grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

Berlin Extorted After Rhysida Ransomware Attack Hits State Network

Berlin ransomware attack
Published on
September 1, 2026

Berlin's state administration has confirmed that criminals stole data from its network and are now attempting to extort the German capital. The Rhysida group listed the city on its dark web leak site on 28 August. Investigators have traced the ransomware attack against Berlin to a window between 7 and 12 August. The city itself discovered the intrusion only in the middle of the month.

The attackers claim to hold 5.79 terabytes of material, roughly 1.44 million files taken from administrative systems. Governing Mayor Kai Wegner has stated that the city will not pay. No German municipality has faced a ransomware attack on this scale, and Berlin's role as both a federal state and the national capital raises the stakes. The State Criminal Police Office, the public prosecutor's office and federal security agencies are investigating.

What the Attackers Say They Took

The leak site entry that followed the ransomware attack on Berlin lists an inventory spanning nearly every function of a city government. Rhysida describes government, legal, financial, contractual, HR, infrastructure, health and mapping records, plus thousands of names, email addresses and phone numbers and 148 IBANs. The group also claims to hold plaintext credentials, database accounts, payment-system data, password vaults and login details belonging to senior officials.

Further items include personnel files, payroll information, email archives, SQL dumps, identity documents and more than 3,200 documents marked as nondisclosure agreements. The attackers also point to disciplinary case files, material they describe as classified Bundesrat committee papers, and security assessments covering the city's water supply. German reporting puts the haul at around 46,500 contracts and roughly 80,000 administrative-offence case files.

Nobody has independently verified any of it, and criminal groups inflate their claims to raise pressure. The Senate Chancellery says the full extent of the theft remains undetermined. Officials first indicated that only geodata had left the network, then conceded they can no longer rule out the loss of personal information.

How the Intrusion Unfolded

Forensic investigators place the data theft in early August. The affected bodies include the Senate Department for Mobility, Transport, Climate Protection and the Environment. Administrators cut two Senate departments off from the state network on 14 August. Staff there lost external email and internet access, and fell back on telephones and internal channels.

The disruption reached residents within days. Processing and payment of housing benefit applications stalled while the affected departments operated in isolation. Nobody has disclosed the method of entry behind the ransomware attack on Berlin's administation. The city has also not said how long the intruders held access before exfiltration began.

Berlin Refuses to Pay After the Ransomware Attack

Rhysida demanded 30 bitcoin, worth close to two million euros at current rates. The group set a one-week countdown before it said it would start publishing files. Wegner rejected the demand outright and confirmed that criminals are extorting the city.

The group has leaned on data protection law to sharpen the pressure. By pointing to potential GDPR violations, the attackers frame non-payment as a regulatory problem rather than an operational one. That tactic has become a fixture of extortion against European public bodies, because a supervisory authority's response sits outside the victim's control.

Refusal carries a predictable consequence. Published data stays published, and Berlin administranow owes notifications to everyone named in the files this ransomware attack put into criminal hands.

Who Is Rhysida?

Rhysida surfaced in mid-2023 out of the earlier Vice Society operation, running a ransomware-as-a-service model built on double extortion. Affiliates steal data first and encrypt second, then publish on a Tor leak site when payment does not arrive. The group has posted around 200 victims since it appeared, concentrating on healthcare, government, education and critical infrastructure.

Its record includes the British Library, the City of Columbus and the Port of Seattle. Microsoft disrupted a Rhysida-linked campaign in October 2025 by revoking more than 200 code-signing certificates. Those certificates signed fake Microsoft Teams installers that delivered the Oyster backdoor.

Rhysida also claimed an attack on Stuttgart in May 2026, demanding around 330,000 euros. Against that, the ransomware attack on Berlin marks a sharp escalation in both target and price.

Stolen Credentials Outlast the Deadline

The credential claims arising from the ransomware attack on Berlin deserve more attention than the file count. Password vaults, database accounts and plaintext logins for senior officials hold value long after any deadline expires. Screenshots the group published reportedly include a Word document full of passwords, which points to storage practices the administration will now need to audit.

Any organisation in this position faces months of work. Every credential touched by the compromised systems requires rotation, service accounts included. Teams also need to invalidate session tokens and review multi-factor enrolment on accounts that may already sit in the wrong hands.

Election Systems and Public Exposure

Senator Iris Spranger said officials found no evidence pointing to compromised election data. She described the technical environment supporting the Berlin House of Representatives election as secure. The vote falls on 20 September, three weeks after the extortion demand became public.

A clean election infrastructure still leaves the wider question open. Personal data on residents, contractors and public employees now sits in criminal hands, and nobody named in those files can withdraw it. Identity fraud, targeted extortion and convincing impersonation attempts follow from that kind of loss.

What Comes Next

The investigation will run for months, and specialists expect the cleanup to take at least as long. Berlin has not published a figure for how many people the ransomware attack affected, and it cannot do so until the file review finishes. Notifications under GDPR will follow, which means many of those involved will learn about their exposure well after the data has moved.

Anyone who has dealt with Berlin's administration recently should treat unexpected contact about official matters with suspicion. Callers armed with genuine case details are far more convincing than generic fraudsters.

For the city itself, the harder problem is structural. One intrusion into a shared state network reached water infrastructure assessments and payroll records alike. Berlin will carry the consequences of this ransomware attack long past the deadline its attackers set.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.