On 31 August 2026, Berlin’s city administration confirmed a data theft carried out by the Rhysida ransomware group. The affected body is the Senate Department for Mobility, Transport, Climate Protection and the Environment. The attackers claim 5.79 terabytes across roughly 1.44 million files were exfiltrated – figures the state has explicitly not yet fully verified.
What Rhysida claims it stole
Rhysida listed Berlin on its leak site on 28 August and put the stolen files up for pressure – reports cite a demand of around 30 bitcoin. Investigators say the exfiltration took place between 7 and 12 August. On its leak site the group claims to have taken personnel files, plaintext passwords, IBANs and payment data, as well as security assessments relating to Berlin’s water supply. These volume and category figures come from Rhysida’s own description and should be treated as preliminary.
Seven days until isolation
One time window is critical: the first data outflow was noticed on 7 August, but the affected department was not disconnected from the central state network until 14 August. During those roughly seven days the attackers could keep siphoning data. Governing Mayor Kai Wegner called it blackmail and ruled out any payment – in line with guidance from Germany’s BSI. Interior Senator Iris Spranger stressed that no data relevant to the 20 September state parliament election had left secure areas and that the election environment is considered safe. State police, prosecutors and federal agencies are investigating.
What organisations should do now
- Isolate compromised network segments immediately – not days later.
- Eliminate plaintext passwords and shared admin accounts; enforce MFA.
- Harden segmentation between line-of-business systems and the central network.
- Keep offline backups and test the incident-response plan regularly.
Sources: BleepingComputer, The Hacker News. As of 1 September 2026, an ongoing incident – some details are preliminary.



















