Berlin State Government: Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026]

Berlin State Government: Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026]

Rhysida Ransomware Group Claims Massive Berlin Government Breach, Demands $2.3 Million

On August 28, 2026, the Rhysida ransomware group posted a claim on its dark web leak site alleging a major breach of Berlin’s state government IT network. The group asserts it exfiltrated 5.79 terabytes of data, encompassing roughly 1.44 million files, including sensitive judicial documents, emergency response plans, and critical infrastructure details. Among the reported haul are 80,000 administrative fine proceedings, 46,500 contracts, and nearly 6,000 files containing login credentials, along with personal data tied to 12,076 individuals.

Rhysida is demanding 30 bitcoin (≈$2.3 million) and has set a one-week deadline before threatening to publish the stolen data. Berlin’s Governing Mayor has publicly stated the city will not pay the ransom, aligning with EU and U.S. law enforcement guidance against ransom payments.

Key Details of the Incident

  • Who: Rhysida, a ransomware group known for targeting public-sector and healthcare organizations since 2023.
  • What: A claimed breach of Berlin’s government IT network, with data exfiltration and encryption.
  • When: The leak site post appeared on August 28, 2026, with a one-week countdown before potential data release.
  • Where: Berlin, Germany one of the largest ransomware claims against a European government in 2026.
  • Why: Rhysida’s playbook focuses on high-pressure extortion, leveraging public-sector vulnerabilities, including legacy infrastructure, fragmented IT governance, and political accountability pressures.

Impact and Regulatory Risks

If confirmed, the breach could trigger GDPR and NIS2 compliance obligations, given the mix of personal data and critical infrastructure documents. The reported exposure of login credentials poses an immediate operational risk, potentially enabling further attacks. Berlin’s government has acknowledged a "major cyber incident" but has not validated Rhysida’s claimed figures, a standard gap in early ransomware disclosures.

Broader Context

2026 has seen a surge in ransomware attacks on public institutions, with Rhysida favoring municipalities, healthcare systems, and government bodies due to their limited negotiating leverage and slower incident response. The Berlin case stands out for its alleged breadth of stolen data, including judicial and infrastructure-related files, which could set a precedent for future government cybersecurity policies.

Security researchers expect Rhysida to publish at least a portion of the data if the deadline passes without payment, though forensic reviews may later reveal discrepancies in the claimed volume. The incident is likely to prompt accelerated cybersecurity budget requests across German and EU public-sector organizations.

Source: https://tech-insider.org/rhysida-berlin-government-ransomware-breach-2026/

Berlin Senate Department for Health, Long-Term Care and Gender Equality cybersecurity rating report: https://www.rankiteo.com/company/senwgpg

"id": "SEN1788114426",
"linkid": "senwgpg",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'customers_affected': '12,076 individuals',
                        'industry': 'Public Sector',
                        'location': 'Berlin, Germany',
                        'name': 'Berlin State Government',
                        'type': 'Government'}],
 'data_breach': {'data_encryption': True,
                 'data_exfiltration': '5.79 terabytes',
                 'number_of_records_exposed': '1.44 million files',
                 'personally_identifiable_information': '12,076 individuals',
                 'sensitivity_of_data': 'High (personal data, login '
                                        'credentials, critical infrastructure '
                                        'details)',
                 'type_of_data_compromised': ['Judicial documents',
                                              'Emergency response plans',
                                              'Critical infrastructure details',
                                              'Administrative fine proceedings',
                                              'Contracts',
                                              'Login credentials',
                                              'Personal data']},
 'date_detected': '2026-08-28',
 'date_publicly_disclosed': '2026-08-28',
 'description': 'On August 28, 2026, the Rhysida ransomware group posted a '
                'claim on its dark web leak site alleging a major breach of '
                'Berlin’s state government IT network. The group asserts it '
                'exfiltrated 5.79 terabytes of data, encompassing roughly 1.44 '
                'million files, including sensitive judicial documents, '
                'emergency response plans, and critical infrastructure '
                'details. Among the reported haul are 80,000 administrative '
                'fine proceedings, 46,500 contracts, and nearly 6,000 files '
                'containing login credentials, along with personal data tied '
                'to 12,076 individuals. Rhysida is demanding 30 bitcoin (≈$2.3 '
                'million) and has set a one-week deadline before threatening '
                'to publish the stolen data. Berlin’s Governing Mayor has '
                'publicly stated the city will not pay the ransom, aligning '
                'with EU and U.S. law enforcement guidance against ransom '
                'payments.',
 'impact': {'brand_reputation_impact': 'Major cyber incident acknowledged by '
                                       'Berlin’s government',
            'data_compromised': '5.79 terabytes (1.44 million files)',
            'identity_theft_risk': 'Personal data tied to 12,076 individuals '
                                   'exposed',
            'legal_liabilities': 'Potential GDPR and NIS2 compliance '
                                 'violations',
            'operational_impact': 'Potential enabling of further attacks due '
                                  'to exposed login credentials',
            'systems_affected': 'Berlin’s state government IT network'},
 'investigation_status': 'Ongoing (claims not validated by Berlin government)',
 'motivation': 'Financial gain, extortion',
 'post_incident_analysis': {'root_causes': ['Legacy infrastructure',
                                            'Fragmented IT governance',
                                            'Political accountability '
                                            'pressures']},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransom_demanded': '30 bitcoin (≈$2.3 million)',
                'ransomware_strain': 'Rhysida'},
 'references': [{'date_accessed': '2026-08-28',
                 'source': 'Rhysida dark web leak site'}],
 'regulatory_compliance': {'regulations_violated': ['GDPR', 'NIS2']},
 'response': {'communication_strategy': 'Public statement by Berlin’s '
                                        'Governing Mayor refusing to pay '
                                        'ransom'},
 'threat_actor': 'Rhysida ransomware group',
 'title': 'Rhysida Ransomware Group Claims Massive Berlin Government Breach',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.