Berlin authorities disconnected two state ministries from the city government network after detecting a cybersecurity breach affecting the ministries for urban development, construction and housing, and for mobility, transport, climate protection and the environment. Officials isolated the ministries as a precaution while investigators examined reports that attackers may have exploited a vulnerability in one ministry’s IT systems; German media also reported that data was exfiltrated. Authorities have not publicly identified the threat actor, disclosed the intrusion timeline, or confirmed the full scope of the compromise.
The incident left parts of the ministries effectively unable to work, with staff reportedly cut off from email and internet access and relying on phone, SMS, and fax for communication. The disruption also affected public services, including processing of housing benefits and education-related assistance at some district offices. Berlin’s central IT service provider, ITDZ Berlin, was reportedly not impacted because the affected ministries operated their portion of the state network independently, though they shared some infrastructure with each other.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
Berlin officials said the cyberattack was discovered on 14 August, after which the Senate administrations for urban development and transport were disconnected from the internet. Officials later described the intrusion as highly professional and began broader network scanning and investigation.
Berlin's Senate Chancellery said sensitive personal or other non-public data may have been exfiltrated in the attack, potentially affecting the Senate Department for Mobility, Transport, Climate Protection and the Environment. Authorities said the scope and content remain under review, while forensic work and network scanning continue.
Berlin officials said all Senate administrations had been reconnected to the Berlin state network and were fundamentally operational again after the cyberattack. Authorities said specialist procedures in the districts were largely available again, while warning that some isolated impairments and delays could continue during recovery.
Berlin authorities said forensic investigations found a compromise of the Berlin regional network following the cyberattack on two Senate administrations. The Senate Chancellery also set up a crisis cell to coordinate the incident response.
The disruption caused by the cyberattack prevented payment of housing benefits to more than 50,000 eligible households in Berlin. The incident also continued to affect the 'Bildung und Teilhabe' support program for children and young people.
The network isolation left employees at the affected ministries without normal email and internet access, forcing them to use telephone, SMS, and fax. The incident also interrupted some district-office services, including processing of housing assistance and education-related benefit applications tied to the urban development ministry's systems.
Berlin authorities disconnected the ministries for urban development and for mobility from the city government's IT network as a precaution after discovering the security breach. The Senate Chancellery said the two ministries had been isolated since Friday to protect the wider state network.
Government sources cited by RBB said attackers allegedly exploited a vulnerability in the IT systems of one of the two affected Berlin state ministries, leading to the breach. The exact intrusion date, threat actor, and full access details were not disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
9 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourceheise.de
Open sourceheise.de
Open sourceheise.de
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcetherecord.media
Open sourcetagesspiegel.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.