Cybersecurity & Protection

Berlin Hack: Senate Walks Back Claim, Personal Data May Be Affected After All

Aug 28, 2026 2 min read
All articles

Sensitive data may have been exposed after all in the cyberattack on Berlin's state network. That reverses an earlier assessment from the State Chancellery, which had said no sensitive information was affected. Specifically at issue is the area covered by the Senate Department for Mobility, Transport, Climate Protection, and the Environment.

From geodata to potentially personal data

Just the week before, the Senate had said that, based on initial findings, no sensitive data had been exposed, with officials only mentioning geodata that was freely available online anyway. Now the State Chancellery says: "It cannot be ruled out that personal or other non-public data was also affected." The content and scope of the affected data are still being reviewed.

According to the State Chancellery, the data exposure occurred before August 14, meaning before the Senate Departments for Urban Development, Building, and Housing, and for Mobility, Transport, Environment, and Climate Protection were disconnected from the state network. The actual IT attack was discovered on August 14.

Investigations continue

"As soon as we have solid findings on the scope and content of the data, we will inform the relevant parliamentary bodies and offices," said Florian Hauer, State Secretary for Digitalization. "We currently assume the attack could be contained. However, the forensic investigations and the scanning of Berlin's state network continue for the time being. The ICT emergency task force also remains active for now." The development shows how uncertain initial assessments after a security incident often are, especially while forensic investigations are still ongoing.