Berlin Refuses Rhysida Ransom After 5.79 TB Stolen From State Network

Berlin's state government confirmed a compromise of its state administrative network and refused to pay the Rhysida ransomware group, which claims to have exfiltrated 5.79 TB of files between August 7 and 12.

Berlin Refuses Rhysida Ransom After 5.79 TB Stolen From State Network

The State of Berlin has confirmed that its state administrative network was breached in August 2026 and refused to meet a ransom demand from the Rhysida ransomware group, which added a "Berlin, Germany" entry to its darknet leak site on August 28 claiming 5.79 terabytes of stolen data and roughly 1.44 million files.

Timeline: exfiltration Aug 7–12, disclosure Aug 17

Forensic work has traced the data outflow to a compromise inside the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated between August 7 and August 12. The department reported the initial outflow on August 7 and was disconnected from the state network on August 14. Berlin first publicly disclosed the incident on August 17, and all Senate departments were reconnected to the state network on August 23 after isolation and hardening.

“The state of Berlin is being blackmailed”

“The state of Berlin is being blackmailed,” Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus. Interior Senator Iris Spranger added that current findings indicate no data left the systems relevant to the September 20 Abgeordnetenhaus election, and that security officers regard the election environment as secure. Berlin has not published a figure for how much data left its network; the only itemized total in circulation is Rhysida's own leak-site claim of 5.79 TB and personal data on 12,076 individuals.

State of Berlin coat of arms

Rhysida: 280 victims and a familiar playbook

A joint CISA / FBI / MS-ISAC advisory describes Rhysida as a double-extortion crew active since 2023 that typically breaks in through unpatched Zerologon (CVE-2020-1472), phishing, or VPN accounts without multi-factor authentication. Leak-site trackers list 280 Rhysida victims to date, including nine in Germany — among them the Stuttgart city administration in May 2026 and Welthungerhilfe in June 2025 — and the U.S. Port of Seattle, indexed in September 2024. The advisory reiterates that the FBI does not recommend paying ransoms.

Election data untouched; investigation continues

Berlin's state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed as forensic scans of the state network continue. Housing benefit applications and payments were unavailable while the affected Senate departments were off the network; those services have resumed. The Manchester Airports Group incident disclosed the following day underscores how quickly public-service data can be swept into extortion campaigns.

Reporting based on coverage from The Hacker News, Reuters, Berlin.de, CISA, and Rhysida darknet leak-site monitoring.

Category: Cyber Security

Tags: Medical Devices medical technology Cybersecurity ransomware Data Breach

Related Articles