HackMyIP
← Back to News
2026-08-18 The Record

Berlin Cuts Two Ministries Off Government Network After Cyber Breach

Incident ResponseVulnerabilityData Breach

Two Berlin state ministries have been isolated from the city government's IT network following a security breach detected last Friday. The Berlin Senate Chancellery confirmed on Monday that the Ministry for Urban Development, Construction and Housing and the Ministry for Mobility, Transport, Climate Protection and the Environment have been cut off from the state network as a precautionary measure. Officials have not disclosed the identity of the threat actors, the initial attack vector, or whether any sensitive data was exfiltrated, though German public broadcaster RBB reported, citing government sources, that attackers allegedly exploited a vulnerability in the IT systems of one of the affected ministries.

Berlin's state-owned IT service provider, ITDZ Berlin, was not compromised in the incident, according to RBB. The two affected ministries operate a shared portion of the state network independently from ITDZ, which investigators now believe served as the entry point for the intrusion. Organizations monitoring similar infrastructure can use a port scanner to identify exposed services that could be exploited by attackers targeting government networks. The Senate Chancellery emphasized that "the security of the state network is the top priority" while declining to share further specifics for investigative reasons.

Both ministries remain operational despite the network isolation, though staff have lost access to email, internal systems, and the internet. Employees are now relying on telephones, text messages, and fax machines to communicate, according to RBB. The disruption has rippled outward, with district offices unable to process housing benefit applications and education and participation assistance requests that depend on systems operated by the urban development ministry. Authorities have not provided a timeline for restoring connectivity to the affected ministries.

The incident underscores how a single unpatched flaw can force entire government operations offline, disrupting critical public services for citizens. Network administrators responding to similar events can leverage a DNS leak test to verify whether internal traffic is being improperly routed during containment efforts. As the Berlin investigation continues, organizations are reminded to verify the integrity of their certificates and encrypted connections with an SSL/TLS checker to prevent attackers from exploiting misconfigured trust pathways within government infrastructure.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →