorized disclosure could endanger Germany’s existence or vital interests
GEHEIM Disclosure could endanger national/state security or cause serious harm
VS-VERTRAULICH Disclosure could harm federal or state interests
VS-NUR FÜR DEN DIENSTGEBRAUCH (VS-NfD) Disclosure could be detrimental to federal or state interests

Tagesspiegel reported finding defense and civil-protection material marked VS-NfD.

VS-NfD is therefore classified/restricted government information. But it is not equivalent to the formal German GEHEIM level.

That matters because English summaries can easily transform “geheime Daten” used generically in German reporting into an assertion that every exposed document carried a formal “Secret” classification.

The evidence supports:

Classified government information was exposed.

It does not currently support:

All of the infrastructure documents were formally classified GEHEIM or STRENG GEHEIM.

Did the hackers steal Germany’s secret Operationsplan Deutschland?

There is evidence that material related to Operationsplan Deutschland was exposed. There is no evidence that the entire national plan was stolen.

The Bundeswehr describes Operationsplan Deutschland, or OPLAN DEU, as a continuously updated plan of more than 1,000 pages integrating Germany’s military defense requirements with necessary civilian support. Its detailed contents are secret. The Bundeswehr develops it in cooperation with the federal Interior Ministry and Germany’s states.

That cooperation explains why Berlin authorities legitimately possessed defense-related planning information.

Tagesspiegel reported that some of the leaked records concerned Berlin’s role in identifying facilities requiring protection as part of this wider defense-planning process.

That is materially different from establishing that Rhysida obtained the full national OPLAN.

The accurate formulation is:

OPLAN-related Berlin and Bundeswehr planning material was exposed. There is currently no evidence that the complete secret Operationsplan Deutschland was stolen.

Were classified files supposed to be on the systems that were breached?

This may become the most important accountability question in the entire incident.

Berlin’s own classified-information directive is explicit: processing classified information is permitted only on VS-IT approved for that purpose. Its VS-NfD guidance specifically says this requirement applies to PCs, IT networks, notebooks, mobile phones and portable storage.

The same rules establish formal approval and security requirements for systems processing classified information, including documented security controls and review of the system’s authorization.

Against that requirement, Tagesspiegel reported finding an internal February 2026 note in which officials dealing with security issues concluded that strict digital classified-information protection was not possible within Berlin’s public administration. It also reported a separate July record concerning civil-defense planning for the water supply that said suitable IT structures for classified files still needed to be created and that cooperation would meanwhile have to continue on paper.

That combination raises an obvious and serious question:

Were the classified records found in the leak actually being processed on IT authorized for their classification level?

At present, the evidence does not answer it.

We do not know the VS-IT approval status of the particular systems from which the files were stolen.

It would therefore be premature to state as fact that Berlin violated its classified-information rules.

The stronger, evidence-based conclusion is:

Berlin’s own rules required approved IT for VS-NfD material, while internal records reportedly show officials struggling with inadequate digital infrastructure for classified work. That creates a substantial compliance question that Berlin has not yet publicly resolved.

Cybersecurity expert Manuel Atug has gone further, telling ZDF that Berlin acted with “gross negligence.” That is a relevant expert assessment, not an established legal finding.

Had Berlin already been warned about cybersecurity weaknesses?

Yes. But those warnings should not be retroactively turned into proof of how Rhysida got in.

At a November 3, 2025 hearing of the Berlin parliament’s Committee on Internal Affairs, Security and Order, Atug pointed out that Berlin’s official information-security guideline dated from 2017 and still referenced older BSI standards that had been superseded years earlier. He told lawmakers he had already criticized the same issue in 2023.

At the same hearing, cybersecurity policy expert Sven Herpig cited official information showing that, as of August 2025, Berlin had not comprehensively implemented ICT business-continuity management across the state administration.

These records establish that Berlin entered 2026 with documented governance, legacy-system and resilience concerns.

They do not establish that any particular one of those deficiencies was the technical cause of the Rhysida breach.

Until investigators publish reliable findings about initial access, lateral movement, privilege escalation and data exfiltration, claims such as “obsolete software caused the attack” remain inference rather than established fact.

Why did Berlin initially say no sensitive data was taken?

Because officials apparently did not yet understand the scale of the compromise.

On August 19, Wegner publicly said that, according to what was then known, no sensitive data had been exfiltrated.

By August 26, Berlin said forensic investigators had discovered additional exfiltration and could no longer exclude personal or other nonpublic information. By September 3, the government was warning that citizens, employees and companies could be affected. Then the dataset was published.

The chronology matters.

It proves the initial reassurance was wrong.

It does not, on the evidence currently available, prove that officials knew it was wrong when they made it.

The defensible criticism is that Berlin made a reassuring public statement before its investigation was mature enough to support it.

That experience is also a reason to treat present-day statements such as “no evidence has been found” carefully while investigators are still reviewing such an enormous dataset.

Was the September 20 Berlin election hacked?

There is no evidence that Berlin’s election systems were compromised.

The timing naturally raises the question because the data was published just weeks before Berlin’s September 20 election.

But Germany’s Federal Office for Information Security, the BSI, has said it currently assesses the attackers as financially motivated rather than politically motivated. That assessment is consistent with the observed sequence: data theft, a bitcoin ransom demand, attempted sale and publication after Berlin refused to pay.

Berlin’s election authority has also said that the election environment was not known to be affected—including election preparation, voting and the process leading to publication of the preliminary result.

There is an important second-order risk, however.

The BSI has warned that stolen authentic documents can later be used in hack-and-leak operations, where genuine material is selectively released or presented in a misleading context to influence political debate.

Those are separate questions:

Question Current evidence
Was Rhysida’s attack financially motivated? Evidence strongly favors yes
Were Berlin election systems compromised? No known compromise
Could authentic stolen files later be exploited politically? Yes, that is a recognized risk

The fact that the breach occurred shortly before an election is therefore not evidence by itself of an election operation.

How dangerous is the Berlin leak if hackers cannot control the utilities?

Potentially very dangerous.

The consequences of a data breach are not limited to whether an attacker can remotely flip a switch.

The Berlin data-protection authority says substantial quantities of government data were copied and published, including employee data and potentially information about citizens. It has warned about identity theft, fraud and phishing.

A corpus containing authentic internal correspondence, personnel information, emergency contacts, credentials, infrastructure planning and security-relevant material can also have intelligence value.

That conclusion is partly inference, but it is a strong one.

Someone planning a later cyberattack, espionage operation or physical intrusion may benefit from knowing organizational relationships, personnel, procedures, vulnerabilities and which facilities authorities consider particularly important—even if none of those documents directly provides control of industrial machinery.

That is why the correct measure of this incident is not simply:

“Can the hackers turn off Berlin’s water?”

The better question is:

“What new information or access did the leak give an adversary that they did not have before?”

On that measure, the breach is plainly significant.

Current risk assessment

Risk Assessment
Personal-data exposure Established
Identity fraud and targeted phishing Established/officially warned about
Follow-on attacks using leaked credentials Plausible; credential scope unknown
Intelligence value from internal infrastructure information Strong reasonable inference
Increased physical-security targeting risk Plausible given the reported contents
Water-utility OT compromise Not established
Electrical-grid OT compromise Not established
Direct manipulation of water or electricity systems No evidence
Election-system compromise No known evidence

What the Berlin leak does not prove

The growing scale of the story makes precision more important, not less.

Nothing currently available establishes that Rhysida obtained SCADA or industrial-control-system access.

Nothing establishes operational access to Berliner Wasserbetriebe.

Nothing establishes operational access to Stromnetz Berlin.

Nothing establishes that the complete Operationsplan Deutschland was stolen.

Nothing establishes that Berlin’s election infrastructure was compromised.

And although Berlin’s classified-information rules combined with its own reported internal documents raise a serious compliance question, the public record still does not establish that the specific compromised systems lacked the required VS-IT authorization.

Those distinctions should not be used to minimize the breach. They are necessary to describe what actually happened rather than what the most dramatic interpretation assumes happened.

What is still unknown

The investigation remains incomplete as of September 6.

The most consequential unanswered question is the scope of the newly confirmed access credentials. Berlin has not identified which systems they access, whether they remain valid, whether any provide privileged access or whether any are connected to infrastructure operators or OT environments.

Investigators also have not publicly established whether the corpus includes industrial-control configurations, SCADA documentation or other information that would move the incident from security-intelligence exposure toward operational cyber risk.

The currentness of the infrastructure files remains another major unknown. At least some reported material dates from 2025 and 2026, but authorities and utilities have not publicly explained which details remain accurate or what security measures have changed since publication.

Nor has Berlin publicly resolved whether the systems holding reported VS-NfD material were approved VS-IT systems.

The highest authenticated classification level found across the entire dataset also remains unclear. VS-NfD material is credibly established; claims that substantially higher GEHEIM or STRENG GEHEIM records were exposed require stronger evidence.

Finally, no final official reconciliation yet tells us exactly how many unique files or bytes were stolen after duplicates, archives and subsequent releases are accounted for.

Those questions matter. None changes the central answer already supported by the evidence.

Bottom line

Berlin’s ransomware breach exposed genuinely sensitive information about critical infrastructure, not merely harmless documents containing the words “water” or “power.”

The published material reportedly includes vulnerability information, civil-defense planning, information about infrastructure protection and the consequences of facility failures. Berlin has separately confirmed that access credentials were also released.

That makes this significantly more serious than an ordinary leak of administrative correspondence.

But an equally important boundary remains.

There is no public evidence that the attackers gained operational control of Berlin’s water system, electricity grid or other industrial-control infrastructure.

The evidence supports an information-security and intelligence compromise involving critical infrastructure.

It does not currently support describing the incident as an operational takeover of critical infrastructure.

That distinction may change if investigators establish what the leaked credentials access or discover OT-related material. Until then, it is the line the evidence supports.

References and Further Reading

Berlin government and regulatory sources

Direct analysis and independent reporting

Critical-infrastructure and defense context

Pre-breach cybersecurity warnings

Editorial currency note: This remains an active forensic and criminal investigation. Details about the credentials, total dataset size, affected organizations, classification levels, utility remediation and attack vector may change as Berlin, federal authorities and infrastructure operators complete their assessments. This article should be updated if materially new official or independently verified evidence emerges.

Reporting note: sherafy.com did not need to download or redistribute the stolen dataset to reach the conclusions above. The analysis relies on official government records, public security and regulatory documents, and reporting by journalists who directly examined the published material.

Cite this article

Published September 6, 2026

More to think on...

A large crowd of protesters walks along a roadway near a port and rail lines in an Italian city.
Why Are Italians “Blocking Everything”? Inside the Strikes Over Wages, War Spending and Meloni

Italy has not simply “stopped going to work” or collectively refused to pay taxes. A more consequential movement has been developing: workers are repeatedly using general strikes, port blockades, transport disruption and the withdrawal of labor as political leverage. What began visibly with Gaza solidarity has expanded into a broader fight over wages, pensions, public services, military spending and the Meloni government’s priorities.

Read More »
Stacks of redacted FBI interview notes and court documents spread across a desk in front of computer screens showing legal and government records databases.
The 37 Missing Epstein FBI Notes: What They Say About Trump, Jim Atkins and DOJ

The 37 handwritten FBI pages missing from DOJ’s official Epstein release now appear to have surfaced outside the government’s public library. The underlying case is more extensive than the viral version: the witness accused Donald Trump, Jeffrey Epstein and a man recorded as “Jim Atkins (phonetic)” of sexual abuse, described other unidentified alleged abusers, and gave investigators potential corroboration leads. We reconstructed what is verified, what is corroborated, what remains allegation, and why DOJ is now defending its handling of the records in federal court.

Read More »