Berlin Confirms Data Theft Following Rhysida Ransomware Attack
Berlin authorities have confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware group published information allegedly stolen during an attack on the Berlin government network.
The ransomware attack was discovered in mid-August, while Rhysida publicly claimed responsibility on Friday, August 28. Berlin Mayor Kai Wegner said the city would not pay the ransom.
Germany’s State Criminal Police Office, the public prosecutor’s office, and federal security agencies are investigating the incident.
Rhysida ransomware has been active since mid-2023 and has targeted healthcare organizations, government agencies, educational institutions, and critical infrastructure around the world.
The ransomware group claims to have stolen 5.79 TB of data, including approximately 1.44 million files, from a Berlin administrative network. The claims have not yet been independently verified, and authorities said the full scope of the data breach remains under investigation.
According to Rhysida, the allegedly stolen data includes:
- Government, legal, financial, contract, human resources, infrastructure, health, and mapping records.
- Thousands of names, email addresses, phone numbers, and 148 IBANs.
- Plaintext credentials, database accounts, payment system data, password vaults, and credentials belonging to senior officials.
- Personnel records, payroll data, administrative criminal records, email archives, SQL database dumps, identity documents, and banking information.
- Documents related to disciplinary proceedings and other personnel or nomination cases.
- Potentially confidential or classified government materials, including records from Bundesrat committees and information about the handling of classified documents.
- Safety assessments involving Berlin’s critical water infrastructure.
- More than 3,200 documents identified as non-disclosure agreements.
The attackers are citing alleged GDPR violations to pressure Berlin’s government into paying a ransom. At the time of writing, Rhysida had given the city four days to make a payment before threatening to publish additional stolen files.

Source: BleepingComputer
Forensic investigators said the attackers also published data allegedly taken from Berlin’s Senate Department for Mobility, Transport, Climate Protection and the Environment. The data may have been stolen between August 7 and August 12.
The affected Senate departments were disconnected from Berlin’s state network on August 14 as authorities worked to contain the ransomware attack and investigate potential data exposure.
Officials said the investigation is ongoing and that they have not yet determined exactly how much information was accessed or stolen.
Senator Iris Spranger said there was no evidence that election data had been compromised. Authorities also determined that the technical systems supporting the upcoming Berlin lower-house election remained secure.
Officials have not disclosed how the Rhysida ransomware operators gained initial access to the network. In previous campaigns disrupted by Microsoft, ransomware groups used malicious Microsoft Teams installers to compromise targeted organizations.
Prevention scores can obscure what happens after an attacker gains initial access. When threat actors use valid credentials, the effectiveness of existing defenses can decline sharply.
The Blue Report 2026 evaluates defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




