Skip to content
The Cyber Security Place

The data was compulsory, and there is no other city

Event dated 2 September 2026 · Published 2 September 2026 · 3 sources

Berlin's city government was compromised in early September 2026 and is being extorted, with the Qilin group claiming on its leak site to hold 5.79 terabytes taken from city systems — a figure that comes from the attackers rather than from any independent count. The same week brought ransomware at Manchester Airports Group, a standstill at Boston Scientific and a Canadian telecoms breach affecting 75,000 customers. What separates the municipal case is a property none of the commercial ones share: everybody in those files was legally obliged to be there, and cannot take their business elsewhere, because there is no elsewhere.

Every commercial breach contains, somewhere behind it, a decision. A person opened an account, bought something, signed up. The decision is often barely a decision — nobody reads the terms, and declining a service the whole economy assumes you use is a hard thing to do. But it exists, and the vocabulary of data protection is built on it: consent, purpose, the lawful basis, the option to withdraw.

A city holds a different kind of file. Registering an address, declaring income, enrolling a child in school, applying for a permit, claiming a benefit — none of those are choices, and none of them have a competitor. There is no consent to withdraw and no alternative supplier to move to.

Why that changes the obligation rather than the incident

The intrusion itself is unremarkable. Ransomware reached a large organisation with a wide estate, data was taken, and a demand followed — the pattern this site has described repeatedly through the year, most recently in a sector where the operator had no security function at all.

What changes is what the holder owes. A company that loses customer data has failed people who trusted it, which is serious. A government that loses citizen data has failed people who were compelled to provide it — and compulsion is a much stronger basis for an obligation than agreement is.

That is not a rhetorical point about outrage. It is an argument about where the standard should sit. The usual defence — that the organisation met the expected level of care, and a determined attacker will sometimes succeed — is available to a company operating in a market. It reads differently from a body that obtained the data by law and against which the affected person had no option to refuse.

A city is not one organisation

The phrase the city government was attacked describes an event with no determinable blast radius, because a city administration is dozens of services that happen to share a budget: registries, schools, social services, transport, planning, licensing. They run different systems, bought at different times, maintained by different suppliers, with different people responsible.

So the volume claimed — whatever the true figure — says nothing on its own about which residents are affected or how. Five terabytes could be one department's document archive or a slice of every service in the city, and the difference is everything to the person trying to work out whether it concerns them.

Establishing which is the slow work described in January, when a hospital took 159 days to move from detecting an intrusion to saying what had been taken. A municipal estate is larger and more fragmented than a hospital's, and there is no reason to expect it to be quicker.

The remedies that assume a market

Consider the standard advice offered to breach victims. Change your password — reasonable. Watch your accounts — reasonable. Consider taking your business elsewhere — meaningless here. Ask for your data to be deleted — the city is legally required to hold it.

Even the market pressure that eventually disciplines companies is absent. A retailer that handles a breach badly loses customers, and that prospect shapes behaviour before anything happens. A city administration has the same residents on the following Monday regardless of how it responds, which removes the mechanism that regulation is usually designed to supplement rather than replace.

What follows, concretely

Two things, and both are about design rather than response. Public bodies collect what statute requires and frequently keep it long after the purpose has passed, because nobody is rewarded for deleting records and somebody might be blamed for it. Retention schedules that are actually executed are the single largest reduction available in what a future intrusion can take.

And separation between services that share nothing but a budget. There is no operational reason for a permits system to be reachable from a schools system, and the only thing connecting them is usually an identity directory that was extended once for convenience. A city that segments along the lines of the services it actually delivers converts a municipal breach into a departmental one.

Neither is achievable in the weeks after an incident, which is the recurring difficulty with everything worth doing in this field. Both are achievable in the years before one, by an organisation that has accepted it holds data nobody agreed to give it.