All incidents

Rhysida ransomware attack on Berlin government steals 5.7TB of data

malwareopenAug 29, 2026 — Aug 31, 2026
Rhysida ransomware attack on Berlin government steals 5.7TB of data

A Rhysida ransomware attack on the Berlin state government resulted in the theft of approximately 5.7 terabytes of data.

The compromise was identified on 14 August after unusual activity was detected on several internal servers.

City officials confirmed the breach in an official statement released the same day.

The incident has prompted an urgent review of the administration’s cyber defences according to the senate’s notice.

Initial access was achieved via a spear‑phishing email that carried a malicious attachment designed to execute a PowerShell loader.

Once the loader ran, it contacted a command‑and‑control server and deployed additional tools for credential harvesting.

Attackers then moved laterally using legitimate admin tools, eventually reaching domain controllers where they staged the ransomware payload.

Throughout the intrusion, data was staged and exfiltrated to an external server before encryption began as outlined in recent coverage.

The exfiltrated archive comprises personal information for over 12 000 individuals, ranging from names and addresses to national identification numbers.

In addition to citizen data, the attackers claim to have taken internal government documents and material classified as restricted.

This combination poses significant risk under the EU’s General Data Protection Regulation, which mandates timely breach notification.

Privacy advocates warn that the exposure could lead to identity theft and misuse of sensitive records as highlighted by SecurityAffairs.

Rhysida has been observed in roughly 280 incidents since it first appeared in 2023, primarily exploiting known vulnerabilities in exposed services.

In the Berlin case, the group scheduled the attack to coincide with the lead‑up to the state parliament election on 20 September.

Officials have stressed that no electoral rolls, candidate lists or voting‑related systems were accessed during the intrusion.

Nevertheless, the timing has heightened concerns about potential influence operations according to the same report.

Mayor Kai Wegner and Senator Iris Spranger have declared that Berlin will not pay the ransom demand of roughly 30 bitcoin.

They emphasized that negotiating with cyber extortionists encourages further attacks and undermines public trust.

Instead, the administration is working with the Federal Office for Information Security and local police to trace the attackers.

Investigators are also monitoring dark‑web markets for any signs that the stolen data is being offered for sale as noted by SecurityWeek.

Defenders should enforce multi‑factor authentication on every remote access portal, including VPNs and cloud consoles.

Network segmentation must isolate critical assets such as domain controllers and file servers from user workstations to limit lateral movement.

Continuous monitoring for anomalous outbound traffic, especially large transfers to unfamiliar endpoints, can help detect exfiltration early.

Finally, maintaining offline, immutable backups that are regularly tested and conducting frequent phishing simulations will reduce the chance of a successful ransomware deployment.

Intelligence briefing updated Aug 31, 2026

Rhysida
Root sourcewww.berlin.de
Timeline Coverage

Swipe to explore timeline