Berlin Confirms Data Theft in Rhysida Ransomware Attack: 5.79TB Claimed, Partial Exfiltration Verified
On August 31, 2026, Berlin’s state government officially confirmed that data was stolen during a Rhysida ransomware attack, marking a shift from initial uncertainty to forensic validation. Investigators pinpointed a five-day exfiltration window between August 7 and 12 within the Senate Department for Mobility, Transport, Climate Protection and Environment, one of two departments disconnected from Berlin’s central network (Landesnetz) on August 14 as a containment measure.
The confirmation closes a critical gap exploited by ransomware groups the delay between extortion claims and independent verification. Rhysida, which listed Berlin on its leak site on August 28, claimed 5.79TB of data across 1.44 million files, including personal records of 12,076 individuals, along with supplier contracts, confidential documents, passwords, and bank account details. However, Berlin’s government has only validated exfiltration from one department during the specified window, declining to verify the attackers’ full claims. This cautious approach reflects standard incident-response protocol to avoid inflating breach notifications and legal exposure.
The attack timeline reveals a week-long undetected data leak before discovery, underscoring the risks of prolonged dwell time in large, interconnected networks. Rhysida, a ransomware-as-a-service group active since mid-2023, demanded 30 Bitcoin via a dark-web auction, threatening to sell or publish the data if unpaid. Berlin’s leadership, including Mayor Kai Wegner and Interior Senator Iris Spranger, rejected the demand outright, aligning with Germany’s federal cybersecurity guidance and broader European trends against ransom payments.
Rhysida’s targeting of public institutions including hospitals, universities, and governments highlights its focus on sectors with sensitive data but limited cybersecurity budgets. Berlin’s breach fits a 2026 pattern of ransomware attacks on public-sector networks, such as Manchester Airports Group and the ATF, where attacker claims initially outpace official confirmations. The incident also exposes vulnerabilities in centralized government networks, where a single breach can cascade across departments.
Forensic reviews continue, with potential expansions of confirmed exfiltration to other departments. The fallout may include GDPR-related inquiries, network segmentation reforms, and heightened scrutiny of Germany’s Länder-level cybersecurity policies. While Rhysida’s auction countdown is likely to lapse without payment, the confirmed theft sets in motion long-term regulatory and operational consequences for Berlin’s administration.
Source: https://tech-insider.org/berlin-confirms-data-theft-rhysida-ransomware-2026/
Berlin’s Senate Department for Mobility, Transport, Climate Protection and Environment TPRM report: https://www.rankiteo.com/company/senmvku
"id": "sen1788222465",
"linkid": "senmvku",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '12,076 individuals',
'industry': 'Public Sector / Government',
'location': 'Berlin, Germany',
'name': 'Senate Department for Mobility, Transport, '
'Climate Protection and Environment',
'type': 'Government Department'}],
'data_breach': {'data_exfiltration': 'Yes (5-day window between August 7 and '
'12, 2026)',
'number_of_records_exposed': '1.44 million files (5.79TB '
'claimed, partial verification)',
'personally_identifiable_information': 'Yes (12,076 '
'individuals)',
'sensitivity_of_data': 'High (personally identifiable '
'information, financial data)',
'type_of_data_compromised': 'Personal records, supplier '
'contracts, confidential '
'documents, passwords, bank '
'account details'},
'date_detected': '2026-08-14',
'date_publicly_disclosed': '2026-08-31',
'description': 'Berlin’s state government confirmed data theft during a '
'Rhysida ransomware attack, validating partial exfiltration '
'from the Senate Department for Mobility, Transport, Climate '
'Protection and Environment. The attack involved a five-day '
'exfiltration window, with Rhysida claiming 5.79TB of data, '
'though Berlin verified only a subset of the stolen data.',
'impact': {'brand_reputation_impact': 'Potential damage to public trust in '
'government cybersecurity',
'data_compromised': 'Personal records, supplier contracts, '
'confidential documents, passwords, bank '
'account details',
'identity_theft_risk': 'High (personal records of 12,076 '
'individuals exposed)',
'legal_liabilities': 'Potential GDPR-related inquiries and fines',
'operational_impact': 'Network disconnection, forensic '
'investigation, potential regulatory '
'inquiries',
'payment_information_risk': 'High (bank account details exposed)',
'systems_affected': 'Senate Department for Mobility, Transport, '
'Climate Protection and Environment '
'(disconnected from Berlin’s central network - '
'Landesnetz)'},
'initial_access_broker': {'data_sold_on_dark_web': 'Threatened (dark-web '
'auction)'},
'investigation_status': 'Ongoing (forensic reviews, potential expansion of '
'confirmed exfiltration)',
'lessons_learned': 'Risks of prolonged dwell time in large networks, need for '
'network segmentation, challenges in verifying attacker '
'claims during ransomware incidents',
'motivation': 'Financial gain (ransom demand), data extortion',
'post_incident_analysis': {'corrective_actions': 'Network segmentation, '
'regulatory compliance '
'reviews, cybersecurity '
'policy reforms',
'root_causes': 'Prolonged undetected dwell time, '
'centralized government network '
'vulnerabilities'},
'ransomware': {'data_exfiltration': 'Yes',
'ransom_demanded': '30 Bitcoin',
'ransom_paid': 'No',
'ransomware_strain': 'Rhysida'},
'recommendations': 'Network segmentation reforms, enhanced monitoring, GDPR '
'compliance reviews, cybersecurity budget increases for '
'public institutions',
'references': [{'source': 'Berlin State Government'}],
'regulatory_compliance': {'regulations_violated': 'Potential GDPR violations'},
'response': {'communication_strategy': 'Official confirmation of data theft, '
'rejection of ransom demand',
'containment_measures': 'Disconnected affected departments from '
'Berlin’s central network (Landesnetz)',
'incident_response_plan_activated': 'Yes',
'network_segmentation': 'Potential future reforms',
'remediation_measures': 'Forensic investigation, validation of '
'exfiltrated data'},
'threat_actor': 'Rhysida',
'title': 'Berlin Data Theft in Rhysida Ransomware Attack',
'type': 'Ransomware'}