Following the publication of data stolen from Berlin’s city administration, Germany’s Federal Office for Information Security (BSI) has warned of an increased risk of targeted phishing attacks and so-called “hack-and-leak” activity. Acronis CISO Gerald Beuchelt weighs in on the risks and recommends steps organizations can take.
Germany’s Federal Office for Information Security (BSI) has warned of an elevated risk of targeted phishing attacks following the publication of data originating from Berlin’s city administration. The agency also pointed to so-called “hack-and-leak” activity, in which stolen information is deliberately released to put additional pressure on affected organizations.
A recent case in North America illustrates how far-reaching the consequences of large-scale data breaches can be: according to a report by KrebsOnSecurity, a dark web service allegedly offered scans of more than 153 million driver’s licenses for sale. The FBI has reportedly opened an investigation into the source of the data. Security experts note that genuinely stolen information and documents can make fraudulent messages considerably more convincing, facilitate identity theft, and be manipulated or taken out of context.
Gerald Beuchelt, Chief Information Security Officer (CISO) at IT security vendor Acronis, commented on the Berlin incident: “The data breach at the Berlin administration shows that the consequences of an attack extend far beyond the initial disruption to IT systems. Once stolen information is published, organizations face a prolonged business and reputational crisis: authentic data can be exploited for convincing fraud and phishing attempts, while genuine documents can be manipulated or taken out of context.”
According to Beuchelt, cyber resilience must therefore not be limited to prevention. Organizations need to detect attacks early, protect identities and sensitive data, maintain secure and isolated recovery options, and be prepared to communicate reliably with employees, customers and partners. Backups remain essential for business continuity, he said, but cannot on their own undo a data theft. What matters, he argued, is a holistic approach that combines cybersecurity, data protection and regularly tested recovery processes.
Acronis outlined eight areas of action for organizations affected by a data leak or facing heightened risk. Unusual requests, such as payment instructions, password resets, document transfers or changes to contact details, should always be verified through a known, independent communication channel. Caution is warranted even with information that appears genuine, the company noted, since attackers can use stolen names, contracts or internal details to make phishing messages more credible.
The company further recommends resetting potentially compromised credentials without delay, reviewing privileged accounts and enforcing multi-factor authentication. Before making major changes, organizations should preserve log data and affected systems so investigators can reconstruct the incident. Exposed data should be classified by sensitivity, with people, systems and partners facing the highest risk prioritized for protection and notified in line with applicable legal requirements.
Published material should be verified before use or distribution, Acronis said, since authentic content can be combined with manipulated files or misleading claims. The company also advises regularly testing recovery capability and keeping backups isolated from production systems and protected against tampering. In the weeks and months following an incident, monitoring should be stepped up for phishing attempts, identity misuse and the reuse of compromised credentials.
Whether and how Berlin’s city administration responds to the BSI warning remains to be seen but it seems to live up to its bad reputation: The far left Bezirk of Lichtenberg has refused the use of security software. Security experts expect phishing campaigns linked to the data leak to increase in the coming weeks.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de