← Back to Daily Briefing (#Ransomware)

Rhysida Ransomware Breach of Berlin State Government Administrative Network

Published September 14, 2026

The Rhysida ransomware group has compromised the administrative network of the Berlin city-state government, exfiltrating approximately 5.79 TB of sensitive data. The attack utilizes a double-extortion model, where the threat actor threatens to leak or sell the stolen data to maximize leverage. This breach was strategically timed to coincide with local elections, increasing the political pressure on municipal authorities. Despite the significant scale of data loss and the specific targeting of government infrastructure, Berlin officials have officially maintained a non-payment policy regarding ransom demands, prioritizing long-term security posture over immediate mitigation via extortion.

  • Incident/Breach Overview

    • Target Infrastructure: The core administrative network of the Berlin city-state government.
    • Attack Period: The breach was identified and escalated in August, timed specifically to coincide with local election cycles.
    • Incident Status: Confirmed large-scale data exfiltration and administrative network compromise.
  • Attack Mechanics and Exfiltration

    • Primary Methodology: Deployment of the Rhysida ransomware strain to facilitate network access and data theft.
    • Exfiltration Scale: Approximately 5.79 TB of sensitive municipal data was successfully extracted from the environment.
    • Extortion Strategy: Implementation of a "double extortion" tactic, combining encryption-based disruption with the threat of public data leaks.
  • Threat Group Profile and Impact

    • Attribution: The Rhysida ransomware group, a known threat actor specializing in high-pressure extortion campaigns.
    • Data Impact: Significant risk of exposure for large volumes of government administrative records and sensitive citizen-related data.
    • Strategic Motivation: The timing of the attack suggests a goal of maximizing political instability and psychological pressure on government leadership.
  • Government Response and Defensive Posture

    • Ransom Negotiation: Berlin officials have officially refused all ransom demands presented by the threat actor.
    • Financial Policy: Strict adherence to a non-payment policy to avoid incentivizing future attacks on public infrastructure.
    • Risk Outlook: Ongoing threat of the 5.79 TB dataset being auctioned or released on dark web repositories.

Related posts

  1. News4Hackers — Berlin Cyber Attack: Hackers Threaten to Sell 5.79TB of Stolen Data
  2. Malware News — Rhysida in Germany - From an Early Ransomware Payload to the 2026 Stuttgart and Berlin Threat…
  3. thehackernews.com — Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
  4. Security Affairs — Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
  5. Cypro
  6. Reddit
  7. The420
  8. Cybernews
  9. Facebook
  10. Igorslab
  11. cybelangel.com — Rhysida Ransomware Explained: TTPs, IOCs and How to Defend in 2026
  12. Threatmon
  13. Safestate
  14. Aa
  15. Berlin
  16. Ebuildersecurity
  17. SecurityWeek — Berlin Won’t Pay Extortion Group Claiming Data Theft

LINK COPIED TO CLIPBOARD