Berlin’s state government spent a week connected to hackers before anyone pulled the plug. According to the announcement from Berlin authorities and reporting from outlets including Tech Times and The420.in, the ransomware group Rhysida sat inside the city-state’s IT backbone, the Berliner Landesnetz, from at least August 7, 2026, and wasn’t cut off until August 14. In that window, reports say, the group pulled roughly 5.79 terabytes of data, close to 1.44 million files, out of Berlin’s Senate departments, including material tied to vulnerability analyses of the city’s water supply.
The story broke publicly around August 17, and Rhysida posted a Berlin entry to its leak site on August 28. What’s drawing attention now, on September 1, isn’t just the breach itself. It’s the seven-day gap between the first internal alarm and the actual disconnection, a gap security teams call dwell time, and one that in this case ran directly through systems tied to water infrastructure and emergency services.
What Happened Inside Berlin’s Landesnetz
The Berliner Landesnetz is the fiber backbone linking roughly 600 government, police, fire, and hospital sites across the city-state, according to reporting on the incident. It’s the kind of network that isn’t supposed to make headlines, precisely because it’s plumbing: the wiring that keeps administrative systems, emergency dispatch, and utility oversight talking to each other. That’s also what makes an intrusion into it different from a typical ransomware hit on a single agency’s file server.
Two Senate departments have been named in connection with the incident: the Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and the Environment. The Berlin Senate Chancellery has served as the central point for official communications about the incident. Reports indicate the Mobility, Transport, Climate Protection and Environment department was the first to flag an internal data outflow, on August 7. Both departments stayed connected to the shared state network for another week before being cut off on August 14.
That detail is the crux of the story. A single compromised department is a containment problem. A compromised department that stays wired into a 600-site shared backbone for seven additional days is a blast-radius problem, and it’s why security researchers who study ransomware dwell time keep circling back to isolation speed as the metric that actually predicts damage, more than the initial entry vector does.
The Seven-Day Gap, Hour by Hour
Piecing together the public timeline from the announcement and subsequent coverage, the sequence runs like this: exfiltration activity is believed to have started around August 7 and continued through roughly August 12. The Mobility, Transport, Climate Protection and Environment department reported an internal data outflow on August 7, the same day activity is now believed to have begun. Despite that early internal signal, the affected departments remained tied into the Landesnetz for another full week.
Disconnection finally came on August 14. Broader public and political acknowledgment of the attack followed around August 17, roughly ten days after the first internal report. The affected departments were reconnected to the state network around August 23, suggesting remediation and forensic work ran for about nine days post-isolation. Then, on August 28, Rhysida listed “Berlin, Germany” on its leak site, the point at which the incident moved from an internal government matter to a public extortion claim.
Line up those dates and the seven-day window between first detection and isolation stands out as the single most consequential decision point in the entire incident. It’s the difference between a contained department-level breach and a shared-network exposure event touching hundreds of connected sites.
| Date (2026) | Event |
| Aug 7 | Exfiltration activity believed to begin; Mobility/Transport/Climate/Environment department reports internal data outflow |
| Aug 7–12 | Data exfiltration window from Berlin state government systems |
| Aug 14 | Affected Senate departments disconnected from the Berliner Landesnetz |
| Aug 17 | Broader public and political disclosure of the cyberattack |
| Aug 23 | Departments reconnected to the state network |
| Aug 28 | Rhysida posts “Berlin, Germany” entry on its leak site |
Who Is Rhysida
Rhysida has built a reputation as a ransomware-as-a-service operation that goes after institutions with high public-interest value: hospitals, school systems, libraries, and now, apparently, a European capital’s administrative backbone. The group runs a leak site that functions as both extortion leverage and marketing, publishing victim names in stages to pressure payment before a full data dump. shattered.io previously covered Rhysida’s Berlin claim and its reported 30 BTC ransom demand tied to the same incident; this piece focuses on the operational failure that let the group sit inside the network for a week rather than the ransom mechanics themselves.
What separates this incident from a routine Rhysida listing is the target category. Government-adjacent critical infrastructure data, particularly anything describing water system vulnerabilities, carries a different risk profile than stolen HR records or financial documents. Vulnerability assessments are effectively a map of weak points, and in the hands of a group willing to publish stolen files to force payment, that map becomes leverage of a different order.
Why Dwell Time Is the Real Story
Every major ransomware post-mortem eventually lands on the same question: how long were they in before someone acted? In Berlin’s case, the public record points to a minimum of seven days between the first internal report and network isolation, measured from August 7 to August 14. Whether that gap reflects incident-response bureaucracy, uncertainty about scope, or the practical difficulty of isolating a department from a backbone shared with 600 other sites isn’t spelled out in the public disclosures, and speculating on internal decision-making inside Berlin’s IT administration would go beyond what’s confirmed.
What is clear is that the gap gave Rhysida a full week of additional access after the intrusion was already flagged internally. For a network connecting police, fire, and hospital sites, that’s a week in which lateral movement, additional exfiltration, or deeper persistence could plausibly have occurred, even if the public timeline doesn’t confirm the group actually did any of that beyond the reported August 7–12 exfiltration window.
Government Ransomware Incidents: How Berlin Compares
Government and municipal ransomware incidents have become frequent enough that security teams now track them almost like a weather pattern. Berlin’s case stands out less for its size and more for its target category: a shared metro-scale backbone rather than a single city hall or school district network. The table below places the publicly confirmed Berlin figures alongside the general shape of comparable government-sector incidents reported over the past two years, without attributing specific unconfirmed numbers to other named incidents.
| Factor | Berlin / Rhysida (2026) | Typical municipal ransomware pattern |
| Network scope | Shared backbone linking ~600 government, police, fire, hospital sites | Usually a single agency or department network |
| Data claimed | ~5.79 TB, ~1.44 million files | Varies widely; often undisclosed by victims |
| Dwell time (report to isolation) | ~7 days (Aug 7–14) | Industry surveys generally show multi-day to multi-week gaps |
| Data sensitivity | Includes water-supply vulnerability analyses | Typically administrative, HR, or financial records |
| Extortion model | Leak-site listing plus reported BTC ransom demand | Leak-site listing standard across RaaS groups |
The Water Supply Angle
Of everything in the Berlin disclosure, the detail most likely to keep security officials up at night is the reported inclusion of vulnerability analyses tied to the city’s water supply. Water and wastewater systems have been a recurring target of nation-state-adjacent and criminal cyber activity globally over the past several years, precisely because they sit at the intersection of physical safety and often under-resourced IT security budgets.
A stolen vulnerability assessment doesn’t cause a service disruption on its own. But it changes the threat model for whoever holds it. Rather than needing to independently discover weak points in water infrastructure, an attacker (or a buyer of leaked data on a criminal forum) would have a pre-built list. That’s the scenario German and EU cybersecurity bodies, including Germany’s Federal Office for Information Security (BSI) and the EU’s cybersecurity agency (ENISA), have flagged in broader guidance on critical infrastructure protection, even though neither has issued a Berlin-specific statement referenced in current reporting.
Historical Context: Government Networks as Ransomware Targets
Municipal and state governments have been a recurring ransomware target for years, largely because they combine two things attackers value: sensitive data with real leverage, and IT budgets that historically lag behind the private sector. What’s changed over the past two to three years is the shift from single-agency hits, a city hall email server, a school district’s student records system, toward attacks on shared infrastructure that spans dozens or hundreds of connected sites.
Berlin’s case fits that trajectory. A backbone network designed decades ago to link administrative offices, emergency dispatch, and utility oversight under one roof made sense when the primary goal was interoperability. It becomes a liability once ransomware groups start treating “one network, many doors” as a feature rather than a bug. Security researchers tracking public-sector incidents have flagged this architecture pattern, shared regional networks connecting emergency services to general government IT, as a recurring risk factor across European municipalities, independent of any single incident.
Market and Political Fallout
Ransomware attacks on private companies move stock prices and insurance premiums. Attacks on government backbones move budgets and political careers instead. Berlin’s Senate Chancellery now faces the kind of scrutiny that typically follows public-sector breaches: questions about why a network connecting emergency services to general administrative traffic wasn’t segmented more aggressively, and why a full week passed between the first internal alarm and disconnection.
For Germany’s broader public-sector IT security posture, the incident lands at an awkward moment. Municipal and state governments across the EU have been under pressure to modernize legacy network architecture, much of which, like the Landesnetz model of one shared backbone serving hundreds of sites, was designed for administrative convenience rather than breach containment. Security vendors and consultancies serving the public sector are likely to point to Berlin as a reference case for why network segmentation and faster isolation protocols need to move up the budget priority list, following patterns already well documented by outlets like BleepingComputer and The Record in their ongoing ransomware coverage.
Rhysida’s Extortion Playbook
The leak-site posting on August 28 followed a pattern Rhysida has used against other public-sector and healthcare targets: claim the victim, publish a partial description of stolen data, and use the threat of a full dump to pressure payment. In Berlin’s case, the group’s own listing describes the scale of stolen material, the 5.79 TB and roughly 1.44 million files, as leverage. Whether Berlin negotiates, pays, or refuses hasn’t been confirmed in public reporting as of this writing, and any claim about payment status should be treated as unconfirmed until officials say otherwise.
What is notable is the gap between the August 14 isolation and the August 28 leak-site posting, a two-week window in which negotiations, if any took place, would have happened. That pattern, quiet isolation followed by a public leak-site listing weeks later, is common across Rhysida’s other claimed victims and is generally read by incident responders as a sign that private negotiation either failed or never started.
Lessons for Enterprise and Public-Sector Security Teams
The Berlin incident offers a fairly clean case study for any organization running a shared network architecture across multiple business units or departments, government or otherwise. A few takeaways stand out from the public timeline alone:
- Detection isn’t containment. Berlin’s Mobility, Transport, Climate Protection and Environment department flagged an outflow on August 7, the same day activity is believed to have started, yet isolation didn’t happen until a week later.
- Shared backbones multiply blast radius. A single compromised department connected to 600 sites turns a local incident into a network-wide exposure question.
- Sensitive technical data (vulnerability assessments, infrastructure maps) deserves stricter access segmentation than general administrative records, precisely because it’s more damaging in an attacker’s hands.
- Public disclosure timelines matter. Berlin’s gap between internal detection (Aug 7) and public acknowledgment (Aug 17) ran ten days, which is a separate metric from the isolation delay and worth tracking independently.
Incident Response Checklist Government IT Teams Are Revisiting
Following incidents like this one, agencies typically revisit a standard set of controls. None of the following is confirmed as something Berlin specifically lacked, but they’re the checklist items security teams reference after any dwell-time failure of this kind, per general guidance from bodies like the US FBI Internet Crime Complaint Center and NIST’s cybersecurity resources.
# Example network segmentation check (illustrative, not Berlin-specific)
# Verify no single compromised VLAN can reach critical-infra subnets
iptables -L FORWARD -v -n | grep -i "critical-infra"
# Confirm isolation runbook exists and has a defined SLA
cat /etc/incident-response/isolation-runbook.yaml | grep "max_time_to_isolate"
What Happens Next
A few things to watch in the coming weeks. First, whether Berlin’s Senate Chancellery releases a formal post-incident report detailing root cause and whether the seven-day gap gets an official explanation. Second, whether Rhysida follows through on a full data dump or whether the August 28 leak-site posting was itself the extent of the public disclosure. Third, whether other German states or EU member governments use Berlin as the trigger for accelerated network segmentation mandates, something EU cybersecurity policy has been trending toward independent of any single incident.
There’s also the open question of what happens to the stolen water-supply vulnerability data specifically. If it surfaces on criminal forums or gets referenced in follow-on attacks against German utilities, that would mark a meaningful escalation from “government data breach” to “critical infrastructure targeting enabled by a data breach,” a distinction regulators and utility operators are watching closely.
Predictions
- Berlin’s Senate Chancellery will likely face formal legislative questions in the coming weeks about the seven-day isolation delay, given the shared-backbone exposure involved.
- Expect German state and federal cybersecurity bodies to cite this incident in upcoming guidance on network segmentation for shared government backbones.
- Rhysida will likely continue targeting public-sector and healthcare networks through year-end, following its established pattern of leak-site listings against high-visibility institutions.
- Other EU municipalities running similarly centralized network architectures may face increased scrutiny or voluntary segmentation audits as a direct result of Berlin’s public timeline.
- Details about ransom negotiation status and whether Berlin paid are likely to leak or be confirmed within the next reporting cycle, given the pattern of other Rhysida-linked government incidents.
Frequently Asked Questions
What is the Berliner Landesnetz?
It’s the fiber network backbone connecting roughly 600 government, police, fire, and hospital sites across Berlin, according to reporting on the incident.
How much data did Rhysida claim to steal from Berlin?
Reports citing Rhysida’s own leak-site listing put the figure at roughly 5.79 terabytes, or about 1.44 million files.
Which Berlin government departments were affected?
The Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and the Environment have both been named in connection with the incident, with the Berlin Senate Chancellery serving as the central communications point.
How long was Rhysida inside Berlin’s network before isolation?
Reports indicate exfiltration activity was underway from at least August 7, 2026, with the affected departments disconnected from the shared network on August 14, roughly a seven-day gap.
Did the attack affect Berlin’s water supply directly?
No service disruption to the water supply itself has been reported. The concern centers on stolen vulnerability analyses related to the water system, which could theoretically inform future targeting rather than an active disruption.
Who is Rhysida?
Rhysida is a ransomware group known for targeting public-sector, healthcare, and education institutions, and for using a leak site to pressure victims into paying by threatening staged data releases.
Has Berlin confirmed paying a ransom?
No payment has been confirmed in public reporting as of this writing. Any claim about ransom payment status should be treated as unconfirmed.
When was the attack publicly disclosed?
Broader public and political acknowledgment of the incident emerged around August 17, 2026, roughly ten days after the department’s internal report of a data outflow.
Related Coverage
- Check Point VPN Zero-Day: CVSS 9.3, Qilin Ransomware [2026]
- Clop Ransomware Exploits PTC Windchill: 43 Victims [2026]
- Rhysida Demands 30 BTC After Claiming Berlin Hack [2026]
- Foxconn Hit by Nitrogen Ransomware: 8TB Stolen, Apple and Nvidia Data Exposed [2026]
- Oracle WebLogic Zero-Day: CVSS 10.0, 140K Attacks in 12 Days [2026]




