ctipilot.ch

Berlin Landesnetz compromise (August 2026)

incident · incident:berlin-landesnetz-compromise-2026-08

Compromise of the Landesnetz, the shared network of the Berlin state administration, established by forensic investigation and confirmed by the Senate Chancellery on 2026-08-17; two Senate departments were isolated from the network from 2026-08-14 and reconnected on 2026-08-23, blocking housing-benefit disbursement to more than 50,000 entitled households and other district-level citizen services. The Landeskriminalamt, the Berlin public prosecutor and the BSI are involved. No named authority has stated an initial-access vector, product or CVE (Senatskanzlei, 2026-08-17; Berlin.de, 2026-08-23).

Aliases: Hackerangriff auf das Berliner Landesnetz, IKT-Vorfall im Landesnetz Berlin

Coverage timeline
2
first 2026-08-23 → last 2026-08-23
Peak priority
notable
2 notable
Sources cited
10
8 hosts
Sections touched
2
weekly-looking-ahead, weekly-multi-day
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet
2026-08-232 appearances2026-08-23

Hunting pivots

Affected products
PTC Windchillmisp-stix

Story timeline

  1. 2026-08-232026-W34 looking ahead — items already in motion: an EU reporting clock nineteen days out, a Swiss ransomware verdict on 10 September, an intelligence library whose only fix is two commits, and a mass-extortion campaign its own analyst expects to widen
    weekly-looking-aheadSix dated items already in motion at the close of the week, each with a source
  2. 2026-08-23Berlin's state network was compromised on 14 August and both isolated Senate departments came back online on 23 August — nine days in which housing benefit stopped for more than 50,000 households and no named authority stated how the attackers got in
    weekly-multi-dayTwo ministries cut off the shared network, and the citizen services that stopped were in the districts

Where this entity is cited

  • weekly-multi-day1
  • weekly-looking-ahead1

Source distribution

  • berlin.de3 (30%)
  • 20min.ch1 (10%)
  • digital-strategy.ec.europa.eu1 (10%)
  • ncsc.gov.uk1 (10%)
  • netzwoche.ch1 (10%)
  • osv.dev1 (10%)
  • reliaquest.com1 (10%)
  • tagesspiegel.de1 (10%)

explore in graph

All cited sources (10)

Entries about Berlin Landesnetz compromise (August 2026) (2)

2026-08-23 · view entry permalink →

NOTABLENATOA1

2026-W34 looking ahead — items already in motion: an EU reporting clock nineteen days out, a Swiss ransomware verdict on 10 September, an intelligence library whose only fix is two commits, and a mass-extortion campaign its own analyst expects to widen

Items already in motion at the close of 2026-W34, each with a source and a date. Not predictions.

  • 11 September 2026 — the Cyber Resilience Act's reporting obligations start, nineteen days from the close of this week. The Act entered into force on 10 December 2024 and its main obligations apply from 11 December 2027, but the reporting obligations apply as of 11 September 2026, from which date manufacturers are required to report actively exploited vulnerabilities (European Commission, 2026-07-27). For a public-sector buyer the near-term consequence is on the supplier side of the relationship rather than the operator side: from that date a manufacturer of a product with digital elements sold into the EU carries a reporting duty it did not carry before, and the Commission published practical guidance on 27 July 2026 to help meet it.
  • Thursday 10 September 2026 — the Zurich verdict. The court intends to deliver judgment on that date (20 Minuten, 2026-08-17) in a trial Netzwoche describes as covering LockerGoga, MegaCortex and Nefilim (Netzwoche, 2026-08-19). It is the point at which the currently contested elements — the defendant's alleged development role, the alleged FSB cover identity of the Moscow-based principal — either become findings of a Swiss court or are rejected, and the defence has argued that the entire computer evidence set is inadmissible, which would collapse the indictment. Four named Swiss companies are victims in this case.
  • No release date for the misp-stix fixes. The load-bearing one of the three flaws disclosed on 21 August against the library MISP and other platforms use to convert between MISP and STIX has no tagged release carrying its remediation: the record for CVE-2026-77710 gives the last affected version as 2026.7.8 and lists the fix as two individual commits (CVE record mirrored into OSV.dev, 2026-08-21); the referenced operational entry records the same shape for its two siblings. Anyone running a MISP-based ingestion path is currently choosing between building from source and waiting for a release with no announced date. This one is close to home: it is the intelligence pipeline itself, not a product it reports on.
  • Berlin's forensic work runs into the coming weeks. Both Senate departments were reconnected to the Landesnetz on 23 August with immediate measures in place including continuously increased monitoring of their IT systems, and the investigation continues (Berlin.de (dpa), 2026-08-23). Nine days in, no named authority has stated an initial-access vector, product or CVE. The moment one does is the moment this becomes an operational finding for every administration running a comparable shared network.
  • Cl0p's Windchill campaign is expected by its own analyst to widen. ReliaQuest assesses with high confidence that exploitation of the flaw will expand to compromise more organisations in the coming weeks, with copycat adoption a moderate-confidence expectation as exploit code spreads (ReliaQuest, 2026-08-18). That is a vendor's assessment, carried at its own confidence; the named-victim count has been flat since 15 August, which is consistent with either a pause or a batch not yet published.
  • NCSC UK's agentic-AI guidance is interim by its own description. The authority states it is working with partners to develop formal guidance which will build upon and ultimately supersede the interim advice published on 20 August (NCSC UK, 2026-08-20). No date is given. Organisations building control sets against the interim version should expect the measuring stick to move, which argues for implementing the parts that are least likely to change — credential scoping, agent activity reaching the same monitoring as user activity, a named owner — rather than the ones written as maturity levels.

Builds on: 2026-08-23/misp-stix-import-trust-boundary-dos-parser-state · 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · 2026-08-19/clop-windchill-custom-implant-reverse-engineered

outlook23 Aug 23:59Zmulti-sourceOpen finding ↗

2026-08-23 · view entry permalink →

NOTABLENATOA2

Berlin's state network was compromised on 14 August and both isolated Senate departments came back online on 23 August — nine days in which housing benefit stopped for more than 50,000 households and no named authority stated how the attackers got in

This is the week's clearest example of an incident that a technical intelligence pipeline cannot publish operationally and a reader nonetheless needs to know about. This pipeline surfaced Berlin's Landesnetz compromise on 20 August, re-worked it with a scoped deep read on 23 August, and could not publish either time — because an entry describing attacker activity has to describe attacker activity, and after nine days there is none on the public record. What there is instead is a complete account of the consequences of isolating two ministries from a shared state network, and that is the part with a transferable lesson for any administration built the same way.

The Senate Chancellery's own release of 17 August states the finding in one sentence — "Im Zuge forensischer Untersuchungen hat sich eine Inkriminierung des Landesnetzes Berlin ergeben," forensic investigations having established a contamination of the Berlin state network — and records that the Landeskriminalamt, the Berlin public prosecutor and the Bundesamt für Sicherheit in der Informationstechnik were all involved, with an ICT emergency crisis team under the state's information-security commissioner stood up that day. The two affected administrations, the Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Climate Protection and Environment, had been separated from the Landesnetz since the preceding Friday, 14 August, as a precaution. The release closes the door on the question every defender asks next: "Aus ermittlungstaktischen Gründen können derzeit keine weiteren konkreten Informationen zu Ausmaß und Hintergründen gegeben werden" — for investigative reasons no further concrete information on scope or background can currently be given (Senatskanzlei, 2026-08-17).

What the isolation actually cost is the strategic content. At a press conference on 19 August the Governing Mayor said Berlin had been the victim of a hacker attack, that the incident was serious, and that on current knowledge no sensitive data had flowed out; the Interior Senator said the state election of 20 September was not endangered by the attack. The two administrations were reachable only by telephone, and services around housing benefit — both application and disbursement — were unavailable (Berlin.de (dpa/BerlinOnline), 2026-08-19). Note where that failure lands: not in the two ministries that were isolated, but in the district offices whose citizen-facing processes run on applications those ministries host. Tagesspiegel puts the population figure on it — disbursement of housing benefit to more than 50,000 entitled households was not possible (Der Tagesspiegel, 2026-08-23). Berlin.de's English news item of 23 August adds that the disruption also reached benefits under the education and participation package for children and adolescents (Berlin.de (dpa), 2026-08-23).

Nine days later the Governing Mayor announced that "All Senate departments are once again connected to Berlin’s state network and are, in principle, operational," with the Senate Chancellery noting that the specialised procedures used in the districts are in principle available again and that occasional disruptions and delays may persist at the outset; both administrations have implemented immediate measures including continuously increased monitoring of their IT systems, and the forensic work continues in the coming weeks (Berlin.de (dpa), 2026-08-23).

Im Zuge forensischer Untersuchungen hat sich eine Inkriminierung des Landesnetzes Berlin ergeben.

Aus ermittlungstaktischen Gründen können derzeit keine weiteren konkreten Informationen zu Ausmaß und Hintergründen gegeben werden.

Presse- und Informationsamt des Landes Berlin (Senatskanzlei) 2026-08-17

All Senate departments are once again connected to Berlin’s state network and are, in principle, operational,

Berlin.de (dpa) 2026-08-23
synthesis23 Aug 23:53Zmulti-sourceOpen finding ↗