Berlin’s state government has confirmed what its IT staff spent most of August trying to contain quietly: a ransomware crew broke into the city-state’s administrative network, pulled out a large volume of files, and is now threatening to sell it. The group behind the intrusion, Rhysida, posted a leak-site entry titled simply “Berlin, Germany” on August 28, 2026, claiming 5.79 terabytes of stolen data and demanding 30 bitcoin, worth roughly $2.3 million at current prices, before a countdown clock reaches zero.
The timing matters. Berlin’s government is a full state administration inside Germany’s federal system, not a city council with a handful of servers. If even a fraction of what Rhysida claims to hold turns out to be accurate, this becomes one of the largest ransomware disclosures against a European public-sector body in 2026, and a case study in how fast one compromised department can spread across an entire government network.
What Happened to Berlin’s Government Network
According to reporting from heise online, Berlin’s state government disclosed a compromise of parts of its administrative IT network in August 2026, with the state formally confirming the ransomware and extortion attempt on August 28. Forensic investigators traced data exfiltration to the Senate Department for Mobility, Transport, Climate Protection and Environment, with the theft window running from August 7 to August 12, 2026, per the reporting cited by heise and crypto.news.
Berlin reconnected all Senate departments to the network on August 23, suggesting the government pulled systems offline department by department while investigators worked out how far the intruders had moved. That is a fairly standard containment step in a ransomware incident: cut network segments, rebuild trust from clean backups, and only reconnect once each department passes inspection. It also means the affected departments spent roughly two weeks partially or fully isolated from the shared network, which is a real operational cost even before any ransom is discussed.
Rhysida’s leak-site post appeared six days after Berlin finished reconnecting departments, which lines up with a pattern seen across dozens of Rhysida cases since 2023: quietly negotiate for a few weeks, then go public with a countdown once talks stall. Crypto.news reports that Berlin’s Governing Mayor has said the city will not pay, a stance consistent with EU and US law enforcement guidance discouraging ransom payments to sanctioned or repeat-offending groups.
The 5.79 Terabyte Claim, Broken Down
Rhysida’s own numbers, which Berlin has not independently verified, describe a haul of about 1.44 million files. That is the group’s claim, not a confirmed inventory, and the distinction matters because ransomware crews routinely inflate file counts to pressure victims into paying quickly. Still, the categories Rhysida lists are specific enough to take seriously as an investigative lead, even before anyone outside the group has opened the archive.
The claimed contents include 46,500 contracts, records tied to nearly 80,000 administrative fine and offence proceedings, information on critical infrastructure facilities, sensitive judicial documents, emergency response plans, and roughly 6,000 files containing login credentials. Rhysida also claims personal data on 12,076 individuals, 16,389 email addresses, 11,963 phone numbers, and 148 IBANs, plus 124,823 map and geodata files. None of these figures have been confirmed by Berlin’s government, and readers should treat them as the attacker’s own description of the stolen set rather than an audited fact.
What makes this list unusual compared to a typical corporate breach is the mix of categories. A retailer breach usually means payment cards and loyalty accounts. A government breach that includes emergency plans, critical infrastructure data, and administrative fine proceedings touches public safety and legal process at the same time, which is why German officials are treating verification as urgent even while publicly declining to pay.
| Claimed data category | Rhysida’s stated volume | Verification status |
|---|---|---|
| Contracts | 46,500 files | Attacker claim, unverified |
| Administrative fine/offence proceedings | ~80,000 files | Attacker claim, unverified |
| Login credential files | ~6,000 files | Attacker claim, unverified |
| Individuals with personal data exposed | 12,076 people | Attacker claim, unverified |
| Email addresses | 16,389 | Attacker claim, unverified |
| Phone numbers | 11,963 | Attacker claim, unverified |
| IBANs | 148 | Attacker claim, unverified |
| Map and geodata files | 124,823 files | Attacker claim, unverified |
| Total claimed volume | 5.79 TB / ~1.44 million files | Attacker claim, unverified |
Who Is Rhysida, and Why Governments Keep Ending Up on Its List
Rhysida has been active since 2023 and has built a track record of targeting public-sector and healthcare organizations, two sectors that tend to run older infrastructure, carry large amounts of sensitive records, and face real political pressure to keep services running rather than shut everything down to investigate properly. Past Rhysida targets reported in the press include the British Library and Chile’s army, both incidents that involved large data dumps auctioned on the group’s leak site after ransom talks failed.
The group’s business model is now familiar: breach a network, quietly exfiltrate as much as possible, encrypt what remains to disrupt operations, then negotiate. If the victim refuses or negotiations stall, the stolen data goes up for public auction on a dark-web leak site with a countdown timer, which is exactly the mechanic Berlin is now facing. Rhysida’s site reportedly shows just under seven days from the August 28 posting before the Berlin data listing moves to auction.
Public-sector victims are attractive to groups like Rhysida for a specific reason: governments cannot simply close up shop while they rebuild. Courts still need to run, benefits still need to be paid, and permits still need to be issued, which creates pressure to either pay quickly or absorb a messy, prolonged recovery in full public view. That dynamic has made European and North American municipal and state governments a recurring target across 2024, 2025 and now 2026.
Why the Timing Around a State Election Matters
Part of the coverage around this incident, including reporting referenced by heise and crypto.news, ties the breach’s public disclosure to the run-up to a Berlin state-parliament election cycle. The exact election date tied to this reporting is not confirmed in the available sourcing, so it should be read as contextual timing rather than a confirmed motive. What is confirmed is that a major state government disclosed a ransomware compromise, went through a multi-week containment process, and is now facing a public leak threat, all within the same month.
Election-adjacent timing raises the political stakes regardless of whether Rhysida deliberately chose the moment. A leaked cache containing emergency plans and critical infrastructure data lands very differently in a news cycle already focused on public trust in government administration, which is likely why Berlin’s Governing Mayor moved quickly to state publicly that the city will not pay.
Berlin’s Response and What Refusing to Pay Actually Means
Berlin’s Governing Mayor has stated the city will not pay the 30 BTC demand, a position that tracks with guidance from EU cybersecurity bodies and US federal law enforcement, both of which generally discourage ransom payments on the grounds that payment funds further attacks and offers no guarantee the data will not be leaked anyway. Refusing to pay does not make the leak threat disappear. It shifts the response toward damage control: identifying exactly which individuals and systems are exposed, notifying affected people where required by German data protection law, and rotating any credentials that may have leaked.
The reconnection of all Senate departments on August 23 suggests Berlin’s technical response was already well underway before Rhysida went public on August 28. That sequencing, containment finishing before the leak-site post appeared, is consistent with a negotiation period that ran quietly for weeks before breaking down. Once a leak site posts a countdown, the pressure moves from private negotiation to public reputation management, which is a harder position for any government to manage cleanly.
How This Compares to Other 2026 Government and Enterprise Breaches
Berlin’s case sits alongside a run of large breaches disclosed earlier in 2026 that give some useful scale for comparison. Manchester Airports Group confirmed a breach affecting 8.7 million people and refused to pay its attackers’ ransom, a similar public posture to Berlin’s. Hasbro disclosed a breach exposing Social Security numbers tied to 436 employees, a much smaller but more narrowly personal exposure. Both cases show the same pattern playing out across sectors: attackers claim a large data volume, the victim refuses payment, and the dispute over what was actually taken plays out in public reporting rather than a courtroom.
What sets Berlin apart is the category of data involved. A retailer or airline breach centers on customer records. A state government breach that includes critical infrastructure information and emergency response plans raises questions that go beyond identity theft risk, touching directly on public safety planning. That is a meaningfully different risk profile even if the eventual confirmed file count turns out smaller than Rhysida’s claimed 1.44 million.
| Incident | Sector | Claimed/confirmed scale | Ransom outcome |
|---|---|---|---|
| Berlin state government (Rhysida, Aug 2026) | Public sector / government | 5.79 TB, ~1.44M files claimed | 30 BTC demanded, refused |
| Manchester Airports Group | Transportation infrastructure | 8.7 million people affected | Ransom refused |
| Hasbro | Consumer products / corporate | 436 employee SSNs exposed | Not disclosed as ransom case |
The Bitcoin Ransom Math
Thirty bitcoin sounds like a specific, almost modest number next to the scale of the claimed data haul, but it reflects how ransomware pricing usually works: demands are set against what negotiators believe a specific victim can plausibly pay quickly, not against the theoretical value of the stolen data. At roughly $2.3 million based on current market pricing, the demand is large enough to matter to a municipal budget but small enough that Rhysida likely expected a negotiation rather than an instant payment.
Bitcoin remains the default settlement currency for ransomware groups because it is liquid, globally accessible, and easy to move through mixing services and cross-chain bridges before cashing out. Law enforcement has gotten better at tracing bitcoin flows after the fact, which is part of why some ransomware crews have experimented with privacy coins, but bitcoin’s liquidity still wins out for groups that need to move funds fast and split payouts among affiliates.
What Happens if the Leak-Site Auction Goes Live
If Berlin’s data goes to auction once Rhysida’s countdown expires, the practical effect is usually one of two outcomes: either a buyer purchases exclusive access to the archive, or, more commonly in cases where no buyer steps forward, the group publishes the data for free to punish the victim and demonstrate credibility to future targets. Free publication is actually the more damaging outcome for Berlin, since it puts the full claimed dataset, including credentials and personal records, into wide circulation rather than limiting exposure to a single buyer.
Either path creates the same follow-on risk: the roughly 6,000 files Rhysida claims contain login credentials would need to be assumed compromised and rotated regardless of whether a buyer ever surfaces, since leak-site data has a way of circulating on secondary forums even after an initial sale.
The Verification Problem Every Ransomware Story Shares
It is worth being direct about what is confirmed here and what is not. Berlin’s government has confirmed the ransomware and extortion attempt itself, the affected department, and the exfiltration window. Everything about the file counts, the specific categories of records, and the number of individuals affected comes from Rhysida’s own leak-site description, which Berlin has explicitly not verified. This gap between attacker claims and victim confirmation shows up in nearly every major ransomware disclosure, and it is the main reason initial headlines about a breach often shrink, or occasionally grow, once forensic teams finish their work weeks later.
Readers should treat the 5.79 TB and 1.44 million file figures as a starting claim rather than an audited total. Governments have strong incentive to downplay scope during an active investigation, and ransomware groups have equally strong incentive to inflate it. The real number typically lands somewhere between the two once independent forensic review is complete, if it is ever made fully public at all.
Lessons for Public-Sector IT Teams
The exfiltration window identified in Berlin, August 7 to August 12, is a useful data point on its own. Five days of undetected data movement out of a government network is not unusual for ransomware intrusions generally, but it underscores a persistent gap in public-sector security operations: many agencies still lack the network monitoring needed to catch large outbound transfers in real time, relying instead on discovering the breach after encryption or extortion begins.
The department-by-department reconnection process Berlin ran between the breach and August 23 is a reasonable containment model for other government IT teams to study, even without full technical detail publicly available. Isolating a single compromised department first, verifying it is clean, and only then reconnecting to the shared network limits how far an intrusion can spread while investigators work, rather than either shutting down everything at once or leaving the whole network exposed while triage continues.
Market and Political Impact
There is no publicly traded company at the center of this breach, so there is no stock price to move, but the political impact is real. A state government confirming a ransomware compromise involving critical infrastructure data and emergency plans, timed close to an election cycle, puts pressure on Berlin’s administration to show a fast, transparent response. Expect German data protection authorities to weigh in on notification obligations under national law, and expect opposition parties to use the incident in upcoming political debate regardless of how the technical details ultimately resolve.
For the broader ransomware economy, a successful, well-publicized hit on a state capital’s government network reinforces to other groups that public-sector targets remain viable even in wealthy, well-resourced countries. That is likely to keep government IT budgets under pressure to spend more on detection and segmentation rather than only on perimeter defenses.
Predictions: Where This Goes From Here
- Berlin will not pay the 30 BTC ransom, consistent with the Governing Mayor’s public statement, and the leak-site countdown will likely expire without a negotiated settlement.
- Independent forensic confirmation of the actual exposed record count will trail the initial claims by weeks, and the confirmed number will probably differ meaningfully from Rhysida’s 1.44 million file claim.
- German data protection regulators will require formal breach notifications to at least the 12,076 individuals Rhysida claims are affected, pending verification of that figure.
- Other Rhysida targets in the pipeline, if any exist, will likely see accelerated leak-site postings as the group uses Berlin’s publicity to pressure other in-progress negotiations.
- Expect increased scrutiny of network segmentation practices across German state and municipal IT departments over the following months, mirroring the response pattern seen after other major European public-sector breaches.
The Bigger Picture: Ransomware Against Governments Isn’t Slowing Down
Berlin joins a growing list of government bodies hit by ransomware in 2026, and the pattern is consistent regardless of country: attackers claim large, specific-sounding data volumes, victims decline to pay, and the actual scope of the breach becomes a slow-moving story that unfolds over the following weeks and months as forensic work catches up to the initial claims. What makes each case newsworthy on its own is the specific mix of data involved and how directly it touches public services people rely on every day, from administrative fines to emergency planning documents.
For now, the confirmed facts are narrower than the headlines suggest: a ransomware and extortion attempt against Berlin’s state government, a five-day exfiltration window in early-to-mid August, a full network reconnection by August 23, and a public leak-site posting on August 28 demanding 30 bitcoin with a roughly week-long countdown. Everything else, the terabyte count, the file categories, the personal data figures, remains Rhysida’s claim until Berlin’s own investigators say otherwise.
Frequently Asked Questions
What is Rhysida?
Rhysida is a ransomware and extortion group active since 2023 that has previously targeted public-sector and healthcare organizations, including reported past incidents involving the British Library and Chile’s army.
Has Berlin confirmed the ransomware attack?
Yes. Berlin’s state government confirmed the ransomware and extortion attempt on August 28, 2026, and confirmed data exfiltration from its Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and August 12, 2026.
How much data does Rhysida claim to have stolen?
Rhysida claims 5.79 terabytes across roughly 1.44 million files. Berlin has not independently verified this figure.
Is Berlin going to pay the 30 BTC ransom?
No. Berlin’s Governing Mayor has publicly stated the city will not pay the demand, which is roughly $2.3 million at current bitcoin prices.
What kind of data is reportedly at risk?
Rhysida’s claims include contracts, administrative fine and offence proceedings, critical infrastructure information, judicial documents, emergency plans, login credentials, and personal data such as email addresses, phone numbers and IBANs. These are attacker claims, not confirmed by Berlin.
What happens if the ransom deadline passes?
Rhysida’s leak site typically moves unpaid data to a public auction. If no buyer emerges, groups like Rhysida have a history of publishing the data for free, which would expose the claimed dataset more broadly than a single private sale.
Is this connected to a Berlin election?
Some reporting notes the disclosure’s timing near a Berlin state-parliament election cycle, but the exact election date and any direct connection to the attack’s timing are not confirmed in current reporting.
How does this compare to other 2026 government breaches?
It follows a similar refuse-to-pay pattern seen in the Manchester Airports Group breach, which affected 8.7 million people, though Berlin’s case involves government infrastructure and emergency-planning data rather than customer records.
Sources: heise online, crypto.news, News4Hackers, FBI Internet Crime Complaint Center, and Coveware ransomware research.




