Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [incident, rhysida, berlin, ransomware, government, germany, gdpr] ยท confidence: high ยท severity: high ยท affected_sectors: [Government] ยท au_impact: false

Berlin Confirms Data Theft After Rhysida Attack; Election Systems Ruled Safe

Summary

Berlin's city administration confirmed in late August 2026 that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on its data-leak site. Governing Mayor Kai Wegner said Berlin will not pay.

Details

Rhysida claims 5.79 TB and approximately 1.44 million files exfiltrated, including plaintext credentials, password vaults, database accounts, personnel files, NDA documents and a critical-infrastructure security assessment of Berlin's water supply. The group is using GDPR-violation exposure as leverage with a four-day publication deadline.

Forensic work found data was also taken from the Senate Department for Mobility, Transport, Climate Protection and the Environment between 7 and 12 August; the affected departments were disconnected from the state network on 14 August. Senator Iris Spranger said investigators found no evidence election data was compromised and the environment supporting Berlin's upcoming House of Representatives election is considered secure.

Assessment

The incident continues a pattern of Rhysida targeting state and local government since mid-2023. Berlin's refusal to pay and the confirmation that formal election systems were untouched are notable for a jurisdiction facing an imminent vote โ€” but the exfiltration of personnel files, credentials and water-supply security assessments represents a serious intelligence and privacy impact regardless of the payment decision.