Berlin's city administration has confirmed that it is facing an extortion attempt following a cyberattack by the Rhysida ransomware group, which listed the city on its data leak site. The incident, discovered in mid-August, was publicly claimed by the attackers on August 28. Berlin Mayor Kai Wegner stated that the city will not pay the ransom. The State Criminal Police Office, the public prosecutor's office, and federal security agencies are currently investigating the breach.
Rhysida ransomware has been active since mid-2023, previously targeting healthcare organizations, state governments, educational institutions, and critical infrastructure. The group claims to have exfiltrated 5.79 terabytes of data, comprising approximately 1.44 million files, from Berlin's administrative network.
According to the attackers, the stolen information includes government, legal, financial, contractual, HR, infrastructure, health, and mapping records. Specific claims detail thousands of names, email addresses, phone numbers, and 148 International Bank Account Numbers (IBANs). The attackers also allege they obtained plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials.
Further claims from Rhysida include the exfiltration of personnel files, payroll information, administrative-offense records, email archives, SQL database dumps, identity documents, and banking information. Documents related to disciplinary proceedings and other named cases were also allegedly compromised. The group claims to possess classified or sensitive government material, including Bundesrat committee records and information on handling classified documents, as well as critical-infrastructure security assessments concerning Berlin's water supply. More than 3,200 documents marked as nondisclosure agreements are also purportedly among the stolen data.
The attackers are leveraging potential GDPR violations to pressure the Berlin government, issuing a four-day deadline for payment before the alleged stolen files are published.
Forensic investigators have determined that data was exfiltrated from the Senate Department for Mobility, Transport, Climate Protection and the Environment, likely between August 7 and 12. The affected Senate departments were disconnected from the state network on August 14. The investigation is ongoing, and the full extent of the data theft has yet to be determined.
Senator Iris Spranger confirmed that officials have found no evidence of compromised election data, and the technical environment supporting the upcoming Berlin House of Representatives election is considered secure. The initial method of entry used by Rhysida in this attack has not been disclosed. In a previous campaign, the ransomware operators reportedly used malicious Microsoft Teams installers to breach targets.






