Rhysida extorts Berlin after breach of two Senate administrations
The State of Berlin disclosed an extortion attempt after the Rhysida ransomware group stole data from the Senate administrations for urban development and for mobility, claiming 5.79 TB and demanding 30 bitcoin; Berlin refused to pay.
- Victim
- State of Berlin (Senate Administrations for Urban Development and for Mobility)
On 28 August 2026, the State of Berlin disclosed that it was being extorted after a cyberattack on two of its ministries: the Senate Administration for Urban Development, Building and Housing and the Senate Administration for Mobility, Transport, Climate Protection and Environment. The ransomware group Rhysida claimed responsibility the same day, saying it had stolen about 5.79 terabytes of data and putting it up for auction with a minimum bid of 30 bitcoin (just over 2 million euros at the time).
According to the state's account, the attackers had access to the two administrations' networks from 7 to 14 August. The state IT service provider ITDZ Berlin noticed unusual network activity, and on 14 August both administrations were cut off from the state network.
What was stolen
Rhysida's samples and the material it later published pointed to contracts, criminal case files, payment records, emails, salary lists, bank account numbers and analyses of water supply infrastructure. Screenshots from the leak showed passwords stored in plain text in a Word document. On 6 September, the Senate Chancellery said that another data package containing access credentials had been released.
Berlin's response
Governing Mayor Kai Wegner and Interior Senator Iris Spranger said the state would not be blackmailed, and the Senate decided not to pay any ransom. Law enforcement agencies opened an investigation.
Why it matters
Rhysida has a long record of attacking public bodies, hospitals and schools. The Berlin case is one of the most serious attacks on a German state government, both for the volume of data and for the sensitivity of material such as criminal case files and infrastructure analyses. The plain-text password file is a reminder that exfiltrated documents often expose secrets that let attackers, or anyone who downloads the leak, return later.
Timeline
Attackers begin exfiltrating data from the networks of two Berlin Senate administrations.
After the state IT service provider ITDZ Berlin detects unusual network activity, both administrations are disconnected from the state network.
Berlin officials publicly disclose the extortion attempt; Rhysida claims the attack and offers 5.79 TB of data at auction for a minimum bid of 30 bitcoin.
The Senate Chancellery reports that a further data package, including access credentials, has been published.
Sources
- borncity.comhttps://borncity.com/blog/2026/08/31/rhysida-cyberangreifer-erpressen-berlin-nach-hack-des-landesnetzes/
- borncity.comhttps://borncity.com/blog/2026/09/04/rhysida-hat-sensible-daten-aus-hack-in-berlin-offen-gelegt/
- b2b-cyber-security.dehttps://b2b-cyber-security.de/en/ransomware-gruppe-rhysida-erpresst-berlin-mit-behoerdendaten/
- de.wikipedia.orghttps://de.wikipedia.org/wiki/Rhysida_(Ransomware)