Rhysida Ransomware Hits Berlin — Germany's Capital Under Cyberattack (2026)
The Rhysida ransomware group breached Berlin's state government network in August 2026, stealing 5.79 TB of data and demanding a bitcoin ransom the city refused to pay.
What Is This Threat?
In August 2026, the ransomware group Rhysida breached the IT network of the German capital's state government — the Berliner Landesnetz — just weeks before a regional election, stealing sensitive administrative data. Officials confirmed the intrusion and refused to pay the attackers' ransom demand.
This incident is part of a broader trend: German authorities report that state-linked and financially motivated groups increasingly target public administration, using ransomware not just to encrypt systems but to steal and threaten to leak data — a tactic known as double extortion.
Timeline of the Attack
| Date | Event |
|---|---|
| August 7, 2026 | Attackers gain initial access to Berlin's state network |
| August 7–12, 2026 | Data exfiltration takes place undetected |
| August 14, 2026 | Berlin disconnects affected systems from the network |
| August 17, 2026 | Berlin publicly discloses the breach |
| August 28, 2026 | Rhysida posts the stolen data on its dark-web leak site and sets a ransom deadline |
Attackers had roughly a full week inside the network before anyone cut off access — enough time to move laterally and copy large volumes of files undetected.
What Was Stolen
According to the attackers' own leak-site posting:
Rhysida demanded a ransom of roughly 30 bitcoin (around $2.3 million) and threatened to auction or publish the data. Berlin's governing mayor stated the city would not pay, calling it blackmail.
How These Attacks Typically Happen
Rhysida and similar ransomware operators generally don't need to "hack" their way in — they log in:
Why It Matters — Even If You Don't Work for the Government
Breaches like this expose ordinary residents' personal data — names, contact details, and financial identifiers — which fuels follow-on phishing, vishing, and identity theft. Attackers frequently use leaked data from public-sector breaches to make later scam messages look convincing and personalized.
Red Flags Checklist
.berlin.de, .bund.de) domainsHow to Protect Yourself
- Be alert for follow-up scams that reference a known government data breach to appear credible
- Never provide passwords, full card numbers, or one-time codes over the phone or via email/SMS
- Verify any message claiming to be from a public authority by contacting the agency directly through its official website
- Enable multi-factor authentication on all accounts, especially email and banking
- Use unique, strong passwords for every account so one breach doesn't compromise others
- If you interact with public administration IT systems professionally, ensure VPN access requires MFA and apply security patches promptly
- Monitor official Berlin government communications for updates on which specific data was exposed
What to Do If Affected
- 1.If you receive a suspicious message referencing this breach, do not click any links — contact the agency directly using a known official number
- 2.If you suspect your data was included in the Berlin leak, monitor your accounts and email for signs of targeted phishing
- 3.Change passwords for any accounts that may share credentials with compromised systems, and enable MFA
- 4.If financial details (e.g. IBAN) were exposed, alert your bank and watch for unauthorized transactions
- 5.Report phishing attempts to Germany's BSI (Federal Office for Information Security) or your local police cybercrime unit
- 6.Keep records of any suspicious contact in case you need to report identity theft or fraud later