Berlin data breach: Giffey holds Wegner personally responsible

Following the hacker attack by the group "Rhysida" on Berlin's administration, the political dispute escalates. SPD senator Giffey launches a frontal attack on CDU mayor Wegner.

Berlin data breach: Giffey holds Wegner personally responsible

Berlin data breach expands – coalition disputes over responsibility

As web.de reports, the political dispute has escalated following the severe cyber attack on the Berlin state administration. At the centre is an open conflict within the black-red state government.

The criminal group "Rhysida" infiltrated parts of the administrative network in mid-August and demanded 30 Bitcoin – equivalent to around two million euros – as a ransom. The Senate refused to pay. When the ultimatum expired last Friday, the attackers uploaded around 1.4 million files to the dark web – accompanied by the comment "Have fun, data hunters". In the night into Sunday, a further data package followed, which contained access credentials among other things.

Sensitive documents publicly accessible

The scope of the breach becomes clearer with each examination. The published documents include internal memos that expose weaknesses in Berlin's infrastructure. There are also plans for the defence case, private mobile phone numbers and addresses of people who are to be deployed in the event of a crisis – as well as personal documents such as birth certificates of children of city employees, identity card copies and certificates of good conduct.

The news magazine "Spiegel" discovered in a spot check, moreover, salary lists, account data, confidential disciplinary proceedings and documents on the protection of Berlin's fire brigade. Particularly sensitive: more than 550 files are said to relate to the expansion of the chancellery – including expert reports and statements from the state criminal police.

Giffey attacks Wegner

Economy senator Franziska Giffey (SPD) held Governing Mayor Kai Wegner (CDU) personally responsible for crisis management on Sunday. "He is responsible," she said at the "Tagesspiegel"'s "Land- und Genussmarkt". Responsibility for administrative modernisation and digitalisation lay – in the person of Chief Digital Officer Florian Hauer – solely with the Senate chancellery.

"He has to manage this now. Then one must be there in a crisis – that is what I would wish for now, and there is still room for improvement," Giffey said according to the "Tagesspiegel". With this, she also targeted the fact that Wegner attended the opening game of the Women's Basketball World Cup on Friday evening – only hours after the extortionists' ultimatum expired – together with Chancellor Friedrich Merz (CDU). Interior senator Iris Spranger (SPD) was also in the hall. The Senate chancellery stated that Wegner had been kept continuously informed.

Chaos Computer Club criticises failures

Sharp criticism comes from IT experts. Joachim Selzer, spokesman for the Chaos Computer Club, criticised substantial failures in the response to the attack. First data had been posted to the internet as "preview snippets" two weeks before the major release – and yet testers were still able to access the affected systems with the published passwords the following Wednesday. "Then I ask myself, why were all access points not blocked immediately after these preview leaks became known?" said Selzer.

The quality of the passwords was also appalling; furthermore, they had been stored in plain text. As a particularly illustrative example, he cited a scanned passport of an employee that was lying on the server. According to Selzer, it would take at least several more weeks until complete analysis of the leaked data was completed, with him calling for "maximum transparency in the processing".

Calls for resignation and parliamentary consequences

Berlin's FDP called for the resignation of both Wegner and Spranger. "Both have failed. Clarification and resignations are not mutually exclusive – they are two sides of the same political responsibility," the party declared. The Left and the Greens in the House of Representatives filed a motion for a topical hour entitled "Failure in the administration's IT security, crisis management bungled once again".

Green member of the federal parliament Konstantin von Notz spoke in the "Handelsblatt" of a "real data super-disaster". The case put "massive failures of the federal government" in the spotlight. Despite repeated warnings, known security gaps had not been closed. "The recent case in Berlin will cost taxpayers millions," von Notz warned.

Digital state secretary acknowledges structural deficits

Digital state secretary Florian Hauer attempted to calm things in the internal affairs committee of the House of Representatives. He explained that exclusively data of the lowest classification level – VS-NfD (classified – for official use only) – had been stolen. Documents relating to national security, the Bundeswehr or the federal government were not, to current knowledge, among them. In the case of files relating to the Military Counterintelligence Service (MAD), it turned out that these were merely parking permits.

Nevertheless, Hauer acknowledged that further checks would "very probably" reveal "structural deficits" that had originated years ago. Addressing them would "cost a considerable amount of money". The federal government stated through a spokesman that its own data systems had not been affected to current knowledge; evaluation was also ongoing through the National Cyber Defence Centre.

Giffey emphasised that her economy administration had not been directly affected by the data loss, as it relied on the state's IT Service Centre (ITDZ). Indirectly, however, supervisory board documents of state enterprises such as Stromnetz Berlin GmbH could have been compromised, as representatives of the affected environment and transport administration sit on their boards. Her department had set up its own crisis team and sensitised all 500 employees to the existing risks.

Source: Google News LU DE

Read this article in the original language