securityaffairs.com 7 Sept 2026, 07:19 UTC

Berlin Refuses Rhysida Ransom as Hackers Claim Sensitive Data Leak

Berlin Refuses Rhysida Ransom as Hackers Claim Sensitive Data Leak
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Rhysida

BERLIN’S state government says it refused a ransom after a Rhysida ransomware incident targeted the city’s administrative network. On 28 August, the group claimed responsibility and asserted it had exfiltrated about 5.79 terabytes across roughly 1.44 million files, with personal information on 12,076 individuals included. The authorities confirmed an extortion attempt and have launched a crisis response, while stressing that no payment was made.

The leaked dataset, as described by Rhysida, reportedly contains a broad mix of material. It includes personnel files and administrative records, payroll and leadership information, credentials including plaintext passwords for systems such as GebäudAtlas and the ePayment PAYONE database, and Z_ADMIN accounts.

The dump is said to span government and legal material, NDAs, supervisory documents, and confidential material handling records, with claims of state secrets and critical infrastructure data related to Berlin’s water supply. The attackers also allege the release encompasses documents touching on chemical, biological, radiological and nuclear threats, and other sensitive infrastructure details.

Investigators are assessing the scope, with the claimed data total around 1.4 million files and descriptions suggesting potential GDPR and KRITIS/BSIG implications; however, these are unverified claims at this stage.

Officials have begun a crisis-management process to review and verify the leaked material and to inform affected citizens and businesses. The breach underscores the need for robust network segmentation and comprehensive incident response to limit exposure once ransom negotiations fail.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline