Berlin’s City Administration Hit by Rhysida Ransomware Attack, Data Theft Confirmed
The city of Berlin has confirmed that it is being extorted by cybercriminals following a ransomware attack attributed to the Rhysida gang. The attackers claimed publicly on August 28 that they had stolen over 5.79 terabytes of data from the city’s administrative network, including sensitive information about government officials, citizens, and critical infrastructure.
The Rhysida ransomware gang has been active since mid-2023, targeting a range of organizations, including healthcare providers, state governments, educational institutions, and critical infrastructure. The attackers use a combination of social engineering and exploitation of vulnerabilities to gain access to their victims’ networks. In this case, it appears that the attackers exfiltrated data from Berlin’s administrative network using valid credentials, which they likely obtained through phishing or other means.
The stolen data includes a wide range of sensitive information, including government records, financial documents, personnel files, and banking details. The attackers have given the city four days to pay the ransom before publishing the stolen files online, claiming that the data is being held as leverage due to alleged GDPR violations. However, Senator Iris Spranger has stated that officials found no evidence of election data being compromised and that the technical environment supporting the upcoming Berlin House of Representatives election is considered secure.
The investigation into the attack is ongoing, with federal security agencies, the State Criminal Police Office, and the public prosecutor’s office all involved. The city administration has confirmed that it will not pay the ransom, citing concerns about setting a precedent for future attacks. This decision reflects a growing trend among cities and organizations to resist paying ransoms in response to cyberattacks.
The attack highlights the ongoing threat posed by ransomware gangs like Rhysida, which are increasingly targeting public sector organizations and critical infrastructure. As these groups become more brazen, it’s essential that individuals and organizations take proactive measures to protect themselves from these types of attacks. This includes implementing robust cybersecurity measures, such as multi-factor authentication, regular software updates, and employee education on phishing and social engineering tactics.
In the meantime, citizens of Berlin can take steps to protect their own data by being cautious when sharing personal information online and monitoring their financial accounts for suspicious activity. As the investigation continues, it’s likely that more details will emerge about the Rhysida gang’s methods and motivations. For now, one thing is clear: cities and organizations must prioritize cybersecurity and work together to combat these types of threats.
Source: Bleeping Computer — 2026-08-31