Rhysida Hacker Group Exposes Major Vulnerabilities in Berlin Government IT — UNITED24 Media | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A series of cyberattacks by the hacker group Rhysida has exposed massive vulnerabilities in Berlin’s state IT networks, according to an investigation by the German newspaper BILD, posted on September 6.

The cyberattacks led to the leak of highly sensitive federal government and critical infrastructure data over a period of months.

We bring you stories from the ground. Your support keeps our team in the field.

DONATE NOW

The scope of the security failures was acknowledged by Matthias Hundt, the recently dismissed State Secretary for Digital Affairs. According to multiple sources, Hundt previously warned colleagues internally: “The networks in Berlin, at the Senate and district levels, are wide open – and there is no information about which systems are running where, by whom, with which software, and at what security level.”

When confronted by BILD about the quote, Hundt responded, “I cannot deny that,” before declining further comment due to an ongoing legal dispute with the state.

The hackers, who are internally suspected of having ties to Russia, reportedly accessed the state network via email accounts at the Mitte and Neukölln district offices.

The Senate Chancellery of Governing Mayor Kai Wegner confirmed the targeted attempt, though a high-ranking representative noted: “We have information that the perpetrators also attempted to gain entry via the Mitte district office. However, as things stand, we do not assume that this attempt was the initial incident.”

The perpetrators ultimately executed a major incursion through the Senate Department for the Environment.

Confidential documents and expert testimonies obtained by the publication reveal severe systemic dysfunction across Berlin’s administration. Despite a central state network, most districts operate disjointed infrastructure with outdated technology.

External service providers often have direct access to feed unchecked updates into the networks, and in some Senate departments, human resources personnel—rather than IT professionals—are responsible for cybersecurity. According to BILD, investigators also found unprotected Windows Exchange servers stored in unsecured rooms, including broom closets, while a significant portion of internal data traffic relies on open, unencrypted Word documents.

The negligence at the state-owned IT Service Center Berlin (ITDZ) has reportedly facilitated compounding breaches. In June 2025, a hack on an external service provider completely compromised site plans for Berlin’s water and electricity infrastructure.

BILD claimed this vulnerability played a role in a January terrorist attack on southwest Berlin’s power grid, a March 20, 2026 cyberattack on a Neukölln heating plant, and a July disruption that took Berlin courts offline.

The fallout may extend well beyond the capital. Max Kilger, a leading US cybersecurity expert, warned that there could be “significant network connections between the attacked Berlin systems and other systems of the German federal government,” indicating the breach may evolve into a far “more serious incident.”

Russian-speaking cybercriminals have also recently executed a massive data heist targeting Western infrastructure. A service on the Russian-speaking cybercrime forum Exploit had offered access to over 153 million US and Canadian driver’s licenses, 10 million identity cards, and 3 million passports.

The breach, which reportedly stemmed from a compromised identity verification platform used by major global brands, even exposed the driver’s license of US Secretary of Defense Pete Hegseth and is currently under investigation by the FBI.

Be part of our reporting
Logo

We report from the front lines to show the reality of war. Your support helps us stay there and tell the stories that matter.



Click Here For The Original Source.

——————————————————–

..........

.

.