Friday, 15:35. The Rhysida blackmail countdown ran out and 1,439,893 files from two Berlin ministries went up on the Internet (via Tor). Personnel files, children’s birth certificates, 80,000 traffic fine cases, and 8,110 documents on critical infrastructure including a vulnerability analysis of the city’s water supply. The mayor and his interior senator spent their evening relaxing at the basketball world championship.
The same Friday afternoon, the AfD pushed out Kristin Brinker’s 100-day program for running the city. After weeks of high-stakes news about the state of information security in Berlin, she came up with fourteen items.
Primarily she said surveillance needs to be massively increased, huge amounts of data gathered, with cameras on crime hotspots and on trashcans. That’s right, cameras on trashcans. She wants police checks without any cause or reason needed. A special police unit would be created inside the immigration office. Data would also be generated with a points file on every applicant for state housing. Everything, all of it, collects more and more data in the hands of government. None of it, however, mentions the headlines about the government network that had just lost 1.4 million files.
Saturday, Brinker finally commented on the data breach her 100-day plan ignored:
Der Daten-GAU zeigt aber auch, dass der Datenhunger des Staates eingehegt werden muss.
That says the data disaster is proof that the state’s appetite for data must be reined in. She’s complaining that the state collects too much data. A day after she complained that the state doesn’t collect enough data.
If you read the AfD press office on Friday and then on Saturday, you’d be excused for thinking they don’t want to win, because then they would have to stand for something and couldn’t just attack everything everyone else said.
State Data Appetite
The state shouldn’t expand to total surveillance, and the state shouldn’t collapse to total ignorance. Those are extremes being pushed by the extremist AfD party, when in reality it is the balanced middle that is the right path. The files in the dump are map data any district office hands out, fines the state is legally required to keep, contracts it must retain, personnel records it must hold, and infrastructure risk analyses that federal law obliges the water utility to write so it knows where it can be broken. If anyone would be so stupid as to choose the Saturday version of the AfD, then the water critical infrastructure operations map is never completed and water is at risk. Brinker thinks data must be collected for safety, and also that data must not be collected for safety. It’s evidence that she doesn’t understand safety, and she doesn’t want to be accountable for the words she uses.
Again, she had three weeks’ notice of the breach and a week’s notice of the dump, and dropped her big plan for Berlin with zero mention of information security. The countdown was public from 28 August. She knew the dump deadline and completely missed it, published an incomplete governing plan that day without noticing, and then Saturday twisted herself into a pretzl to look like she cared.
How Berlin Failed
Nevermind the AfD lack of a clue. The real problem beyond the data itself being exposed is how Berlin has scaled down the team needed to detect and prevent breaches, while the risk of breach has gone up.
In November 2024 the CDU-SPD coalition cut the state network budget from 32 to 18 million euros and took 2 million specifically out of intrusion detection. Yup, they cut the budget to detect breaches. The head of the state IT agency, Maria Borelli, told the digital affairs committee what that meant:
“Es entsteht das Risiko von Cyberangriffen oder Fehlern.” The risk of cyberattacks or errors arises.
She added that the finance ministry was taking her agency’s surplus into the state budget over her own board’s vote, so she couldn’t invest to maintain what she had. Manuel Atug, an infrastructure security consultant, had already told the interior committee twice:
“Ihr betreibt desolate Cybersicherheit.” You run desolate cybersecurity.
The Left objected on the record. Nobody else did. And from that you might gather which party was reading the security budget.
Twenty months later Rhysida spent five days, 7 to 12 August, emptying two ministries. No alerts went off. The agency’s security team caught it by accident, noticing odd traffic in ministries outside its remit, two days after the data was gone. That is the outcome Borelli described to the committee before the cut was made.
It’s worth looking at how other states made a different choice. Bavaria created a state information security office in 2017 with a legal mandate over the whole state network: every security element’s logs into one central SIEM, suspicious cases to a Cyber Defence Center, and an advisory duty covering municipalities and state-owned utilities. A water utility is a client by design.
Berlin runs its security as a service line inside an agency expected to turn a profit, then taxed the profit, and split responsibility between the agency, a commissioner in the chancellery, a security officer in every ministry and twelve districts. By the Left party’s own working-group audit it doesn’t know how many applications run on the network. A state that can’t do inventory and asset management, which is step one, can’t move to prevention and detection because it doesn’t even understand what it’s looking at yet.
A year to the day before the dump, the Senate told the Greens that comparable attacks were “nicht bekannt,” not known, and that responsibility for cyber defence was still being evaluated. Not known meaning an absence of evidence, not the evidence of absence.
Who Will the AfD Target Now
Stefan Evers, finance senator since 2023 and now the CDU’s candidate for mayor. His ministry cut the detection budget, took the agency’s surplus, and holds the state’s stake in the water utility, whose 2020 audit found eight critical and nine high vulnerabilities, firewalls “faulty, incomplete and untraceable,” overall grade deficient. Ten were promised fixed by that July. Seven were never publicly closed. A freedom of information request for the audit, filed 31 July 2020, still shows awaiting response. Now the map of all that procrastination has been dumped onto the Internet.
Iris Spranger, interior, who heard Atug twice. Florian Hauer, chief digital officer, who couldn’t tell parliament in closed session when the attack happened or whether it was over. Kai Wegner, who on 19 August said no sensitive data was taken. While we can say Brinker’s attack script “Wegner lied” is correct, it also was what the dpa wire ran Friday under “gross negligence.” She showed up a day late and said “again.”
Her own record contradicts the remedy she’s proposing now. Her recent parliamentary questions are about cutting state personnel costs, the media regulator’s scrutiny of journalists, and NGO funding. The Senate’s answer on personnel costs notes that the transport ministry couldn’t respond because of the cyberattack. The breach was in her own paperwork weeks before the dump. I can’t emphasize enough there is zero evidence she asked anything or came up with any ideas. It’s shocking how she didn’t seem to care.
Who Serves Berliners
The Greens said there should be a breach portal so citizens can check whether they’re in the dump. The Senate says notification is offered “on a risk basis” and a web form. The Rhein-Pfalz district, hit by a similar crew in 2022, was able to post 2,549 individual letters within three weeks. Berlin, four years later and with a 45-billion-euro budget, points you to a form built for reporting bicycle theft.
The Left and the Greens have the seats to force a parliamentary inquiry but they won’t file before the election, because every coalition afterward runs through the SPD that held the interior ministry while this happened. Brinker won’t file either. A hearing about what steps were taken minute-by-minute on the detailed network logs is where a “safety” party that stands for nothing goes to die.
What the breach proves is not that Berlin has gathered too much data. It’s that Berlin stopped paying to watch what the law requires it to know, was warned in public, and did the wrong things anyway. That has names: Evers, Spranger, Hauer, Wegner.
What Brinker’s fish-out-of-water flip-flop act from Friday to Saturday proves is that the AfD will repeat this failure at higher and higher cost. Her cameras, checkpoints and housing file are all the kind of data that attackers want. Her plan adds them to a network she has no plans to secure. If the problem is the data, then the AfD shouldn’t run on collecting the most data and doing the absolute least to protect it.
The Left and Greens should immediately file the inquiry and let the coalition explain why it should wait. The Senate should publish how much data left the network between 7 and 12 August and the status of the seven open water findings, or admits it can’t. And every candidate for mayor should be held to answer one question in public: will you restore intrusion detection on the state network, and how much? Brinker’s already proved she won’t and can’t. She popped out fourteen items, and not a single one of them protected against cyberattack.




