Berlin's state government has confirmed it's the target of an extortion attempt after hackers compromised the city's administrative network in August and won't pay the attackers' demands, according to The Hacker News. The ransomware group Rhysida claimed responsibility for the breach on August 28, posting an entry on its darknet leak site that advertises stolen data from "Berlin, Germany." The incident has involved multiple data thefts from government systems, with forensic investigators still working to determine the full scope of what was taken and whether sensitive information about residents is at risk.
Forensic analysis uncovered additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and August 12, 2026, with the first breach detected on August 7—seven days before the department was disconnected from the network on August 14. The attackers' leak-site post, indexed on August 28, claims 5.79 terabytes of data and personal details on 12,076 individuals were exfiltrated. The posting lists approximately 1.44 million files across eleven categories, with the largest category containing 124,823 maps and geodata files, though these categories together represent only about a quarter of the total claimed file count. Berlin officials have published no figure for the volume of data stolen, and no ransom amount has appeared in the leak-site entry. As of August 29, the Senate had issued no guidance for people whose records may be among the stolen data.
"The state of Berlin is being blackmailed," Governing Mayor Kai Wegner said after a special Senate session, according to Berlin's official city portal. The Senate Chancellery confirmed that state criminal police, prosecutors, and federal security authorities are investigating the suspected perpetrators but identified no group behind the attack in its official releases. Der Spiegel named Rhysida as the responsible party on August 28, citing the group's darknet leak site and security sources involved in the response. At an August 19 press conference, Wegner characterized the incident as serious but emphasized that, based on current knowledge, no sensitive data had left the state network—a statement made before the later forensic discoveries.
U.S. federal agencies warned in November 2023 that Rhysida typically gains initial access through valid accounts on external-facing remote services, where attackers authenticate to internal VPN access points using compromised credentials, particularly at organizations that haven't enabled multi-factor authentication by default. The group also exploits Zerologon, an elevation of privileges vulnerability Microsoft patched in August 2020, and uses phishing as a successful route into victim networks. The joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center documents the group's double extortion tactics and notes that paying ransom doesn't guarantee recovery and may embolden adversaries to target more organizations. A monitoring service listed 280 Rhysida victims as of August 29, including nine in Germany, among them Stuttgart's city administration in May 2026 and the aid organization Welthungerhilfe in June 2025, as well as the Port of Seattle in September 2024.
Federal agencies recommend prioritizing remediation of known exploited vulnerabilities, enabling multi-factor authentication across services, and segmenting networks to prevent ransomware from spreading, according to the advisory. All Senate departments were reconnected on August 23 after being isolated, and forensic work and scanning of the state network continue. Interior Senator Iris Spranger said that as things stand, no data left the areas relevant to the conduct of the September 20 election, and her security officers regard the election environment as secure. Housing benefit applications and payments were unavailable while the two departments were offline. Berlin's decision to refuse the extortion demand aligns with guidance from security agencies that payment fuels further attacks, though the city now faces the risk of public data leaks and potential identity theft affecting thousands of residents. The episode illustrates how legacy infrastructure gaps—particularly missing multi-factor authentication on remote access—create persistent exposure that sophisticated groups continue to exploit efficiently.

