Cyber & AI intelligence
Wasteland.
Briefs indexed2464
Issues27
Published Mondays07:30 CT
█ Ransomware BERLIN-STATE-GOVER 2026-09-07

Berlin State Government: Rhysida Ransomware Data Leak

"The German capital's state administration has confirmed that the Rhysida ransomware group published a multi-terabyte archive of stolen government data on its dark web leak site after Berlin refused a 30 bitcoin ransom…"

The German capital's state administration has confirmed that the Rhysida ransomware group published a multi-terabyte archive of stolen government data on its dark web leak site after Berlin refused a 30 bitcoin ransom, equivalent to roughly €2m (approximately $2.32m, per TechTimes). Two Senate departments were breached: the department for mobility, transport, climate protection and the environment, and the department for urban development, construction and housing. Rhysida's own listing claims 5.79 TB across approximately 1.44 million files, though some coverage rounds this down (Silicon Republic and Infosecurity Magazine both frame it as roughly 5.7 TB and "nearly 1.5m files"). Governing Mayor Kai Wegner confirmed at an emergency Senate session that Berlin would not pay. The leak landed 16 days before the September 20 Berlin House of Representatives election.

What Happened

The incident surfaced publicly on August 18, when The Record reported that two Berlin state ministries had been isolated from the city government's IT network as a precaution. At that stage the Senate Chancellery would say only that "the security of the state network is the top priority" and declined to confirm attribution, access vector, or whether data had been taken. Both ministries stayed operational but staff lost email and internet access and fell back to telephone, SMS and fax. Housing benefit and education participation applications stalled at some district offices because they depend on systems run by the affected urban development ministry.

Rhysida claimed the attack on August 28 with a leak site entry titled simply "Berlin, Germany," attaching a countdown. Berlin acknowledged the extortion attempt the same day and publicly confirmed data theft on August 31 after emergency Senate deliberations at the Rotes Rathaus. "The state of Berlin is being blackmailed," Wegner said. "Berlin has fallen victim to a serious crime."

The ransom deadline was Friday, September 4. It passed without payment. In a statement that day the Senate Chancellery wrote: "The ultimatum issued by the hacker group Rhysida following its cyber-attack on Berlin's state network expired on Friday afternoon. According to experts, the entire dataset was published on the dark web." Berlin says there are currently "no indications" that the state network remains compromised.

Accounts of the intrusion timeline differ in an important way. Help Net Security reports the exfiltration is believed to have occurred between August 7 and 12, with the affected departments not disconnected until August 14. TechTimes goes further and frames the incident as a "seven-day gap" between initial detection and network isolation, arguing that the delay rather than the ransomware payload is what enabled the theft. That detection-to-isolation framing appears only in that lower-tier source and has not been confirmed by the Berlin Senate Chancellery, which has not published a detection date. Treat the exfiltration window as reasonably well supported and the seven-day detection gap as an unverified claim.

What Was Taken

Every category below comes from Rhysida's own leak site inventory and has not been independently verified by Berlin. The state has confirmed a large-scale data theft occurred and that personal data of employees, citizens and businesses may be affected, but forensic analysis of the dumped archive is still underway.

Rhysida's breakdown, as reported by BleepingComputer, Help Net Security and Security Affairs:

Silicon Republic reports the published files contain scanned identity documents, payslips, employment references and contract documents, and that Rhysida has been circulating filename lists on social media. That outlet also carries a claim by Hamburg-based investigative journalist and weapons expert Lars Winkelsdorf that the leaked material includes national defence planning, "ranging from the federal government's secret communication channels in the event of an apocalypse to defence-related companies and emergency plans." That is a single lower-tier attribution and should be read as an allegation pending official confirmation, not as an established fact about the archive's contents.

Rhysida itself asserts the dataset implicates violations of GDPR, German classified information rules, criminal law and KRITIS/BSIG obligations. That is the extortion pitch, not an independent legal finding.

Why It Matters

The interesting part of this incident is not the encryption event. It is that the entire coercive leverage sat in exfiltrated data, and when the victim declined to pay, the leverage converted into a permanent public disclosure of material that a state government cannot re-issue. Passports, ID cards, payslips and personnel files do not rotate like credentials. Water supply vulnerability assessments do not expire on a schedule. Berlin made the defensible decision, and it still ends up with a durable downstream problem in fraud, identity theft and physical infrastructure targeting.

The credential exposure compounds it. If Rhysida's inventory is accurate, plaintext passwords, password vaults and administrative accounts for named systems are now in open circulation, which means the leak is itself an attack surface for follow-on intrusion into systems that were never part of the original breach.

The election timing deserves attention without overreach. Rhysida hit a city-state weeks before a parliamentary vote, and the leak dropped 16 days out. Interior Senator Iris Spranger stated that the technical environment supporting the September 20 election is isolated from the compromised network: "As far as we know, no data has been compromised there. According to our security officers, the election environment is secure." No source establishes an election-interference motive, and Rhysida is a financially motivated operation with a long record of hitting healthcare, education, state government and critical infrastructure since mid-2023. TechTimes describes the group as "claiming ties to Russia," a characterisation not carried by the higher-tier reporting here.

There is also a governance lesson in the structure. The two breached ministries share IT infrastructure and, per RBB reporting cited by The Record, run their portion of the state network independently of ITDZ Berlin, the state-owned IT service provider. ITDZ was not affected. A federated architecture where individual departments operate their own slice of a government network means the security floor of the whole is set by its weakest operator.

The Attack Technique

No official technical detail has been released, and Berlin has cited investigative reasons for withholding it. The one substantive indication comes from German public broadcaster RBB, which reported, citing government sources, that attackers exploited a vulnerability in the IT systems of one of the affected ministries. The specific product, CVE and exploitation date have not been disclosed.

What is visible from the pattern is a standard Rhysida double-extortion sequence: initial access into a departmental environment, lateral movement and staging, bulk exfiltration measured in terabytes across an exfiltration window reported as August 7 to 12, then leak site listing with a countdown on August 28 and publication on September 4 when payment did not arrive. The volume, roughly 1.44 million files, points at mass collection from file shares and database exports rather than targeted document theft. The presence of SQL dumps and PST archives in the claimed inventory supports that reading.

Investigation is being run by the Berlin State Criminal Police Office (LKA), the public prosecutor's office and federal security agencies. Berlin has stood up a dedicated task force inside the Senate Chancellery led by Chief Digital Officer Florian Hauer, bringing together the LKA, the two affected Senate departments, data protection officials and other security authorities, with a remit that includes notifying state and federal agencies if security-relevant material is found in the dump. "The State of Berlin will not give in to blackmail," Hauer said. "The safety of the State of Berlin's staff and the people of Berlin is our top priority." IT forensic experts are examining the published data "around the clock," with affected individuals to be notified on a risk-based basis once analysis completes.

What Organizations Should Do

  1. Measure and shorten your detection-to-isolation interval. Whatever the true figure in Berlin's case, the reported exfiltration window of roughly five days is what determined the size of the loss. Rehearse network segment isolation as a drill with a named decision-maker and a pre-authorised trigger, so containment does not wait on a meeting.

  2. Hunt for plaintext credentials before an adversary inventories them for you. Scan file shares, config repositories, ticketing systems and shared drives for stored passwords, connection strings and exported vault contents. In this incident, credential files for payment systems and admin accounts sit in the same haul as the HR records.

  3. Treat critical infrastructure assessments as classified data with matching controls. Vulnerability analyses of water, power and transport systems should not live on general administrative file shares. Apply separate storage, separate access control and separate logging, and audit who currently holds copies.

  4. Instrument for bulk egress, not just malware. Terabyte-scale exfiltration over days is detectable through volumetric and behavioural signals: unusual outbound volume per host, novel destinations, off-hours archive creation, and abnormal read rates against document repositories. Encryption is the last step, not the first alarm.

  5. Close the federated-architecture gap. Where departments, subsidiaries or agencies run their own slice of a shared network, enforce a common minimum standard for patching, EDR coverage, MFA and logging, and put hard segmentation between those slices so a single weak operator cannot become an entry point to the whole.

  6. Prepare the no-pay path in advance. Berlin's refusal was the right call and it still produced a public dump. Have the notification workflow, the law enforcement contacts, the regulator timeline and the affected-individual guidance drafted before you need them, and decide in advance who triages a leaked archive for security-relevant content that other agencies or partners must be warned about.

Sources: Rhysida Publishes Berlin Government Data After €2m Extortion Demand... | Berlin confirms data theft after Rhysida ransomware attack claims | Berlin refuses to be blackmailed after network breach - Help Net Se... | Rhysida Ransomware Group Targets Berlin Government Ahead of Vote | Berlin cuts two state ministries off government network after secur... | Rhysida leaks 5.7TB of sensitive Berlin state data in major hack | Berlin launches crisis response after Rhysida dumps 5.79TB of alleg... | Berlin's Seven-Day Ransomware Isolation Gap Let Rhysida Steal Criti...