Berlin confirms data theft after Rhysida ransomware attack claims

Berlin’s city administration has been hit by a devastating Rhysida ransomware attack, with cybercriminals threatening to extort the city unless they pay up. The attack, which was discovered in mid-August, has left the city reeling as it attempts to assess the extent of the damage.

According to the attackers, they have stolen an estimated 5.79 terabytes of data from Berlin’s administrative network, including sensitive information such as government records, financial documents, and personnel files. The list of compromised data is staggering, with thousands of names, email addresses, phone numbers, and even bank account details (IBANs) among the stolen files.

The attackers claim to have obtained plaintext credentials, database accounts, payment-system data, password vaults, and sensitive information belonging to senior officials. They also appear to have accessed critical-infrastructure security assessments related to Berlin’s water supply and nondisclosure agreements. Perhaps most concerning is that they have allegedly exfiltrated classified or sensitive government material, including records from the Bundesrat committee.

The Rhysida ransomware gang has been active since mid-2023, targeting various organizations across multiple sectors, including healthcare, state governments, education institutions, and critical infrastructure. This attack marks a significant escalation in their tactics, with the attackers now using GDPR violations as leverage to pressure the city into paying them off.

Berlin’s Mayor, Kai Wergner, has stated that the city will not pay the ransom, instead opting to work with law enforcement agencies to investigate the incident. The State Criminal Police Office, the public prosecutor’s office, and federal security agencies are all involved in the investigation, which is ongoing.

One of the most disturbing aspects of this attack is the ease with which the attackers appear to have gained access to sensitive data. Forensic investigators have revealed that they likely exfiltrated data from the Senate Department for Mobility, Transport, Climate Protection and the Environment between August 7 and 12. The affected Senate departments were subsequently disconnected from the state network on August 14.

While the exact method of entry used by Rhysida in this attack has not been disclosed, it is worth noting that they have previously breached their targets using malicious Teams installers. This highlights the importance of robust security measures and regular updates to protect against such threats.

In light of this incident, it’s essential for organizations to prioritize data protection and ensure that they are prepared for potential breaches. Regular backups, robust access controls, and employee education can all help mitigate the impact of a ransomware attack. Furthermore, staying informed about emerging threats and vulnerabilities is crucial in today’s increasingly complex cybersecurity landscape.

As the investigation into this incident continues, one thing is clear: organizations must be vigilant in protecting their data from falling into the wrong hands. By taking proactive steps to secure their networks and systems, they can minimize the risk of a devastating ransomware attack like Rhysida’s.


Source: Bleeping Computer — 2026-08-31