Berlin Government Allegedly Hit by Rhysida Ransomware: 5.79 TB of Data Claimed Stolen

Berlin Government Allegedly Hit by Rhysida Ransomware

TL;DR / Key Findings

  • Threat Actor: Rhysida ransomware group
  • Target Platform/Sector: Public sector and administrative infrastructure of the Berlin State Government
  • Activity Window: August 28, 2026
  • Alleged Victims & Records: Berlin State Administration (~1.44 million files scanned and classified)
  • Total Disclosed Data: 5.79 TB
  • Alleged Data Types Exposed: Maps/geographical data (124k+), legal complaints (77k+), financial records (55k+), official contracts (46k+), PII (16.389 emails, 11.963 phone numbers, 12.076 sensitive individual records, 148 IBANs), GebäudeAtlas, PAYONE ePayment database, password vaults, plaintext management credentials, 5.000+ personnel files (Personalakten), Convotis payroll data, LKA Staatsschutz disciplinary files, Federal Council (Bundesrat) committee protocols, and Berlin water supply vulnerability analysis.
  • Primary Source: ThreatMon Ransomware Monitoring and Rhysida ransomware leak site
  • Attack Vector: Unverified (potential unauthorized network access and data exfiltration)
  • Company Responses: Ransom demand rejected, data put up for auction
  • Status: Alleged / Unverified official confirmation of specific technical entry vectors

What Happened in the Alleged Berlin State Administration Breach

On August 28, 2026, Rhysida claimed to have targeted the Berlin State Administration in Germany. An analysis of the ransomware group’s leak site revealed that the attackers systematically scanned and categorized approximately 1.44 million files and claimed to have seized a massive 5.79 terabytes of data.

Following the administration’s refusal to meet ransom demands, the threat actors escalated their pressure tactics by putting the stolen archives up for auction. Security analysts and investigators emphasize that while the scale of the exfiltrated database is documented by the group’s leaks, the full scope and immediate operational impacts remain subject to ongoing evaluation.

Rhysida claims to have stolen 5.79 TB of data, consisting of approximately 1.44 million file

Who Was Involved and Targeted

The cyber attack directly targeted the administrative infrastructure of the Berlin state government and related public sector entities. The alleged breach encompasses sensitive departmental and regional divisions:

  • Berlin State Administration (General administrative infrastructure and regional records)
  • LKA Staatsschutz (State Security discipline files)
  • Federal Council (Bundesrat committee protocols)
  • Critical infrastructure administrative oversight (including Berlin water supply vulnerability analyses)

Data Exposed and Risk Categories

The 5.79 TB data dump reportedly contains a vast array of high-value administrative, financial, and personal records. The exposure profile elevates significant compliance and security risks:

  • Personally Identifiable Information (PII): 16,389 emails, 11,963 phone numbers, 12,076 sensitive individual records, and 148 IBAN numbers.
  • Critical Infrastructure & Operational Data: Security vulnerability analyses concerning Berlin’s water supply system and classified material management records (Geheimschutz).
  • Administrative & Legal Records: 124,000+ geographical and map files, 77,000+ legal complaints, 55,000+ financial records, and 46,000+ official contracts.
  • Credentials & Internal Databases: GebäudeAtlas, PAYONE ePayment database, personal password vaults, and plaintext credentials belonging to management tiers.
  • Internal Personnel & Law Enforcement Files: Over 5,000 personnel files (Personalakten), Convotis payroll data, and LKA Staatsschutz disciplinary records.

This diverse repository presents multi-vector exploitation risks ranging from identity fraud to direct threats against regional operational security.

Attack Vector Analysis

As of reporting, the precise initial access vector utilized by the Rhysida ransomware operators remains unverified by public forensic authorities. Common threat mechanisms typically associated with enterprise-scale ransomware deployment include compromised credentials via infostealer malware, phishing campaigns, or unpatched perimeter vulnerabilities.

Organizations must treat these specific entry vectors as unverified hypotheses until formal forensic investigations are fully concluded and published by incident response teams.

ThreatMon Assessment: What Is Confirmed, Claimed, and Still Unverified

A structured breakdown helps security leaders differentiate between verified data listings from threat actor portals and official confirmations:

Institution

Actor Claim

Evidence (Credential Log / Leak Portal)

Official Confirmation / Response

Berlin State Administration

5.79 TB exfiltrated data, 1.44M files classified and auctioned

Dark web leak site samples including PII, credentials, and internal protocols

Ransom rejected; ongoing assessment of the breach scope

Why This Incident Matters for Cybersecurity Leaders

The Rhysida attack on the Berlin State Administration transcends a standard ransomware encryption event by directly compromising critical infrastructure (KRITIS) oversight and government secrets. The exposure of plaintext management credentials, water supply vulnerability analysis, and high-tier financial data creates severe secondary risks:

  • Advanced Business Email Compromise (BEC) and Spear Phishing: Adversaries equipped with granular organizational charts, executive communications, and direct contact directories can orchestrate highly sophisticated social engineering campaigns tailored to bypass standard security awareness controls. 
  • Account Takeover (ATO) Vectors: The inadvertent exposure of plaintext credentials and compromised password vaults directly undermines the integrity of core administrative authentication domains, facilitating lateral movement. 
  • Severe Regulatory and Compliance Penalties: This security failure initiates multi-layered legal liabilities under the General Data Protection Regulation (GDPR Articles 32, 9, and 33), stringent German IT Security Act (BSIG/KRITIS) mandates, and relevant provisions of the German Criminal Code (StGB).

 

The timing adds another layer of sensitivity. Any confirmed exposure involving citizen data or critical infrastructure documentation would increase the potential impact of the incident beyond a conventional ransomware case. In a critical city like Berlin, the leak of both citizens’ personal data (GDPR violations) and critical infrastructure and water management data just weeks before the elections makes it abundantly clear that public institutions must urgently review their network security, internal network segmentation, and crisis management processes. As extensively reported by mainstream outlets such as RBB24, the decision not to pay the ransom and instead put the data up for auction on the eve of the election lays bare the pressure tactics threat actors employ against public institutions.

What Security Teams Should Learn

Incidents like the alleged Berlin State Administration breach highlight the importance of detecting external threat signals before they develop into broader security incidents. For public-sector organizations, this requires visibility beyond the internal network and traditional security controls.

ThreatMon helps security teams strengthen this visibility by continuously monitoring external attack surfaces, underground sources, and threat actor activity for signals that may indicate emerging exposure.

  • Monitor ransomware and dark web activity: Track ransomware leak sites, underground forums, and other threat actor channels for organization names, domains, sensitive documents, or data being advertised or published.
  • Detect exposed and compromised credentials: Monitor for employee and administrative credentials appearing in infostealer logs, credential dumps, and underground marketplaces. Exposed privileged credentials should be prioritized due to their potential role in account takeover and follow-on intrusion attempts.
  • Identify external attack surface exposure: Continuously assess internet-facing assets for vulnerabilities, exposed services, misconfigurations, and other weaknesses that could provide attackers with an entry point.
  • Correlate external threat signals: Individual findings such as a leaked credential, exposed service, or dark web mention may appear isolated. Correlating these signals with threat actor activity and organizational assets can help security teams identify higher-risk situations and prioritize investigation.
  • Prioritize intelligence for response: Rather than treating every external finding equally, security teams should evaluate findings based on asset criticality, severity, exposure, and threat context to determine which risks require immediate action.

For public sector organizations managing sensitive citizen data and critical infrastructure, gaining early visibility into these external signals is critical for minimizing risks, preventing service disruptions, and ensuring public safety.

How ThreatMon Provides Visibility

Public sector teams need to connect ransomware activity, leaked credentials, exposed assets, and threat actor activity to understand the risks facing their organizations. Looking at these signals separately can make it difficult to see the bigger picture and identify threats early.

This is where ThreatMon’s external threat intelligence capabilities come into play. ThreatMon combines dark web monitoring with data theft intelligence to help organizations track compromised credentials and leaked corporate assets before they are used in ransomware campaigns. It continuously monitors threat actors’ forums, auction sites, and underground channels, giving security teams visibility into relevant activity and helping them respond before threats escalate.

For public sector organizations, this intelligence can support the protection of critical infrastructure and public sector networks against evolving cyber threats. The ThreatMon National Cyber Defence module brings this intelligence together to help organizations identify relevant threats and take action to strengthen their security.

Conclusion

The alleged Rhysida attack on the Berlin State Administration shows why ransomware risk needs to be monitored before encryption begins. Public institutions may already be exposed through compromised credentials, exposed assets, infostealer logs, dark web activity, or signals linked to threat actors.

These signals do not always mean an attack is imminent, but they can provide important context about where an organization may be at risk. Monitoring them early gives security teams a better chance to identify weaknesses, investigate suspicious activity, and take action before a ransomware incident becomes a larger operational or public crisis.

For public sector organizations, ransomware prevention is not only about responding to an attack. It also means monitoring external signals that may reveal risk before it reaches the point of encryption, disruption, or data exposure.

The lesson from Berlin is not simply that public institutions are attractive ransomware targets. It is that the warning signs of ransomware risk often exist outside the perimeter before the incident becomes a public crisis.

Table of Contents
advanced divider

More posts

This image is about multiple Nginx vulnerabilities.
This image is about multiple Microsoft IIS vulnerabilities.
This image is about SMTP open mail relay vulnerability.
advanced divider

Share this article

Found it interesting? Don’t hesitate to share it to wow your friends or colleagues

advanced divider

Subscribe to our blog newsletter to follow the latest posts