Berlin Refuses Ransom After Rhysida Breach Leaks Critical Infrastructure Data
The German capital's administrative network was compromised in August 2026, exposing water supply vulnerabilities and personal data of thousands.
The Berlin state government has fallen victim to a massive data breach by the Rhysida ransomware group, resulting in the leak of nearly six terabytes of sensitive information. The incident, which occurred in August 2026, has exposed critical infrastructure vulnerabilities and the personal details of thousands of citizens.
Rhysida exfiltrated approximately 5.79 TB of data, comprising 1.44 million files. The attackers demanded a ransom of 30 Bitcoin—roughly 2 million euros—to prevent the public release of the stolen material. Berlin officials refused to pay the extortion demand, prompting the group to list the data on its dark web leak site on August 28, 2026. The stolen cache includes the personal information of 12,076 individuals, 16,389 email addresses, 11,963 phone numbers, and 148 IBANs.
A Critical Security Gap
The breach took place between August 7 and August 12, 2026. However, a significant delay in response allowed the attackers to maintain their foothold; affected departments were not disconnected from the network until August 14. This window provided the attackers ample time to secure the massive volume of data before the systems were isolated.
Rhysida is a ransomware-as-a-service (RaaS) operation that has been active since May 2023. The group is known for targeting high-value sectors, including healthcare, education, and government entities, utilizing "double extortion" tactics where data is both encrypted and stolen to maximize pressure on the victim.
Risks to Public Safety
The implications of this breach extend beyond identity theft. The exfiltrated content includes passport and ID scans, as well as plaintext credentials for internal government systems. Most alarmingly, the leak contains vulnerability assessments of Berlin's water supply, creating a tangible risk to the city's physical security.
Governing Mayor Kai Wegner characterized the event as a serious crime, stating that the state of Berlin was being blackmailed. By refusing the ransom, the city has adhered to a strict policy against rewarding cyber-extortionists, though it now faces the long-term challenge of mitigating the exposure of its administrative secrets and critical infrastructure weaknesses.
Election Integrity and Next Steps
The timing of the attack was particularly sensitive, occurring shortly before the Berlin parliamentary election on September 20, 2026. While the administrative network was compromised, government officials maintain that systems specifically related to the election remained secure and were not affected by the breach.
Security analysts will now be watching for how the leaked plaintext credentials are used in subsequent attempts to penetrate other government layers. The focus remains on rotating all compromised credentials and patching the vulnerabilities identified in the leaked water supply assessments to prevent a physical security crisis.