Hackers publish Berlin administration data after ransom deadline
The reported disclosure raises questions about sensitive government records and protections for people whose information was exposed.
Hackers published a large collection of Berlin state administration files after a ransom deadline expired, Euronews reported on September 5. The outlet identified the group as Rhysida and said the material included personal information about civil servants. The disclosure puts protection of government records and affected individuals under scrutiny.
According to the report, Berlin's Senate had rejected paying the demand before publication. Some files were described as relating to emergency planning and security. Those descriptions require careful assessment: the available reporting does not establish that every document is authentic, current or operationally useful, or identify a state directing the hackers.
Two different protection duties
European rules address both the resilience of public systems and the consequences of exposing personal information. In its November 2022 adoption statement, the Council of the European Union explained that NIS2 extends cybersecurity requirements to central and regional public administrations. It establishes minimum risk-management and incident-reporting requirements, alongside arrangements for cooperation between national authorities dealing with serious cyber incidents.
That framework has important boundaries. The Council explicitly excluded activities involving defence, national security, public security and law enforcement, as well as several other institutions. Consequently, the mere presence of government documents in a reported leak does not establish which cybersecurity provisions govern every affected system. Determining the responsible entities and the character of their activities remains essential to assessing applicable obligations.
Notification and the next assessment
For personal information covered by the General Data Protection Regulation, Article 33 requires notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness. An exception applies when a breach is unlikely to create risks to people's rights and freedoms. Where notification is late, the controller must explain the delay; these are standing requirements, not findings of a violation in Berlin.
The regulation also requires communication to affected people when a breach is likely to create a high risk, subject to its exceptions. The next meaningful developments would therefore be an authoritative account of what was exposed, the risks involved and the protective response. Public disclosure of stolen files alone cannot establish whether notification duties were fulfilled or what lasting security consequences will follow.