Cyber & AI intelligence
Wasteland.
Briefs indexed2890
Issues29
Published Mondays07:30 CT
█ Ransomware BERLIN-RHYSIDA-RAN 2026-09-27

Berlin Senate: Rhysida Leaks 5.8TB After Mayor Refuses €2M Ransom

"Rhysida, a ransomware group, stole about 5.8TB of data from the administration of the German city-state of Berlin and demanded 30 bitcoin. That was roughly €2 million (BBC, citing Der Spiegel; DW; Euronews), or about…"

Rhysida, a ransomware group, stole about 5.8TB of data from the administration of the German city-state of Berlin and demanded 30 bitcoin. That was roughly €2 million (BBC, citing Der Spiegel; DW; Euronews), or about $2.3M to $2.4M in dollar terms (DW; BankInfoSecurity). Governing Mayor Kai Wegner publicly confirmed the extortion attempt and said "Berlin will not be blackmailed." After the deadline passed in early September, Rhysida published the data on its dark web leak site. The group claims 5.79TB across about 1.44 million files. Euronews counted 1,439,893 files, while DW describes the set as "approximately 1.4 million records." None of the sources here are PRIMARY-tier. The city's statements reach us through established press (BBC, Reuters, BankInfoSecurity).

What Happened

The attack came weeks before Berlin's state parliament election. Security Affairs gives the election date as Sept 20. BankInfoSecurity notes that Wegner had withdrawn his re-election bid in July.

What Was Taken

Rhysida's leak site listing, as summarized by Security Affairs, claims the data includes:

Security Affairs stresses that these are Rhysida's claims and have not been independently verified.

Reporting on the published files adds more:

These national-security characterizations come from commentators and have not been officially confirmed.

Why It Matters

This is not just a ransomware incident at a city office. If the OPLAN, CBRN and water-supply material is real, the leak hands adversaries a map of how Germany's civil authorities coordinate in a crisis. Plaintext credentials for payment and admin systems create a direct risk of follow-on attacks, even after systems are restored. The data on thousands of civil servants (IDs, home addresses, payroll) makes them easy targets for social engineering and coercion.

Berlin's refusal to pay follows a familiar Rhysida pattern. The group published British Museum data in 2023 after the museum refused to pay (BBC). Paying would not have guaranteed deletion. Defenders should plan on the basis that stolen data will be published, whatever the ransom decision.

The timing before the election, and Rhysida's history of targeting public bodies, also show that municipal networks holding federal-level material need protection to match the most sensitive data they hold.

The Attack Technique

The city has not officially disclosed how the attackers got in. DW, an OTHER-tier source, reports that an employee unknowingly opened a phishing email. Treat that as unconfirmed. It is consistent with Rhysida's known methods: phishing and credential abuse for initial access, followed by large-scale exfiltration and double extortion. The pattern visible here fits that model:

The sources do not say whether files were also encrypted, or how the ransomware was deployed.

What Organizations Should Do

  1. Harden email as an entry point. Enforce phishing-resistant MFA (FIDO2), sandbox attachments, and restrict macros and script execution on staff workstations.
  2. Remove plaintext credential stores. Search file shares for password lists and config files, move secrets into a vault, and rotate anything that was ever stored in cleartext.
  3. Segment by sensitivity. Keep classified, KRITIS and civil-defense planning material off general administrative networks, and apply strict access controls to it.
  4. Detect bulk exfiltration. Alert on unusual outbound volume, archive creation and mass access to SQL/PST files. A week-long gap between exfiltration and detection is too long.
  5. Assume publication and act early. After a breach, notify affected staff, reset credentials and brief partners before the leak deadline, not after.
  6. Practice the no-pay decision. Agree in advance, at leadership level, on the ransom policy, the communications plan and the continuity plan for public services such as benefit payments.

Sources: Berlin Mayor Declares Will Not Pay Ransom as Hackers Demand €2M | Berlin Responds After Data Leaked by Cyber Extortion Group | Rhysida Ransomware Group Targets Berlin Government Ahead of Vote | Berlin Rejects Rhysida Ransomware Blackmail | Berlin is being blackmailed by hackers, mayor says | Ransomware group says it stole Berlin data, offers it for ... | Cyberattack in Berlin: 1.4 million files on the dark web | Berlin cyberattack: hackers leak highly sensitive data ...