Russians are having a laugh about Ahab on the East Sea 1-2-3. And then there’s Sunshine 13. These were passwords disclosed in the Berlin Senate breach. The “Ahabostsee123”, is in fact a yacht for vacations in the Baltic. Much of the press seems to be wagging a finger about BSI recommendations, calling the passwords weak.
The actual story is that 8,110 critical infrastructure risk analyses and emergency plans walked out the door as if nobody is paying attention.
The password story is a form of institutional misdirection. The laughs obscure the real story, the structural one.
Seven Days, Six Terabytes, One Breach
From August 7 to 14 the Russian-speaking ransomware crew Rhysida held access to the networks of two Berlin Senate administrations, transport and building. Seven days of continuous exfiltration before anyone noticed. 5.79 terabytes. Roughly 1.44 million files spanning at least 2014 to 2026, down to Bundesrat correspondence with a federal minister who retired in 2018. That’s a decade of unsegmented material, reachable from a single intrusion, in the largest data theft in the history of the Berlin Landesverwaltung.
It’s floating up now for a 30 bitcoin minimum, roughly two million euros, with bids closing Friday afternoon. The Regierender Bürgermeister says Berlin will refuse to be extorted, no blackmail. Smart. Germans agree on the whole and extortion payments are always advised against, always. The 5.79 terabytes are gone no matter what.
What the Russians Took
Read the ransomlook.io inventory that the Tagesspiegel has documented, once you skip past the giggles and passwords:
- 8,110 documents, risk analyses, and emergency plans for critical infrastructure, with Rhysida specifically showcasing Verwundbarkeitsanalysen of the Berlin water supply
- 11,777 folders and documents marked confidential or classified
- 5,941 files of access credentials, including credentials for the electronic building permit system and for the database of Payone, the payment processor handling transactions for the Land Berlin
- 27,299 personnel files and pay records, including disciplinary proceedings now dangled as individual extortion material
Rhysida sells to whoever pays. That is the thing to watch. Moscow’s sabotage arm, the one Dobrindt keeps calling Vulkangruppe (a name that fails every German left-wing naming test, no less) left-wing, can arrive any minute. It needs 30 of Putin’s bitcoin and a Friday afternoon. Expect this to work its way into another round of Dobrindt waving his favorite false-flags through the next critical infrastructure breach.
The plain-text credentials sat in files with the operationally efficient names like “Passwort.docx”. Unencrypted. Working access data for permit and payment infrastructure, typed into a Word document named after exactly what it contained, which an attacker had a week to poke around and read.
Mangelhaft Wasser
The water supply item deserves special attention, because it has German history worth telling. In summer 2020 the consultancy Alpha Strike Labs, commissioned by the Berliner Wasserbetriebe themselves, found more than 30 vulnerabilities and graded the utility’s IT security “mangelhaft“. Is there a better word for failing? The BWB announced a Sofortpaket (immediate) fix-it project. Remediation, however, was only at the level of self-reported. Independent verification of the fixes, six years later, translates into a fat zero: none that I can find.
So Rhysida is advertising a vulnerability analysis of the city’s water system, which sounds like offering a Weißwurst to Oktoberfest. The map already exists. Alpha Strike drew it in 2020 and handed it to the utility. Whether Rhysida holds that old map or a newer one goes undisclosed, which is how sellers inflate value. Here it makes no difference. Berlin bet that it would never have to show proof the 2020 holes were closed. The auction calls that bet. Every buyer gets to test the Sofortpaket, and the Wasserbetriebe get to find out who was right.
Gears of fear turning
The Senate’s access decisions tell you how governance is spelled in German. The breach becomes public in mid August: the home office access is restricted. Then a week later access gets restored. Monday morning, September 1, access is cut again. Ok, but why? This time we know Tagesspiegel published two of the stolen passwords.
Ahab on the East See and Sunshine are funny, but really they are scary.
All the credentials were exposed the entire two weeks. The intrusion, the plaintext files, the exfiltration were known to the Senate for two full weeks. What actually changed is exposure to the public of what the institution was sitting on, and who was attacking. Berlin incident response wears the suit and tie of press response, which happens to be the same reflex I documented in the recent tragic CSD attack: the state performs a dance around what’s leaking to the public, while the ground level failure analysis goes unowned and unanswered.
Let’s talk about what really is going on, as much as Berlin culture seems to want to do everything except that.
The Cover-Up
Call it what it is. Operators knew, operators played dumb.
They knew in 2020. Their own consultants handed them a failing grade on the water system and a list of more than 30 holes. They interpreted that as a moment of self-certification, in order to produce no written record of whether anything was fixed. They manufactured a silence as their product, instead of a list of failures and fixes.
An operator who types passwords for their payment backend into “Passwort.docx” knows what all of that means. It’s 2026 in Berlin, not 1936. That file existed because nobody touching it believed in accountability, what an honest audit would bring, let alone the press.
And they knew when they were exposed. Watch the dates. Breach goes public: access restricted. A week later: access quietly restored. Monday, the Tagesspiegel prints the passwords: access cut the same morning. That is a team tracking how they look to someone judging them, lacking internal moral compass, acting on getting exposed instead of getting a clue. Nobody managing legibility that precisely is confused about what they prioritize. They are covering and ducking, pivoting to please whomever they think has immediately authority over them.
A state of improvisation, as political scientists have explained about German institutional habits, instead of rational documented actions.
Throwing blame at “Sonnenschein13” is part of the same operation. Point at the clerk’s password, have a laugh and click on the BSI hygiene lecture. The questions start and stop at that weak endpoint. That’s a shadow of Dobrindt pointing at an attacker’s suspended sentence while perimeters fail to meet baselines, with barrier plans unfunded. The employee is strung up to be visible, far more attention gathering than the operators and the curse of Dobrint.
Berlin collected everything, then they apparently protected nothing, such that when the story broke they spun into managing perceptions of risk instead of the risk. Run the training budget and the apology as routine, then write it off. The questions that actually need to be invested in have names attached: who signed off on skipping independent verification of the Sofortpaket? When? Who owned the directory and the file in it called Passwort.docx? Who ordered home office access restored mid-incident, and who ordered it cut again Monday morning, and what did that person hear over their morning coffee? Put those names in an Untersuchungsausschuss and the whole blowup about a Russian-driven auction gets a lot less interesting. And if they have ties to the AfD, we’ll get closer to the real story here about Russia getting a visit from the CIA about a Winchester America being unable to defend Germany anymore.
Ahab on the East Sea in the Sunshine, is not the story people think it is.

