SYS::ONLINE
Wasteland.
Briefs2310
Issues25
SinceFeb 2026
LIVE
▣ Breach BERLIN-GOVERNMENT- 2026-08-28

Berlin State Government: Rhysida Ransomware Data Extortion

"Berlin's city-state government has confirmed it is the target of a criminal extortion attempt after attackers breached the Landesnetz, the state IT network, and exfiltrated data from two Senate departments. Governing…"

Berlin's city-state government has confirmed it is the target of a criminal extortion attempt after attackers breached the Landesnetz, the state IT network, and exfiltrated data from two Senate departments. Governing Mayor Kai Wegner said on Friday that the demand arrived Thursday evening and that Berlin will not pay. The Rhysida ransomware group has claimed the attack on its darknet leak site, listing 5.79 terabytes of data (rounded to "nearly 6 TB" by several German outlets) and opening an auction with a starting price of 30 bitcoin, valued at roughly €2 million by Der Spiegel and $77,622 by Reuters, behind a seven-day countdown timer.

What Happened

The Senate Chancellery confirmed an "Inkriminierung des Landesnetzes Berlin" (a compromise of the Berlin state network) discovered through forensic investigation. Two departments are confirmed affected: the Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and the Environment. Both were isolated from the state network on Friday as a precaution.

The timeline as given by city-state officials and reported by the BBC: an initial data leak occurred between 7 and 12 August; on 14 August the two department networks were shut down; forensic work later revealed further data leaks inside the transport and environment department. The Record noted that at the point of the Senate Chancellery's Monday statement, officials had not said who was behind the breach, how access was gained, or whether data was stolen, citing investigative reasons. That disclosure posture has since shifted as the extortion demand and Rhysida's leak-site post surfaced.

The Landeskriminalamt, the Berlin public prosecutor's office and the federal BSI are all engaged, and a prosecutor's spokesperson told dpa that a criminal investigation has been opened. An emergency crisis staff led by the state's information security commissioner was stood up and, per Tagesspiegel, was still meeting daily as of the following Monday. Economics Senator Franziska Giffey told RBB a crisis team had been established and that the city will need to invest more in cybersecurity.

Operationally, the isolation was disruptive. Both departments lost internet access and external email; home working was impossible. The Senate Chancellery maintained the administrations were still functional, with internal email and telephone available. A transport department employee told Tagesspiegel the opposite: "Wir sind praktisch arbeitsunfähig" (we are practically unable to work). Housing benefit payments to more than 50,000 eligible Berlin households were put at risk, and district offices could not process housing benefit or education-and-participation applications that depend on urban development systems. Both departments were reconnected on the Sunday following, after a risk assessment coordinated with the BSI.

What Was Taken

Accounts differ sharply between what Rhysida claims and what Berlin officials have verified, and this gap is the central uncertainty in the incident.

Rhysida's leak-site listing, as reported by UA.NEWS, Pollar and Der Spiegel via the BBC, claims:

The group has published document excerpts as proof of access. None of this has been independently verified; UA.NEWS explicitly notes the full extent of the leak is unconfirmed.

Berlin's own account is narrower and, at least initially, far less alarming. Digitalisation State Secretary Florian Hauer (CDU) told the Abgeordnetenhaus interior committee on Monday that as things stood, the attackers were after "geo-data that is not sensitive and was already open via the open data portal," adding: "They wouldn't have needed to hack it at all." Hauer said he could not yet say exactly what data had been exfiltrated and that forensic work continues. That sits against RBB reporting, cited by WELT, that "in part very sensitive data" was stolen, and against the mayor's office statement that "it cannot be ruled out that personal or other non-public data may also be affected."

Weight the official line over the criminal listing, but note that the official line is provisional. Extortion groups routinely inflate volume and sensitivity to force payment; equally, "we think it was only open data" is a common early read that hardens badly once forensics complete. Treat the 5.79 TB figure as a claim, not a finding.

Why It Matters

Berlin is a city-state, meaning its Senate departments carry both municipal and state-level functions. A breach here touches housing, transport, environmental regulation and administrative enforcement for a population of 3.8 million, with direct citizen impact evidenced by 50,000+ households whose housing benefit payments were disrupted.

The timing is politically loaded. Berlin's Abgeordnetenhaus election is set for 20 September, and the extortion demand landed weeks before it. Officials stated that disruptions to the postal-vote application portal are unrelated to the attack and are being handled by the responsible state office, but the proximity alone raises the pressure on decision-makers and creates fertile ground for influence operations regardless of the attackers' actual intent.

Berlin's refusal to pay is the correct policy call and should be read as such by other public-sector bodies. Rhysida has a documented pattern of following through: the group hit the British Library in autumn 2023, demanded 20 bitcoin (then worth over €760,000), and leaked roughly 500,000 visitor and subscriber files after the institution declined. The BBC also links the group to an attack on the British Museum. A public "we will not be blackmailed" posture must therefore be paired with an assumption that everything claimed will eventually publish.

The credential exposure claim is the most operationally serious element. If Rhysida genuinely holds ~6,000 files of login credentials plus emergency plans and critical infrastructure documentation, the incident becomes a durable access and targeting problem for the entire Berlin administration, not a one-time data loss. Hauer's own testimony is instructive here: "Wir sind überrascht, wie groß es ist" (we are surprised how large it is), said of the state IT estate being scanned. An organisation that does not know the size of its own network cannot bound the blast radius of an intrusion.

The Attack Technique

Initial access has not been officially attributed to a specific vector. RBB, cited by The Record, reported that attackers allegedly exploited a vulnerability in the IT systems of one of the two affected departments. Hauer characterised it publicly as "ein sehr professioneller Angriff" (a very professional attack).

Two structural details matter for defenders. First, ITDZ Berlin, the state-owned central IT service provider, was not affected, per RBB. The two compromised departments share some IT infrastructure and run their portion of the state network independently of ITDZ. That is a textbook federated-IT failure mode: a shared network perimeter with unevenly governed segments, where the least-hardened segment defines the exposure of the whole.

Second, the response reveals the detection gap. The initial exfiltration window is dated 7 to 12 August; network isolation followed on 14 August; further leaks in the transport and environment department were only found through subsequent forensics. Dwell time before containment ran at least several days, and the full scope was still not established weeks later.

Hauer stated there is no further evidence of ongoing infiltration and no indication other systems were compromised, but qualified it directly: "that is a snapshot. There are still grounds for suspicion." He also noted Berlin fends off roughly 1.2 million attacks a month and declined to claim the state is perfectly positioned on IT security. No IOCs, malware hashes, or CVE identifiers have been published by Berlin authorities or the BSI at time of writing.

What Organizations Should Do

  1. Hunt for Rhysida TTPs now if you run public-sector or federated networks. Rhysida typically gains entry via exposed remote services, valid accounts and phishing, then uses living-off-the-land tooling and RDP for lateral movement before exfiltration and encryption. CISA and partners have published a Rhysida advisory (AA23-319A) with detection guidance; map your telemetry against it rather than waiting for Berlin-specific IOCs that may never come.

  2. Inventory and segment your federated IT estate. The Berlin case turns on departments running their own slice of the state network outside the central provider's governance. Identify every network segment your central IT team does not fully administer, and enforce hard segmentation between them and shared services. A department you do not patch is a department that can breach you.

  3. Treat exposed credentials as compromised on day one. With ~6,000 credential files claimed, the correct assumption is full rotation, not selective rotation. Force password resets across affected domains, revoke and reissue service account secrets and API keys, invalidate active sessions, and enforce phishing-resistant MFA on every remote access path and privileged account.

  4. Patch and inventory internet-facing systems on a department-by-department basis. The reported vector is a vulnerability in one department's systems. Run authenticated external attack surface discovery per organisational unit, not just for the enterprise as a whole, and prioritise known-exploited vulnerabilities in remote access, VPN, and file transfer appliances.

  5. Plan for the isolation, not just the intrusion. Berlin's containment cost 50,000 households their housing benefit processing. Pre-identify which citizen-facing or revenue-critical services depend on each network segment, define manual fallback procedures, and rehearse operating without email and internet for multiple days. Fax and telephone as an unplanned fallback is a failure of continuity planning, not a success of it.

  6. Decide your ransom policy before the countdown timer starts. Berlin refused within roughly 24 hours because the decision framework was already in place at Senate level. Document who authorises a payment decision, what legal and sanctions review applies, and how you will communicate a refusal. Then build the corollary: an assumption-of-publication plan covering regulatory notification under GDPR, data subject notification, and pre-drafted communications for when the leak lands.

  7. Verify claimed scope independently, and communicate provisionally. Do not let either the attacker's inflated inventory or your own optimistic first read set your public position. Berlin's "it was only open geo-data" assessment may hold, but it was offered while forensics were explicitly incomplete. State what you know, state what you do not, and update.

Sources: Hackers are demanding €2 million from Berlin for the stolen data U... | Berlin cuts two state ministries off government network after secur... | Berlin is being blackmailed by hackers, mayor says | Ransomware group says it stole Berlin data, offers it for ... | Hackerangriff: Was der Cyberangriff auf die Berliner Verwaltung bed... | „Ein sehr professioneller Angriff“: Hacker wollten Berliner Geo-Dat... | Berlin: Hackerangriff auf Senatsverwaltung – laut RBB „zum Teil seh... | Cyberattack cuts two Berlin ministries from state network, putting...