Cybersecurity

Berlin Confirms Data Theft After Being Listed as a Rhysida Attack Victim

The Berlin city administration confirmed that it is facing an attempted cyber extortion following a ransomware attack attributed to the Rhysida group, while authorities say the investigation is ongoing and the full extent of the stolen data has not yet been determined. Berlin’s mayor refused to pay the ransom, while authorities found no evidence that data related to the upcoming elections had been compromised.

2026-08-31
4 min read
8 views
فريق تحرير certi.news
Berlin Confirms Data Theft After Being Listed as a Rhysida Attack Victim

The Berlin city administration confirmed that the city is facing an attempted cyber extortion after being listed on a leak site operated by the Rhysida ransomware group, which claims to have stolen data from the city’s administrative network. The attack was discovered in mid-August, before the group publicly claimed responsibility for it on August 28, 2026.

Berlin Mayor Kai Wergner said that the city would not pay the attackers. In parallel, the state criminal police, the public prosecutor’s office, and federal security agencies began investigating the incident. The affected entities had been disconnected from the state network on August 14, after indicators of data exfiltration from the systems were detected.

How Much Data Is Allegedly Involved?

Rhysida claims to have exfiltrated 5.79 terabytes of data, distributed across approximately 1.44 million files. Authorities have not yet confirmed the accuracy of this figure or whether the list of data the group says it obtained is complete, as the criminal investigation and digital forensic examination are still ongoing.

According to material published by the attackers, the alleged data includes government, legal, financial, contractual, and human-resources records, along with infrastructure, health, and mapping information. The list also includes names, email addresses, and phone numbers, 148 IBANs, as well as credentials in plain text, database accounts, payment-system data, and password vaults.

The group also refers to personnel files, payroll records, email archives, copies of SQL databases, identity documents, and banking information, in addition to documents related to disciplinary proceedings and specific cases. Among the most sensitive claims are records belonging to Bundesrat committees and information about the handling of classified documents, security assessments of critical infrastructure linked to Berlin’s water supply, and more than 3,200 documents marked with nondisclosure agreements.

Pressure Through the General Data Protection Regulation

The attackers are using the possibility of violations of the General Data Protection Regulation (GDPR) as leverage and, according to the report, gave the Berlin government four days before publishing the stolen files. This means that the threat is not limited to disrupting systems but extends to the possible exposure of personal data and sensitive administrative documents, although the actual scale of the leak has not yet been confirmed.

What Has Been Confirmed and What Remains Unresolved?

Forensic investigators reported that data was also exfiltrated from the Senate Administration for Mobility, Transport, Climate Protection, and the Environment, likely between August 7 and 12. By contrast, Senator Iris Spranger said there was no evidence that election data had been compromised and that the technical environment supporting the upcoming elections for the Berlin House of Representatives was considered secure.

The initial method of accessing the network has not been disclosed. This point has practical significance because confirming data theft does not clarify whether the weakness resulted from stolen accounts, a vulnerability, or another method. Rhysida operators have previously used malicious Teams installers to compromise targets in a campaign disrupted by Microsoft, but the source does not establish that the same technique was used in the Berlin attack.

Why Does This Matter?

The incident is significant because it brings together three elements: the targeting of a major government administration, the potential compromise of personal data and sensitive infrastructure documents, and the use of data-protection obligations to maximize the impact of extortion. Nevertheless, details about the scale and contents of the theft should be treated as claims by the ransomware group until the authorities complete their verification.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news