Rhysida claims to have exfiltrated 5.79 TB of data — roughly 1.44 million files — from Berlin’s administrative network, and is urging the city to pay within days or the files will be published, according to the ransomware group's post and Berlin officials.
Rhysida's claim: scale and types of data reportedly taken
The threat actor listed Berlin on its data leak site on August 28 after the incident was discovered in mid‑August. Rhysida says the haul totals 5.79 TB, about 1.44 million files, and includes a long catalogue of records: government, legal, financial, contractual, HR, infrastructure, health and mapping records; thousands of names, email addresses and phone numbers; 148 IBANs; plaintext credentials, database accounts, payment‑system data and password vaults; personnel files and payroll information; administrative‑offense records, email archives and SQL database dumps; identity documents and banking information; and documents related to disciplinary proceedings and other named cases.
The group additionally alleges it has taken material it describes as classified or sensitive government material, specifically citing Bundesrat committee records and information about handling classified documents. Rhysida also claims to hold critical‑infrastructure security assessments concerning Berlin’s water supply and more than 3,200 documents marked as nondisclosure agreements.
Berlin's response: no payment, investigations, and network containment
Mayor Kai Wergner said the city will not pay the attacker. The State Criminal Police Office, the public prosecutor's office and federal security agencies are investigating the incident, according to the city administration's confirmation.
For containment, affected Senate departments were disconnected from the state network on August 14. Forensic investigators report that data was also exfiltrated from the Senate Department for Mobility, Transport, Climate Protection and the Environment, likely between August 7 and 12. The announcement stressed that the investigation is ongoing and that the full extent of the data theft has yet to be determined.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleElection systems: Senator Iris Spranger's assurance
Berlin officials have placed special emphasis on election systems. Senator Iris Spranger said investigators found no evidence that election data was compromised and that the technical environment supporting the upcoming Berlin House of Representatives election is considered secure.
Tactics and precedent: what is known about Rhysida and defensive gaps
Rhysida has been active since mid‑2023 and has targeted healthcare organizations, state governments, education institutes and critical infrastructure, according to the reporting. The method of entry in the Berlin incident has not been disclosed. In a previous campaign that Microsoft disrupted, the operators used malicious Teams installers to breach targets.
The reporting also cites a defensive finding from the Blue Report 2026: prevention scores can mask post‑access behavior, and once attackers operate with valid credentials, prevention drops sharply. The Blue Report quantifies its technique‑by‑technique measurement across 338 million simulations run in customer production environments, a dataset the report uses to illustrate how defenses behave after initial access.
What this means for technologists, policymakers, and Berlin residents
- Technologists and security teams: ongoing forensic work and the disconnection of affected departments show containment steps already taken; teams will be watching investigators' findings about the method of entry and whether credentials or vaults were compromised, since Rhysida claims plaintext credentials and password vaults among the stolen items.
- Policymakers and prosecutors: the State Criminal Police Office, the public prosecutor's office and federal security agencies are involved; these authorities will lead decisions about legal responses, public notifications tied to GDPR leverage cited by the attacker, and any cross‑jurisdictional coordination.
- Berlin residents and institutions named in the haul: officials have said election systems appear secure, but the list of allegedly exposed personal and banking data — including thousands of contact details and 148 IBANs — means individuals and organizations named in the claims will need to await the formal investigation to determine actual exposure and required notifications.
The attackers set a payment timeline to increase pressure — the disclosure said the city had four days (at the time of writing) before files would be published — but Berlin has publicly ruled out paying. With the investigation ongoing, the key facts left to be established are how the intruders entered the network, the degree to which claimed files exist and are readable, and which specific individuals or systems are demonstrably affected. Authorities have already disconnected impacted departments and opened criminal and federal inquiries; the next concrete developments will come from those forensic findings and prosecutorial actions.




