Full Report
Die Senatskanzlei berichtet von einem Angriff auf Teile der Verwaltung. Ein Krisenstab ist eingerichtet. Aus einer betroffenen Verwaltung heißt es, man sei „ohne Internet und Mailkommunikation nach außen“. Auf zwei Berliner Senatsverwaltungen hat es einen Hackerangriff gegeben. Das teilte das Presse- und Informationsamt des Landes am Montagnachmittag mit. Demnach habe sich „im Zuge forensischer Untersuchungen“ eine „Inkriminierung des Landesnetzes Berlin“ ergeben, heißt es in der Mitteilung. Betroffen seien sowohl die Stadtentwicklungsverwaltung als auch die Verkehrsverwaltung. Beide seien am Freitag vom Landesnetz isoliert worden.
Analysis Summary
# Incident Report: Cyberattack on Berlin Senate Departments
## Executive Summary
Two major Berlin Senate departments (Urban Development and Transport) were targeted in a cyberattack, resulting in a forensic "incrimination of the state network." To contain the incident, the departments were isolated from the state network, leading to severe operational disruptions, including the potential delay of housing benefit (Wohngeld) payments for over 50,000 households. Initial assessments suggest a data leak occurred, though the government claims the exfiltrated data was already publicly accessible.
## Incident Details
- **Discovery Date:** Approximately Friday (Isolation date) / Monday (Public announcement), August 2026
- **Incident Date:** Ongoing / Detected August 14-17, 2026
- **Affected Organization:** Senate Department for Urban Development, Building and Housing; Senate Department for Mobility, Transport, Climate Protection and the Environment.
- **Sector:** Government / Public Administration
- **Geography:** Berlin, Germany
## Timeline of Events
### Initial Access
- **Date/Time:** Not specified (Forensic discovery reported by Monday, Aug 18)
- **Vector:** Unknown (Forensics confirmed "incrimination" of the Berlin state network)
- **Details:** Attackers compromised portions of the high-speed data network used for city administration communication.
### Lateral Movement
- **Details:** The extent of movement is under investigation; there are concerns the attack on the two departments might have been a diversion for a broader compromise of other government entities.
### Data Exfiltration/Impact
- **Details:** A data leak was confirmed. While some sources suggested sensitive data, the Senate Chancellery stated that only publicly available Geoinformation/Open Data was exfiltrated.
### Detection & Response
- **Friday (Aug 15):** Affected departments were isolated from the Berlin state network.
- **Monday (Aug 18):** Public announcement by the Senate Chancellery; crisis management team established.
- **Ongoing:** Forensic investigations continue to determine the full scope of the breach.
## Attack Methodology
- **Initial Access:** Not disclosed.
- **Persistence:** Under investigation.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Suspected "diversionary tactic" using open data exfiltration to mask other activities.
- **Impact:** System isolation leading to "Denial of Service" for internal administrative procedures (Wohngeld, WBS, BuT).
## Impact Assessment
- **Financial:** Risk of delayed social welfare payments to 50,000+ households.
- **Data Breach:** Exfiltration of Geoinformation data (confirmed as Open Data by official sources).
- **Operational:** Total loss of external email and internet communication for affected departments; specialized software for housing applications (WBS) and social benefits (BuT) rendered inoperable.
- **Reputational:** High public concern regarding the vulnerability of municipal IT infrastructure and legacy systems.
## Indicators of Compromise
- **Network indicators:** Isolation of departmental segments from the Berlin "Landesnetz."
- **Behavioral indicators:** Unauthorized access/forensic traces within the state high-speed data network.
## Response Actions
- **Containment:** Full network isolation of the affected departments on Friday.
- **Eradication:** Forensic analysis initiated by the State Press and Information Office.
- **Recovery:** Implementation of manual workarounds and crisis meetings to ensure social benefit payments can be processed.
## Lessons Learned
- **Key Takeaways:** Legacy infrastructure (referenced in the article regarding Windows 11 updates and old servers) creates significant security debt.
- **Vulnerabilities:** The interconnected nature of the "Landesnetz" means a compromise in one department necessitates the isolation of others, causing massive service disruptions.
## Recommendations
- **Modernization:** Accelerate the decommissioning of legacy servers and Windows versions mentioned as risks in the context.
- **Segmentation:** Improve network micro-segmentation to prevent having to isolate entire departments during an incident.
- **Monitoring:** Enhance detection capabilities to identify "incriminated" network segments before data exfiltration occurs.
- **Culture:** Shift from treating IT security as a department-specific task to a city-wide security culture.