LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Threats
Critical🔐 RansomwareNEW

Rhysida Ransomware Hits Berlin — Germany's Capital Under Cyberattack (2026)

The Rhysida ransomware group breached Berlin's state government network in August 2026, stealing 5.79 TB of data and demanding a bitcoin ransom the city refused to pay.

Published: 28 August 2026

What Is This Threat?

In August 2026, the ransomware group Rhysida breached the IT network of the German capital's state government — the Berliner Landesnetz — just weeks before a regional election, stealing sensitive administrative data. Officials confirmed the intrusion and refused to pay the attackers' ransom demand.

This incident is part of a broader trend: German authorities report that state-linked and financially motivated groups increasingly target public administration, using ransomware not just to encrypt systems but to steal and threaten to leak data — a tactic known as double extortion.

Timeline of the Attack

| Date | Event |

|---|---|

| August 7, 2026 | Attackers gain initial access to Berlin's state network |

| August 7–12, 2026 | Data exfiltration takes place undetected |

| August 14, 2026 | Berlin disconnects affected systems from the network |

| August 17, 2026 | Berlin publicly discloses the breach |

| August 28, 2026 | Rhysida posts the stolen data on its dark-web leak site and sets a ransom deadline |

Attackers had roughly a full week inside the network before anyone cut off access — enough time to move laterally and copy large volumes of files undetected.

What Was Stolen

According to the attackers' own leak-site posting:

  • Approximately 5.79 terabytes of data, spanning roughly 1.44 million files
  • Personal information on over 12,000 individuals, including email addresses, phone numbers, and IBANs
  • More than 46,500 contracts, along with emails, passwords, and internal records
  • Geodata and mapping files from a Berlin senate department
  • Rhysida demanded a ransom of roughly 30 bitcoin (around $2.3 million) and threatened to auction or publish the data. Berlin's governing mayor stated the city would not pay, calling it blackmail.

    How These Attacks Typically Happen

    Rhysida and similar ransomware operators generally don't need to "hack" their way in — they log in:

  • Initial access via compromised VPN credentials without multi-factor authentication, unpatched vulnerabilities (such as Zerologon), or targeted phishing emails
  • Lateral movement across the internal network to reach file servers and databases
  • Data exfiltration of as much sensitive data as possible before deploying any encryption
  • Extortion: threatening to leak or sell the stolen data on a dark-web portal unless a ransom is paid
  • Publishing a sample or the full dataset if the deadline passes without payment
  • Why It Matters — Even If You Don't Work for the Government

    Breaches like this expose ordinary residents' personal data — names, contact details, and financial identifiers — which fuels follow-on phishing, vishing, and identity theft. Attackers frequently use leaked data from public-sector breaches to make later scam messages look convincing and personalized.

    Red Flags Checklist

  • ❌ Unexpected emails, SMS, or calls referencing your dealings with a public authority or city administration
  • ❌ Messages citing accurate personal details (name, address, case number) to appear legitimate after a known breach
  • ❌ Urgent requests to "verify" your identity, bank details, or login credentials by phone or email
  • ❌ Links to portals that don't match official government (.berlin.de, .bund.de) domains
  • ❌ Any request for passwords, full card numbers, or one-time codes
  • How to Protect Yourself

    • Be alert for follow-up scams that reference a known government data breach to appear credible
    • Never provide passwords, full card numbers, or one-time codes over the phone or via email/SMS
    • Verify any message claiming to be from a public authority by contacting the agency directly through its official website
    • Enable multi-factor authentication on all accounts, especially email and banking
    • Use unique, strong passwords for every account so one breach doesn't compromise others
    • If you interact with public administration IT systems professionally, ensure VPN access requires MFA and apply security patches promptly
    • Monitor official Berlin government communications for updates on which specific data was exposed

    What to Do If Affected

    1. 1.If you receive a suspicious message referencing this breach, do not click any links — contact the agency directly using a known official number
    2. 2.If you suspect your data was included in the Berlin leak, monitor your accounts and email for signs of targeted phishing
    3. 3.Change passwords for any accounts that may share credentials with compromised systems, and enable MFA
    4. 4.If financial details (e.g. IBAN) were exposed, alert your bank and watch for unauthorized transactions
    5. 5.Report phishing attempts to Germany's BSI (Federal Office for Information Security) or your local police cybercrime unit
    6. 6.Keep records of any suspicious contact in case you need to report identity theft or fraud later
    #Germany#Berlin#Rhysida#ransomware#government#data breach#2026