Cyber Threat Intel 6 min read

Berlin's Second Leak Is Credentials, and the Way In Was a Fake CAPTCHA

Login details went up over the weekend and the state will not say whether they still work. Researchers trace the intrusion to a page that asked a user to paste a command.

Priya Nair
Data, AI Governance & Policy Analyst
Published 14 Sep 2026, 11:07 AM (SGT)
Share:
A close-up of a laptop keyboard at a shallow angle — illustrating the step this attack depends on, which the victim performs themselves. A close-up of a laptop keyboard at a shallow angle — illustrating the step this attack depends on, which the victim performs themselves. Photo by webandi on Pixabay
Advertisement

14 SEP 2026 — A second tranche of Berlin's stolen data went up over the weekend of 7 September, and this one is login credentials. The state has not said whether any of them still work.

Alongside it, the initial access route has a name. Researchers have traced the intrusion to TerminalFix, a campaign that puts a fake verification page in front of a user and asks them to copy a command into their own terminal. Nothing was breached in the sense the word usually carries. Somebody was persuaded to run it.

Where the incident now stands

Data left two Berlin ministries — urban development and housing, and transport, mobility, climate protection and environment — between 7 and 12 August. Departments were disconnected from the government network on 14 August. Rhysida claimed responsibility in late August and put the figure at 5.79 terabytes: tens of thousands of contracts, emails, passwords and material it described as classified.

Governing mayor Kai Wegner called it "a very serious crime committed against the State of Berlin" on 6 September. The state's chief digital officer, Florian Hauer, has said Berlin will not be blackmailed. The weekend leak followed.

The personal data potentially exposed is the kind that does not expire. Names, addresses, dates of birth, bank details, email addresses and telephone numbers, alongside correspondence with government and the documents people submitted to it.

What TerminalFix asks of the victim

The technique belongs to the ClickFix family, and its whole design is to move the difficult step onto the person. A page appears claiming a verification check has failed — often styled as a CAPTCHA, which is the part that does the work, because a failed CAPTCHA is the one error message the internet has trained everybody to fix without thinking. The page then supplies a command and instructs the user to paste it into a terminal or a run box.

That command is the compromise. No exploit runs, no vulnerability is involved, and no patch was ever missing, because the payload arrives through the operating system's own perfectly legitimate ability to execute what its user tells it to.

What separates TerminalFix from earlier ClickFix variants is the objective. Consumer-grade versions of this trick were after one machine and its browser cookies. This one delivered a foothold inside a government network from which the attacker moved outward, which is a different class of outcome from the same three-second social interaction.

5.79 TBClaimed by Rhysida in late August
7 SepSecond leak, publishing login credentials
0Vulnerabilities required by the access route
20 SepBerlin goes to the polls, thirteen days later

Credentials are the part that keeps moving

The first leak was documents. This one is access, and the difference matters operationally rather than reputationally.

A published document is a fixed loss. Its damage is bounded by what it contains, and it does not grow. A published credential is a loss that other people can act on: it invites credential-stuffing against every other service where the same password was used, and it lets an attacker who is not Rhysida walk into whatever it still opens.

Berlin has not confirmed whether the credentials remain valid, and the absence of that confirmation is itself the useful signal. Rotating credentials across two ministries is not a weekend job when nobody can be certain which systems the stolen set covers — a difficulty created by the original intrusion rather than by the response to it.

An election in thirteen days

Berlin votes on 20 September. A state government has to answer for a breach of its own systems while campaigning, which shortens every timeline the incident response would otherwise run on and puts pressure on officials to say more than they can yet verify.

Advertisement

The federal information security office has established no connection to a state-sponsored actor, and the attribution so far is to a financially motivated group. That matters for the reading of the timing: a leak dropped a fortnight before a vote is consistent with ordinary extortion pressure against a target that publicly refused to pay, and does not require an interference narrative to explain it.

The timing is conspicuous, and nothing published so far establishes an intent beyond money.

What actually stops this one

Very little of the standard patch-and-harden advice applies here, which is what makes the case instructive rather than routine.

The controls that bite are narrow ones. Blocking the run dialogue and restricting terminal access for staff who have no reason to use one removes the hands the technique needs. Application allow-listing stops the downloaded payload even when the command executes. Monitoring for the specific shape of the attack — a clipboard paste immediately followed by a scripting host launching a network fetch — is detectable, and most organisations do not look for it.

The rest is training that has to be more specific than "be careful online". The instruction that works is a rule rather than a caution: no legitimate website will ever ask you to paste a command into a terminal to prove you are human. That sentence is the entire defence, and it fits on a poster.

The questions still open

Berlin can answer whether the credentials still work, and has not. Confirming they have all been rotated would close the most dangerous part of this leak and cost nothing to say.

The TerminalFix attribution also needs confirming or correcting by the state rather than sitting at the level of reported research. Other German public bodies cannot act on a vector nobody official has stood behind.

A wider question sits underneath both. Did the affected ministries leave the run dialogue available to ordinary staff? If they did, that was a configuration decision taken long before August, and it is the one a review should be about.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement