The Berlin Senate was saying the theft amounted to at most 215,000 records until Friday afternoon. After 15:35 the Rhysida countdown ran out and the state began downloading its own files. That is how Berlin learned what it lost.
Florian Hauer, state secretary for digitalisation, told the interior committee on Monday:
“Was tatsächlich abgeflossen ist, wissen wir positiv erst seit Freitag 15.35 Uhr. Bis Freitag waren die Informationen, die wir hatten, der Index, den die Täter ins Darknet gestellt hatten.”
What actually left, we know for certain only since Friday 15:35. Until Friday, the information we had was the index the perpetrators had posted on the darknet.
Last week this blog asked the Senate to publish how much data left the network between 7 and 12 August, or admit it can’t.
Hauer admitted it.
The state isn’t able to assess its own exfiltration without help from the attackers, since its count came first from the attack catalogue and then from the actual attack files. The download alone, he said, would take days. Why? Is that because Copperhead Dobrindt blocked fiber speeds, personally slowing Germany down?
Hauer says the Landeskriminalamt is reading the dump alongside an unspecified AI sorting for classification markings. Reviewing what attackers publish is fine. Having nothing else to review is…not. Berlin claims no record of its own traffic, weighting investigations on whatever Rhysida chose to post. Berlin asks the bank robber for a copy of selfies because their own cameras were off and they never kept a vault ledger.
Twenty-One Systems
Then Maria Borelli, head of the state IT agency ITDZ, took the microphone.
“Wir haben alle Fachverfahren, die bei uns in Betrieb sind, haben wir die administrativen Passwörter bereits geändert, bis auf 21 Verfahren, wo das nicht möglich ist, weil das Passwort fest verdrahtet ist in dem Quellcode. Das heißt, es ist nur mit Unterstützung des Softwareherstellers möglich, das zu tun.”
For all the specialist applications we operate, we have already changed the administrative passwords, except for 21 applications where that is impossible, because the password is hardwired in the source code. That means it can only be done with the support of the software vendor.
Administrative credentials. Hardcoded. No rotation in sight.
Twenty-one systems that ITDZ itself runs, three weeks after discovery, with the vendor as the only path to rotation and no date offered.
Rhysida’s second package on Sunday night carried login credentials.
Joachim Selzer of the Chaos Computer Club said passwords from the first pre-release two weeks ago still opened the published systems the following Wednesday.
The first post in this series argued the laughter over weak passwords was a cover story for 8,110 critical infrastructure documents walking out the door.
I stand by that assessment. These 21 are a very different animal from the joking around with Ahabostsee123. A user picks a weak password and there’s in-built agility to rotate it, usually required by regulations.
The open question is why Germany in this day and age allows a vendor to have an admin password nobody can change, what procurement office signs for that, and which operator ran it for years without formal complaint (e.g. audits).
Any credential Rhysida captured for those hardcoded admin systems depends now on a vendor, if they even exist anymore, shipping code.
Note that we are making an assumption about the number. ITDZ can count 21 among the systems in its own care. The Left’s working-group audit found the Land has no inventory of applications on its network, and Hauer told parliament in August he was “surprised how big” the state IT system is.
It’s only big in a relative sense. If you don’t have a working inventory management system it’s always too big. Twenty-one is the figure from someone who kept track. Now we are wondering about the Land systems uncounted, and their password age that nobody has checked.
Radioactive reaction
Borelli opened her answer with a sentence about how ITDZ fits into the response:
“Aktuell agieren wir reaktiv, das heißt, wir reagieren auf explizite Anweisungen des Landes.”
Currently we are acting reactively, meaning we respond to explicit instructions from the Land.
The operator of the state network, during an active incident, describes itself to parliament like an obedient cog that merely turns as it is told, waiting for orders. That is the failure mode already described in the earlier post: security run as a service line inside an agency expected to turn a profit, the profit taxed, responsibility split between the agency, a chancellery commissioner, a security officer in every ministry and twelve districts.
That’s not a healthy environment for security to improve.
Bavaria gave its state security office a legal mandate over the whole network in 2017. Berlin’s equivalent explains that it has no initiative or ideas, and merely changes passwords when told to by people who don’t even know how many passwords exist.
In November 2024 Borelli told the digital affairs committee that cutting detection spend would produce “the risk of cyberattacks or errors.” That was right.
In September 2026 she tells the committee her agency is in “exchange” with the vendors and the security office on how to proceed with the 21 systems, now that the prediction has landed and it’s too late.
Monday run down
One answer on Monday placed the stolen data, “to my understanding,” on employees’ personal drives.
Bianca Kastl of the CCC, live-tooting the hearing, pointed at the leak’s own directory tree: “Personalangelegenheiten / GI-Vertraulich / 00_alt”. That’s personnel matters, classified confidential, archive folder. That has the hallmarks of a departmental share, which if so would be the third official account of this breach corrected by the dump itself, after “no sensitive data” on 19 August was completely wrong and the 215,000 figure changed on Friday.
A member asked whether the E-Akte, the electronic file system the Land is rolling out across its administration, is built so that a single admin account is unable to download everything. Kastl reports there is no answer. The E-Akte by design pulls copies out of distributed systems of varying security and joins them at one point. That looks to be where the 8,110 infrastructure files go next.
BSI president Claudia Plattner reached for platitudes and said Germany needs passkeys and real zero-trust architectures, “and that applies to all of Germany.” Marketing buzzwords are buzzwords. Passkeys and Zero-Trust are terms used for selling not for actual securing. Agility is the proper term for the rotation capability, without the downsides to Passkeys. RBAC projects will make all the Zero-Trust products look like bicycles on the Autobahn.
Hauer said further checks will “most probably” surface structural deficits that arose years ago, and that fixing them “will not cost little money.” Well, well they sure will cost a lot less money than NOT doing them. That’s how security usually works when it’s run right. Spend now or spend way more later. The money in November 2024 was yanked out under a coalition that is now asking for it back just thirteen days before the election.
The Left and Greens have an Aktuelle Stunde on Thursday.
The FDP wants an inquiry and two resignations. Let the politics run its course. The engineering here is much smaller and it shouldn’t matter who wins. At least twenty-one admin passwords are vendor dependencies, and if any of them sit in what Rhysida took, they belong to whoever reads the dump. The Land’s own operator has said on video that it is just following orders and can’t know or do what’s right on its own.
Every candidate for the Rotes Rathaus should be asked who is investigating, where the data flows, which systems and by what date will be burned to the ground and replaced.