"The state of Berlin is being blackmailed," Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus, the blunt assessment that encapsulates a week of forensic disclosures, a leaked data dump claim, and a refusal by the city to meet extortion demands.
Governing Mayor Kai Wegner and Berlin’s decision not to pay
Berlin's state government confirmed it is the target of an extortion attempt following an August compromise of the city's state administrative network, and publicly stated it will not meet the extortionists' demands. Wegner voiced the city's position after the Senate convened to consider the incident; the quote appears in the machine-translated English version on Berlin's official city portal. The Senate Chancellery has issued two public releases but, as of August 29, those statements carried no specific guidance for people whose records may be among the data.
Forensics, timeline, and the data the attackers claim to hold
Forensic work disclosed further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated between August 7 and August 12, 2026. That department first reported an outflow on August 7 and was cut off from the state network on August 14; Berlin first disclosed the incident publicly on August 17, saying forensic work had established a compromise and that both affected departments had been isolated since the previous Friday. All Senate departments were reconnected on August 23, and forensic work and scanning of the state network continue.
The Senate Chancellery said scope and content are still being examined and that personal or other non-public data cannot be excluded from what was taken. Berlin has published no official figure for how much data left the network. The only itemized account in circulation is the attackers' own: a leak-site post indexed on August 28 that claims 5.79 terabytes of data and personal information on 12,076 individuals. The same entry claims roughly 1.44 million files scanned, and lists eleven file categories — the largest being 124,823 maps and geodata files — together accounting for about a quarter of the claimed total file count. No ransom figure appeared in the entry.
Operationally, public services were affected while departments were off the network: housing benefit applications and payments were unavailable during the outage. Interior Senator Iris Spranger said that, as things stand, no data left the areas relevant to the September 20 Abgeordnetenhaus election and that security officers regard the election environment as secure.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadRhysida, leak-site posting, and attribution
The Senate Chancellery said state criminal police, the public prosecutor, and federal security authorities are investigating the suspected perpetrators and identified no group behind the attack. Independent outlets, however, reported an attribution. Der Spiegel named Rhysida as the group that first reported the attribution on August 28, citing an entry on the group's darknet leak site and security sources involved in the response. The Hacker News confirmed via a leak-site monitoring service on August 29 that an entry titled "Berlin, Germany" was added to Rhysida's leak site on August 28.
The monitoring service listed 280 Rhysida victims as of August 29, including nine in Germany — for example, the Stuttgart city administration in May 2026 and the aid organization Welthungerhilfe in June 2025 — and prior international entries such as the Port of Seattle, indexed in September 2024.
CISA, the FBI, and MS-ISAC on Rhysida tradecraft and mitigation
A joint advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) set out Rhysida's known routes for initial access. The advisory — dated to November 2023, when the agencies first warned of Rhysida's double extortion attacks — documents three primary vectors: valid accounts on external-facing remote services where threat actors authenticate to internal VPN access points with compromised credentials (notably at organizations lacking multi-factor authentication enabled by default); exploitation of Zerologon (CVE-2020-1472), an elevation-of-privilege vulnerability in Microsoft's Netlogon Remote Protocol; and phishing.
The agencies reiterate that the FBI and CISA do not encourage paying ransom, noting that payment does not guarantee recovery and may embolden further targeting. Their recommended mitigations include prioritizing remediation of known exploited vulnerabilities, enabling multi-factor authentication across services, and segmenting networks to prevent ransomware spreading. The advisory also notes open-source reporting of similarities between Vice Society (tracked by Microsoft as Storm-0832) and actors deploying Rhysida, a connection Check Point reported in 2023.
Manchester Airports Group confirms a separate customer data theft
In a separate incident reported in the same period, Manchester Airports Group (MAG) said on August 27 that an unauthorized third party obtained customer data related to car park, lounge and Fast Track bookings and in-airport WiFi sign-ups at Manchester, London Stansted and East Midlands airports. MAG emphasized that "At no point has passenger safety or aviation security been compromised," and that airport operations and customer parking services continue to operate normally.
MAG said the data obtained includes email addresses, phone numbers, vehicle registrations and postcodes, and that neither MAG nor the accessed system holds customers' bank or payment details. The company described the affected system as distinct from MAG itself. As of August 29, access to the online Manage My Booking service was suspended as a precaution; changes to bookings due within the next 72 hours were being handled by customer services on 0208 163 8001, weekdays between 9:00 and 17:00. A figure of roughly 8.7 million affected customers has circulated, sourced to a company spokesperson speaking to the press, though MAG's own materials left the count unstated. MAG said it has contacted affected customers directly and pointed them to the U.K. National Cyber Security Center's data breach guidance, advising them to stay alert for suspicious emails, texts and calls.
Investigations in Berlin continue under the state criminal police, the public prosecutor and federal security authorities, while the Berlin state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed. The Hacker News found no statement on the incident from the Berlin Commissioner for Data Protection and Freedom of Information as of August 29. The central questions left on the table are concrete: will forensic work confirm the attackers' claim of 5.79 terabytes and the asserted file counts, and will the ongoing investigations establish how the network was first accessed and whether additional exfiltration remains undiscovered?
