Cyberattack in Berlin, Data Incident at LMU: What This Means for Data Protection in AI

Two separate incidents, one central question: how can sensitive data reach the outside – and what does that mean for organizations that use generative AI?

Two incidents, one central question

In August 2026, an attack on two Senate administrations connected to Berlin’s state network was detected. The affected areas were isolated, and the State Criminal Police Office (LKA), the Berlin public prosecutor’s office and the Federal Office for Information Security (BSI) were notified1. The Rhysida group subsequently claimed responsibility, published parts of the stolen data on its darknet page and demanded 30 Bitcoin. According to eGovernment, the published data included, among other things, access credentials and personal information; the full extent is still under investigation2, 3.

One month later, unauthorized access to enrollment data was recorded at LMU Munich. According to LMU, names, contact details, bank details and information about previous educational qualifications may be affected. It is not yet clear how many people are affected, and there are currently no indications that the data has been published or misused4, 5. According to LMU, passwords and LMU login credentials were not compromised6.

What has been confirmed?

In the Berlin case, parts of the stolen data have been published. At LMU, unauthorized access has been confirmed, but there are currently no indications that the data has been published. The two incidents are separate.

AI and data protection: how sensitive data can reach the outside

Even though the two incidents do not establish AI as the cause, generative AI creates an additional data channel. Employees may inadvertently copy personal data, internal documents or access information into an external service. The issue is that, depending on the provider and its configuration, inputs may be processed or stored outside the organization’s own IT environment. This would not constitute a hacking attack, but it could still be a data protection incident.

Data protection starts before the prompt – but how?

SOWA Privacy replaces sensitive data with placeholders before the prompt leaves the device and is fed into an AI model. This prompt anonymization prevents raw data from being unnecessarily transmitted to external AI services. Nevertheless, clear rules, approved tools and training remain essential.

Use AI securely and avoid data leaks

Have data automatically detected and replaced before transmission using AI privacy tools such as SOWA Privacy – and do not copy sensitive content into prompts without protection. Equip staff through training, clearly defined rules and approved tools.

Frequently asked questions

Can entering data into ChatGPT or other AI tools be a data protection issue?

Yes. If personal or confidential information is entered into an external AI tool, the data may be processed outside the organization's own IT environment. Whether a specific risk exists depends, among other things, on the provider, the contractual terms and the technical configuration.

Which data should never be entered into an AI prompt without protection?

Names, addresses, dates of birth, bank account details, health data, personnel information, passwords, access credentials and confidential company documents should never be entered without protection. They should instead be protected through prompt anonymization, for example with SOWA Privacy.

What does prompt anonymization mean?

Prompt anonymization identifies personal or confidential information and replaces it with placeholders. For example: “Ms. Anna Mustermann applies for basic income support” becomes “Person A applies for basic income support.” The AI can therefore continue processing the factual context without receiving the original sensitive data.

What should you do if sensitive data has already been entered into an AI tool?

The incident should be documented and reported immediately to the responsible IT security or data protection team. It should also be reviewed which data was transmitted, which provider was involved, and whether deletion or other remedial action is possible.

Protect sensitive data. Use AI securely. Discover how SOWA Privacy works.

Further reading

Sources

  1. eGovernment (German): Hacker attack on Berlin Senate administration, August 18, 2026
  2. eGovernment (German): Update on the cyberattack on Berlin's state network, September 7, 2026
  3. eGovernment (German): Senate confirms multimillion-euro ransom demand after ransomware attack, September 1, 2026
  4. eGovernment (German): Hacker steals data from students at LMU Munich, September 21, 2026
  5. LMU Munich (German): Information about a data protection incident, September 19, 2026
  6. LMU Munich (German): Questions about the data protection incident, September 19, 2026