The state government of Berlin, Germany, has confirmed a major cyberattack and subsequent extortion attempt by the Rhysida ransomware group. The attackers claim to have stolen 5.79 TB of data, comprising 1.44 million files, from the city's administrative network. The compromised data allegedly includes contracts, emails, passwords, and classified information. Rhysida is auctioning the data on its darknet leak site, starting at 30 bitcoin. Berlin's Governing Mayor, Kai Wegner, has issued a strong statement that the state will not submit to extortion. The breach was traced to the Senate Department for Mobility, Transport, Climate Protection and Environment, with the data exfiltration occurring over several days in early August 2026.
What Happened: The Rhysida ransomware group compromised the network of a Berlin Senate Department, exfiltrated a massive trove of data, and is now attempting to extort the city government by auctioning the stolen information online.
Attacker: Rhysida is a ransomware-as-a-service (RaaS) operation that emerged in mid-2023. The group is known for its double-extortion tactics and has targeted a wide range of sectors, including healthcare, education, and government. Security researchers believe the group may have ties to Russia or Eastern Europe.
Victim: The primary victim is the Berlin state government, specifically the Senate Department for Mobility, Transport, Climate Protection and Environment. The attack impacts the city's administration and potentially exposes the data of citizens and government employees.
Attack Vector: The initial access vector is not specified in the reports. However, the prolonged data exfiltration period (August 7-12) before the network was disconnected (August 14) suggests the attackers maintained persistent access for some time before being detected and fully contained.
Rhysida is known for using various TTPs, often leveraging phishing emails for initial access and exploiting known vulnerabilities. Once inside a network, they engage in lateral movement and data exfiltration before deploying their ransomware payload. The public auctioning of data is a classic pressure tactic to coerce payment.
T1566 - Phishing: A common initial access vector for ransomware groups.T1190 - Exploit Public-Facing Application: Potentially exploited a vulnerability in an internet-facing system.T1078 - Valid Accounts: Likely used compromised credentials to maintain access over the multi-day exfiltration period.T1560.001 - Archive Collected Data: Archive via Utility: Attackers typically compress and stage data before exfiltration.T1074 - Data Staged: The 5.79 TB of data would have been staged on a compromised server prior to exfiltration.T1041 - Exfiltration Over C2 Channel: Exfiltrating large amounts of data over their command-and-control channel.T1490 - Inhibit System Recovery: While not explicitly mentioned, ransomware groups often delete backups.T1657 - Financial Theft: The ultimate goal of the extortion attempt.The theft of 5.79 TB of government data represents a severe security and privacy failure. The exposed data, including contracts and personal information, could be used for espionage, fraud, or to launch further attacks against government employees and partners. The public refusal to pay the ransom is a principled stance but increases the likelihood that the data will be leaked or sold, leading to long-term consequences. While officials state election infrastructure is unaffected, the breach erodes public trust in the government's ability to protect sensitive information. The cost of investigation, remediation, and potential regulatory fines under GDPR will be substantial.
No specific Indicators of Compromise (IOCs) were provided in the source articles.
Security teams can hunt for signs of Rhysida activity using the following patterns:
.rhysida appended to them, which indicates encryption by the ransomware.Critical_Message.pdf or similar, dropped in compromised directories.Segment networks to prevent attackers from moving laterally from a less-sensitive department to critical administrative systems.
Mapped D3FEND Techniques:
Maintain a rigorous patch management program to close vulnerabilities commonly exploited by ransomware groups.
Mapped D3FEND Techniques:
Train users to recognize and report phishing attempts, a primary initial access vector for ransomware.
Use modern EDR/XDR solutions capable of detecting ransomware behavior heuristically, not just based on signatures.
Mapped D3FEND Techniques:
Implement a robust network segmentation strategy to contain threats like the Rhysida ransomware. The breach originating in the Department of Mobility should not have been able to impact the broader state administrative network. Create distinct network zones for different government departments with strict firewall rules (a default-deny policy) controlling traffic between them. Critical infrastructure, such as election systems, should be in a highly restricted, air-gapped, or logically isolated zone. This containment strategy limits an attacker's ability to move laterally and stage large amounts of data from across the organization, significantly reducing the blast radius of an intrusion.
Deploy network detection and response (NDR) tools to monitor for large-scale data exfiltration. The exfiltration of 5.79 TB of data over several days is a significant anomaly that should be detectable. Configure alerts for sustained, high-volume outbound data transfers from internal servers to external destinations, especially those not on an approved list. Baselining normal traffic patterns is key. An alert for a server in the 'Mobility' department suddenly pushing terabytes of data to an unknown IP over 5 days would provide an early warning, potentially allowing for intervention before the full dataset is stolen.
Seed network shares with decoy files and folders designed to act as tripwires. These 'honeydocs' or 'canary tokens' should be named enticingly (e.g., 'passwords.xlsx', 'classified_projects.docx') and placed in locations accessible to attackers moving laterally. When an attacker opens or exfiltrates one of these files, it triggers a silent alert sent directly to the security team, providing high-fidelity, early warning of a compromise. This can significantly reduce detection time, which in this case could have stopped the exfiltration before 5.79 TB of real data was stolen.
Data exfiltration begins from the Senate Department for Mobility, Transport, Climate Protection and Environment.
Data exfiltration period ends.
The affected government network is disconnected.
Rhysida adds Berlin to its leak site and city officials publicly refuse to pay the ransom.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.