Faultline Faultline Kommando 161

Germany · de.indymedia · · 3h

Degitalization: The Disservice

Deutsch (original) · Auto-translated to English

The name of the city of Berlin is not directly related to bears. And yet several disservices there facilitated a major cyber attack. This attack is not an isolated case and information security in Germany is grotesque.


https://cdn.netzpolitik.org/wp-upload/2026/09/jin-yeong-kim-f98dJ8VkuTk-...class="attachment-landscape-860 size-landscape-860 wp-post-image" alt="A close-up of a fly" decoding="async" srcset="https://cdn.netzpolitik.org/wp-upload/2026/09/jin-yeong-kim-f98dJ8VkuTk-...1920w,https://cdn.netzpolitik.org/wp-upload/2026/09/jin-yeong-kim-f98dJ8VkuTk-...860w,https://cdn.netzpolitik.org/wp-upload/2026/09/jin-yeong-kim-f98dJ8VkuTk-...1200w,https://cdn.netzpolitik.org/wp-upload/2026/09/jin-yeong-kim-f98dJ8VkuTk-...380w,https://cdn.netzpolitik.org/wp-upload/2026/09/jin-yeong-kim-f98dJ8VkuTk-...1536w" sizes="(max-width: 1920px) 100vw, 1920px" />
The annoying insect. – Public domain-like released by unsplash.com:https://unsplash.com/de/@jkslash">Jin Yeong Kim


Once upon a time there was a bear and an amateur gardener in his retirement home.
Both were lonely and became friends from then on.
Now the bear lived in the little garden and worked here and there.
One day the gardener was sleeping peacefully.
It happened that a fly crawled up his friend's nose.
Tries to scare away the annoying insect the bear.
The bear takes a paving stone and throws it with full force.
Killed his friend with full force.


To get started with today's degitalization, we should give us a slightly poetic short versionhttps://projekt-gutenberg.org/authors/jean-de-la-fontaine/books/lafontai...“The Bear and the Garden Friend” by Jean de La Fontaine serve. The fable is the origin of the saying “doing someone a disservice.” It describes the attempt, with supposedly good intentions, to ultimately make a situation much worse through one's own actions.

In the past few weeks, situations have repeatedly arisen in which information security in particular has been done a proverbial disservice. It almost seems as if a whole herd of bears were on the move, although bears tend to be solitary creatures, even the particularly notorious oneshttps://de.wikipedia.org/wiki/Problemb%C3%A4r">Problembarys. An attempt to summarize the disservice of the last few weeks.

The little bear

Despite phonetic similarity, the name of the city of Berlin is not directly related to bears. Berlin comes from more of a placehttps://de.wikipedia.org/wiki/geschichte_Berlins#Namensherkunft">Swamp, from the origin of the word. Apart from that, the bear is Berlin's heraldic animal and in view of current events, this leads us to a first example of disservice.

Now the cyber attack with the subsequent leak of around a million data from two Berlin Senate administrations is a topic whose deeper causes are not so easy to explain, especially since the situation is of a certain kindhttps://www.heise.de/meinung/Auf-Luecke-spiele-Was-in-Berlin-den-Rhysi...brims.

What actually happened? An attacker has been moving in the networks of two Senate administrations in Berlin since at least the beginning of August and is happily extracting data. The attack finally takes place around mid-Augusthttps://www.heise.de/news/Cyberattacke-auf-Berliner-Verwaltung-Ermittlun.... It turns out that this has probably been going on for a whilehttps://www.heise.de/news/Berlin-Cyberattack-auf-Verwaltung-begann-lang...

Due to the attack, the affected Senate administrations are temporarily unable to act because they are disconnected from the state network. The payment of housing benefit for around 50,000 eligible households is not within the normal periodhttps://www.heise.de/news/Berliner-Verwaltungen-nach-Cyberattack-weiter...possible. After a few days, the authorities concerned get back to workhttps://www.heise.de/news/Nach-Cyberattack-Senatsverwaltungen-wieder-am.... A very large network, the size of which is up to youhttps://taz.de/Hackerattack-auf-Berliner-Verwaltung/!6206839/">surprisedwas, as interim CDO Hauer then discovered. In between, the Senate administration tries to reassure people that it was just a “very professional attack”.https://www.tagesspiegel.de/berlin/ein-sehr-professional-attack-hack...publicly viewable datadrained away. Don't worry, everything is under control.

Enter the problem bear

Shortly afterwards, the loss of control follows. A first admission that maybehttps://www.t-online.de/nachrichten/deutschland/id_101406574/sensible-da...more datacould have flowed away. Rhysida, an internationally active ransomware group that is more financially motivated and whose origins are unknown, appears on the darknethttps://www.morgenpost.de/berlin/article413028932/forschungen-zu-cybe...constantcan be clarified, a subtle hint. This states that the data from Berlin can be “purchased exclusively” before it is published by paying 30 Bitcoin. He was the first to find ithttps://www.spiegel.de/netzwelt/berlin-cyberattack-auf-die-hauptstadt-d...[€].

As a result, the state of Berlin behaves consistently correctly, at least with regard to the ransom demand: it wants tohttps://www.inforadio.de/rubriken/interviews/2026/09/04/hacker-attack-b...don't blackmaillet. As a result, it will take place on Friday, September 4thhttps://www.spiegel.de/netzwelt/berlin-hacker-veroeffentlichen-offenbar-...publicall data on the dark web.













We sound the alarm.
For your basic rights.



Join now








The hacker group is a bit sloppy when uploading the data andhttps://www.rbb24.de/politik/teil/2026/09/berlin-cyberattack-neues-d...third data packetonly appears on the night of September 5th to 6th. With the publication of all data on the Darknet, a laborious search for clues begins as to exactly which data was actually leaked. This tedious search for clues can still be donehttps://www.rbb24.de/politik/teil/2026/09/berlin-innen committee-hacke...last. Although the exact extent of the data outflow is not yet entirely clear, the all-clear has already been given: there arehttps://www.zeit.de/politik/deutschland/2026-09/cyberattack-berlin-rhys...military datadrained andhttps://www.zeit.de/digital/2026-09/hackerattack-berlin-stadtverwaltung...Data of the lowest level of secrecy. Meanwhile, we are already supportinghttps://www.zeit.de/digital/2026-09/hackerattack-berlin-rhysida-bsi-bka...Federal authoritiesduring processing.

Years of disservice

In the midst of this Berlinness, a lot of disservice has crept in. Be it the hasty communication that it wasn't all that dangerous, which then had to be taken back several times. Be it when selecting the service provider who will provide support with digital forensics and yourselfhttps://www.tagesspiegel.de/berlin/nach-hackerattack-auf-verwaltung-ber...further dangerfor digital sovereignty.

This can be particularly interesting when processinghttps://www.youtube.com/watch?v=KVLhj4F97pc&list=PLgqUxMeOmFHwGeGhst...of the Committee for Digitalization and Data Protection on September 7th.

Of course, the Senate asserts that it has done nothing wrong. The employee who clicked on the link in the phishing email is simply part of the security architecture on which one is dependent. A statement that represents a disservice to all administrative employees. No, employees who respond to a sophisticated phishing campaign with an overhttps://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-cam...levelsongoing attack chain likehttps://www.bsi.bund.de/SharedDocs/Cybersicherheitswarenen/DE/2026/202...Falling in and portraying them as the culprit defeats any commitment to the digitalization of administration. A person cannot be blamed for the lack of safety rails that should be taken for granted.

In Berlin, investments in information security have been delayed over the years. Gaps were ignored and over decades a zoo of applications that could no longer be handled in a modern way emerged, all of which have lowered the level of information security to such an extent that such major damage as the current one could have occurred in the first place.

Cuts in information security funding?https://netzpolitik.org/2024/berliner-finanz-2025-it-sicherheit-und-ve...Budget 2025 recent. Were there any known defects? Yes, of course, there are particularly serious deficiencies in the context of the administration of justice, for example, as the Court of Auditors inhttps://www.parlament-berlin.de/ados/19/IIIPlen/verfahren/d19-2082.pdf?#pa...2024stated. Security of specialist procedures, i.e. the specialized applications that host the majority of administrative processes? “You yourself know how old some specialist procedures are,” was the statementhttps://www.youtube.com/watch?v=KVLhj4F97pc&list=PLgqUxMeOmFHwGeGhst...from the House of Representatives. With 21 specialized procedures in the Berlin context, compromised passwords cannot be changed at all because they are permanently stored in the source code.

All of which are a disservice to information security. Be it because of stinginess, ignorance, lack of prioritization or “we’ve always done it that way”. Added to thathttps://www.golem.de/news/verwaltung-it-dienste-berlins-kaempft-um...chronic underfundingthe Berlin municipal service provider ITDZ, which was not responsible for monitoring the affected Senate administrations, but nevertheless noticed and reported the suspicious network connections during the exfiltration of the data - in an administrative sense, almost illegally without direct responsibility. In addition, there is “completely destroyed communication” between the ITDZ and the Senate administrationhttps://www.tagesspiegel.de/berlin/kern Schmelze-und-katastrophe-streit-z...Mid-year [€].

With all this confusion in Berlin, it is no longer so clear who is doing what service to whom, but all in all it is a chain of disservices in the sense of information security that has lasted for years. They have to wear ithttps://www.cyberkritikenmanagement.blog/was-berlins-datenabfluss-fur-komm...The leak in Berlin will affect many people, authorities and organizations outside of Berlin over the next few years.

Falk Steiner, of all people, spreads hope in this Berlin atmospherehttps://www.heise.de/meinung/Auf-Luecke-spiele-Was-in-Berlin-den-Rhysi...a comment, who feared even worse:




Everything that is relevant to network policy


Three times a week as a newsletter in your inbox.




Subscribe now



The only positive side of the Berlin-Rhysida debate is that, in view of the planned reform of intelligence law, no one has yet called for a “hackback” by the Federal Intelligence Service on Rhysida infrastructure - even if they didhttps://www.heise.de/news/Geheimdienst-Reform-Mehr-Befugnisse-fuer-BND-u...Amendment to the Federal Intelligence Service Actcould, in principle, make exactly that possible. Sometimes it's progress if the most absurd ideas aren't aired.


Bear traps

Actually, this column should be about that other disservice. The amendment to the Federal Intelligence Service Act. Thehttps://www.heise.de/meinung/Kommentar-Das-BSI-darf-nicht-zum-Zero-Day-H..., wanting to “make valuable” security gaps for German secret services. The political attempt to pass on security gaps that are reported to the Federal Office for Information Security (BSI) to secret services. Security gaps, which are now also reported in the context of the Cyber ​​Resilience Act by manufacturers of products with digital elements to the BSI as a central officehttps://www.heise.de/news/Gilt-ab-heute-CRA-satz-24-HRS-Frist-fuer-...eat.

But that seems to have been averted for the time being: No, now there's no rejection againhttps://www.heise.de/news/Geheimdienst-Reform-Mehr-Befugnisse-fuer-BND-u.... Promised. Or?

When the topic for this column was set, attackers in two Berlin Senate administrations were so deep into the system that they were able to quietly exfiltrate several terabytes of data over days. Data of almost all types of confidentiality, data from citizens, companies, critical infrastructures, the water supply in Berlin, information about plannedhttps://netzpolitik.org/2026/kameras-und-dronen-in-berlin-was- Behavior...Property protection, copied MP3s to administrative directories and so on.

The picture of information security in Germany is grotesque. On the one hand, more and more political powers are being devised for surveillance, but also for offensive cyber attacks, at least in thehttps://www.bmi.bund.de/SharedDocs/gesetzlementverfahren/DE/Downloads/r...urfof departments in ministries. It was said at the beginning that this could form the basis for order fulfillment. This reflects an outdated and grotesquely distorted image of information security, in which security gaps can only be exploited by the “good guys” and professional cybercriminals are deterred by the threat of punishment.

On the other hand, public institutions that can hardly maintain an adequate level of information security on their own. The Senate administrations in Berlin are not an isolated case, they are just the part of the administration that is currently in focus. The cyber attack on Anhalt-Bitterfeld washttps://kommunalwiki.boell.de/index.php/Cyberattack_auf_Landkreis_Anhal..., South Westphaliahttps://kommunalwiki.boell.de/index.php/Cyberattack_auf_die_S%C3%BCdwes.... Berlin,https://kommunalwiki.boell.de/index.php/Cyberattacke#Senatsverwaltung_B.... As a result, the next major incident will come – when exactly is uncertain.

To keep it grotesque, this column ends with a quote from Sinan Selen, President of the Federal Office for the Protection of the Constitution, whohttps://www.heise.de/news/Verfassungsschutz-sicht-kein-Zero-Day-Problem-...with a view to protecting society, at least clearly outlines:


The mission is clear: protect the economy and society. And that won't work if we act at the front as if we had secured the front door and then consciously leave the patio door open at the back.


Let's hope that they have already found all the patio doors in Berlin.



The work of netzpolitik.org is financed almost 100% from donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

web address: https://netzpolitik.org/2026/der-baerendienst/author/group: Bianca KastlTopics: Netactivismfeed date: Sunday, September 13, 2026 - 07:57

Read the full story at the source →

Source: de.indymedia