Berlin’s state government has crossed a line it spent two weeks trying to avoid. On August 31, 2026, officials confirmed that data was actually stolen from the city-state’s administrative network during the Rhysida ransomware attack, moving the story from “hackers claim” to “government admits.” BleepingComputer reported that forensic investigators pinpointed a confirmed data-exfiltration window between August 7 and August 12 inside the Senate Department for Mobility, Transport, Climate Protection and Environment, one of the departments Berlin disconnected from its central network as a precaution.
The admission matters because it closes a gap that ransomware crews exploit constantly: the window between an extortion claim and independent verification. As tech-insider.org reported when Rhysida first listed Berlin on its leak site, the gang claimed 5.79 TB of data spread across roughly 1.44 million files, including personal records tied to 12,076 individuals. For days, Berlin’s Senate would only say an attack had occurred and that non-public data “may” be among what was taken. That hedge is gone. The city government now says the theft is real, even as it maintains that the full scope is still being pieced together.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
Add Now
What Berlin has now confirmed, and what it still won’t say
Berlin’s confirmation is narrower than Rhysida’s marketing copy, and that gap is the story. Officials have validated exfiltration from one Senate portfolio during a specific five-day window in August. They have not validated Rhysida’s headline figure of 5.79 TB, nor the claim that 12,076 people had personal data exposed. Investigators from the State Criminal Police Office, the public prosecutor’s office and federal security agencies are working the case, according to reporting picked up by multiple outlets covering the breach.
That distinction between “confirmed” and “claimed” is not a technicality. Ransomware gangs routinely inflate stolen-data figures to pressure victims into paying, and defenders who over-correct by publicly matching the attacker’s numbers can end up owing more in breach-notification costs and legal exposure than the incident actually warrants. Berlin’s approach, validate what forensics can prove and stay quiet on the rest, is standard incident-response doctrine, even if it frustrates residents who want a straight answer about whether their own records were in the batch.
Berlin’s State Secretary for Digital Affairs, Florian Hauer, has said the data had been leaking for roughly a week before the intrusion was even discovered, according to The Berliner. That detail alone explains why the confirmed exfiltration window predates the August 14 network disconnection by roughly a week: the attackers had already finished moving data out before anyone noticed they were inside.
The timeline: from quiet intrusion to public confirmation
Piecing together statements from Berlin’s Senate and the outlets tracking the case, the sequence runs like this. Data began leaving the network around August 7, undetected. The breach itself was discovered in mid-August, prompting the city to sever two Senate departments, Urban Development, Building and Housing, and Mobility, Transport, Climate Protection and Environment, from the shared state network (the Landesnetz) on August 14 as a containment measure. Rhysida went public on August 28, posting its Berlin entry to a leak site and opening what it described as a four-day countdown toward auctioning the data, with a starting price of 30 Bitcoin. Berlin’s leadership responded within the same window, rejecting the ransom demand outright. By August 31, the government’s language had shifted from “an attack occurred” to an explicit acknowledgment that data exfiltration had been forensically confirmed.
That two-week gap between the last confirmed data outflow and the public disclosure is not unusual for a network of Berlin’s size, but it is exactly the kind of dwell time that turns a contained incident into a citywide crisis. Every day the attackers had unsupervised access inside the Landesnetz was a day they could map connected systems, harvest credentials and select which departments to hit hardest.
Why Berlin is refusing to pay
Berlin’s political leadership drew a hard line almost immediately. Mayor Kai Wegner said plainly that “Berlin will not be blackmailed,” a position reported by the BBC. Berlin’s Interior Senator, Iris Spranger, went further, telling reporters that “regardless of the amount demanded or the method of extortion, we will not allow this extortion to take place in the federal capital and in Berlin,” a statement covered by The Berliner.
The refusal is consistent with guidance from Germany’s federal cybersecurity agency and with a broader European trend of public-sector bodies declining to negotiate with ransomware crews, on the logic that payment funds future attacks and rarely guarantees the data won’t leak anyway. It also carries political weight: Berlin is heading toward elections, and a government seen caving to a criminal extortion demand weeks beforehand would hand opponents an easy line of attack. Security Affairs flagged the pre-election timing as a factor amplifying the political stakes of the breach.
The tradeoff is real, though. Refusing to pay means Rhysida’s auction proceeds on schedule unless law enforcement or a third party intervenes, and whatever data the group actually holds could surface publicly or get sold to another criminal buyer. Berlin is betting that the reputational and financial cost of validating extortion as a business model outweighs the cost of a data leak it can’t fully prevent at this point regardless of payment.
What Rhysida claims to have taken
Rhysida’s leak-site posting is the source of the eye-catching numbers attached to this story, and it’s worth being precise about which figures come from the attackers versus what the government has verified. According to the group’s own claims, reported by outlets including The Hacker News and SecurityWeek, the dataset includes roughly 46,500 supplier and third-party contracts, more than 11,000 confidential documents, close to 6,000 passwords, tens of thousands of emails and phone numbers, and 148 IBAN bank account numbers. Separate reporting on the leak-site listing puts personal records at 12,076 individuals, alongside personnel files, administrative-offence records and payroll data.
None of that is independently verified by Berlin’s government as of this writing. What is confirmed is narrower: exfiltration occurred, it touched at least one Senate department, and it happened in a specific window in early August. Everything past that point, the exact volume, the exact categories of personal data, and whether the 5.79 TB figure is accurate or inflated, remains under forensic review.
| Detail | Rhysida’s claim | Government-confirmed status |
|---|---|---|
| Total data volume | 5.79 TB / ~1.44 million files | Not independently verified |
| Exfiltration window | Not specified by attackers | Confirmed: August 7–12, 2026 |
| Departments confirmed affected | Entire “Landesnetz” implied | Mobility, Transport, Climate Protection and Environment |
| Personal records exposed | 12,076 individuals | Not independently verified |
| Contracts allegedly stolen | ~46,500 | Not independently verified |
| Ransom demand | 30 BTC via dark-web auction | Confirmed demanded, confirmed refused |
| Auction countdown | ~4 days from August 28 listing | Confirmed by Berlin officials’ public response |
Who is Rhysida, and why does it keep hitting public institutions
Rhysida operates as a ransomware-as-a-service group that has been active since mid-2023, and reporting on the Berlin incident places its victim count at roughly 280 organizations worldwide. The group has built a reputation for targeting sectors with limited cybersecurity budgets relative to the sensitivity of the data they hold: hospitals, universities, school districts and, increasingly, city and state governments. That pattern isn’t accidental. Public-sector networks tend to be large, interconnected across many departments, and built up over years through mergers of legacy systems, which makes them harder to segment and easier to move through laterally once an attacker gets a foothold.
Rhysida’s business model also leans on the auction format rather than simple encryption-for-ransom. Encrypting a government network raises the alarm immediately and disrupts services in a way that draws national attention and law-enforcement resources. Quietly exfiltrating data, then dangling a countdown auction, gives the group leverage without the same operational disruption; it also puts pressure on the victim organization rather than the group’s own timeline, since a public agency has far more to lose from a data leak involving citizens’ personal information than most private companies do.
Germany’s public sector has a pattern problem
Berlin’s breach lands inside a broader trend that German cybersecurity reporters have been tracking through 2026: a steady rise in ransomware and extortion attempts against state and municipal IT systems, often via credential theft and lateral movement rather than sophisticated zero-day exploits. Germany’s federal government has pushed stricter cybersecurity requirements onto public administrations in recent years, but the Berlin case shows the gap between policy and practice. A single compromised credential, once inside a shared state network connecting multiple Senate departments, can produce exactly this kind of cascading exposure.
The comparison that keeps coming up among German security researchers is less about any single vulnerability and more about network architecture. Large, centralized government networks that link many departments under one administrative umbrella are efficient to run day to day, but they turn any single breach into a multi-agency incident. Berlin’s decision to sever two departments from the Landesnetz on August 14 was itself an acknowledgment that the shared-network model made containment harder than it should have been.
How this compares to other 2026 public-sector breaches
Berlin’s incident is not an isolated event in 2026’s ransomware calendar. Manchester Airports Group disclosed a breach affecting 8.7 million customers earlier this year, and the FulcrumSec group separately claimed an 86 GB theft from Manchester airport systems that MAG’s leadership refused to pay out on. The ATF was hit by the Qilin ransomware group, which claimed roughly 885 victims tied to that incident. McKesson, a healthcare distributor, faced ShinyHunters’ claims of 284 million exposed records. Each of these cases shares a structural feature with Berlin: an attacker claim that outpaces what the victim organization is willing or able to confirm in the first days after disclosure, followed by a slower, more conservative government or corporate confirmation days or weeks later.
What sets Berlin apart is the explicit political dimension. Airport operators and healthcare distributors answer to boards and regulators; a state government answers to voters, and it’s doing so weeks before an election. That timing pressure shapes both the refusal to pay and the pace of public disclosure, since silence looks worse for an elected government than it does for a private company managing a shareholder relations problem.
| Incident | Attacker group | Claimed/confirmed scale | Ransom outcome |
|---|---|---|---|
| Berlin state government (Aug 2026) | Rhysida | 5.79 TB claimed; partial exfiltration confirmed | Refused |
| Manchester Airports Group | FulcrumSec (claim) | 8.7M customers disclosed; 86 GB separately claimed | Refused |
| ATF breach | Qilin | ~885 victims claimed | Not disclosed as paid |
| McKesson | ShinyHunters | 284M records claimed | Not disclosed as paid |
| Cl0p / PTC Windchill campaign | Cl0p | Multiple enterprises hit (Shell, GE, Philips) | Not disclosed as paid |
The market and institutional impact
Government ransomware incidents don’t move stock tickers the way a breach at a public company does, but they carry a different kind of cost: procurement disruption, insurance premium increases for public-sector cyber coverage, and pressure on national cybersecurity budgets. Berlin’s confirmed exfiltration will likely accelerate conversations already underway in Germany about ring-fencing sensitive Senate department data from the shared Landesnetz architecture, a change that costs money and takes years to implement properly.
There’s also a vendor angle. Incidents like this one tend to boost near-term demand for network segmentation consulting, identity and access management audits, and breach-response retainers among public-sector IT departments watching Berlin’s response play out in real time. Cybersecurity vendors serving government clients across Europe are likely to reference this case in sales conversations for the rest of 2026, the same way past high-profile municipal breaches became reference points for budget requests in other cities.
What residents and affected organizations should do now
For Berlin residents and any organization that had contracts on file with the affected Senate department, the practical guidance mirrors standard breach-response advice: watch for phishing attempts that reference specific contract or account details (a common follow-on tactic once financial and contact data circulates), and treat any unsolicited communication claiming to be from Berlin’s administration with skepticism until the Senate publishes an official notification channel. Businesses with IBANs or contract data potentially in the exposed set should flag their accounts with their banks for enhanced monitoring, given that 148 IBAN numbers are among Rhysida’s claimed haul.
Berlin’s Senate has not yet published a full breakdown of which individuals or organizations were affected, which mirrors the same “confirmed but not comprehensive” disclosure pattern seen in most large-scale government breaches. A more complete accounting typically follows the initial confirmation by several weeks, once forensic teams finish reconstructing exactly what left the network during the confirmed exfiltration window. Organizations looking to avoid the same exposure can review this step-by-step ransomware protection guide.
Predictions: where this story goes next
- Rhysida’s auction countdown will likely lapse without a sale within the announced window, at which point the group either publishes the data outright or quietly shelves the listing, a common pattern when high-profile victims refuse to engage.
- Berlin’s Senate will expand its confirmed-exfiltration disclosure to cover at least one additional department beyond Mobility, Transport, Climate Protection and Environment, given that two departments were disconnected as a precaution on August 14.
- Expect German federal cybersecurity officials to reference this incident directly when pushing for stricter mandatory segmentation requirements on Länder-level government networks later in 2026.
- Class-action-style complaints or data-protection authority inquiries tied to GDPR notification obligations are likely within weeks, given the scale of personal data Rhysida claims to hold.
- Other German municipal and state governments will quietly accelerate network segmentation and credential-hygiene audits in the fourth quarter of 2026, using Berlin’s public disclosure as internal justification for budget requests that were previously delayed.
The bigger picture: confirmation as a turning point
The shift from “Rhysida claims” to “Berlin confirms” is a small phrase change with a large practical effect. Once a government body confirms data theft, it typically triggers formal breach-notification obligations, regulatory scrutiny, and a documentation trail that outlives the news cycle. Rhysida’s leak-site claims will fade from headlines within weeks regardless of whether the auction proceeds. Berlin’s forensic confirmation, by contrast, sets in motion a slower process, data-protection filings, individual notifications, potential legal exposure, that will likely still be working through German institutions well into 2027.
For other public-sector IT leaders watching from outside Berlin, the lesson isn’t really about Rhysida specifically. It’s about the dwell time between initial compromise and detection. Data was reportedly leaving Berlin’s network for roughly a week before anyone noticed. That gap, not the ransom demand or the auction theatrics, is the part of this story most likely to repeat itself in the next city, the next state, the next agency that hasn’t yet had its own confirmation moment.
Frequently asked questions
Has Berlin officially confirmed data was stolen in the Rhysida attack?
Yes. As of August 31, 2026, Berlin’s government confirmed forensically verified data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment during a window between August 7 and August 12, according to reporting from BleepingComputer. The full scope beyond that department remains under investigation.
Who is behind the Berlin ransomware attack?
Rhysida, a ransomware-as-a-service group active since mid-2023 with roughly 280 claimed victims worldwide, listed Berlin on its dark-web leak site on August 28, 2026.
How much data does Rhysida claim to have stolen from Berlin?
Rhysida claims 5.79 TB of data across roughly 1.44 million files, including personal information tied to 12,076 individuals, according to the group’s leak-site posting reported by multiple outlets including The Hacker News and SecurityWeek. Berlin’s government has not independently verified this figure.
Is Berlin paying the ransom?
No. Berlin’s Mayor Kai Wegner and Interior Senator Iris Spranger have publicly and repeatedly stated the city will not pay, framing the refusal as a stand against extortion targeting the federal capital.
What ransom did Rhysida demand?
Rhysida demanded 30 Bitcoin through a dark-web auction listing, with a countdown of roughly seven days from the August 28 posting, threatening to publish or sell the data if no payment was made.
Which Berlin government departments were affected?
Berlin disconnected two Senate departments from its shared administrative network (the Landesnetz) as a precaution on August 14, 2026: the Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and Environment. Confirmed data exfiltration has so far been tied specifically to the latter.
Was personal data of Berlin residents exposed?
Berlin’s Senate says personal or otherwise non-public data may be among what was stolen, but has not published a complete list of affected individuals or data categories. Rhysida’s own claims cite personal records for 12,076 people, a figure not independently confirmed by the government.
How does this compare to other 2026 government and enterprise breaches?
It follows a familiar pattern seen in 2026 incidents involving Manchester Airports Group, the ATF, and McKesson: an attacker claim that significantly outpaces what the victim organization initially confirms, followed by a narrower, forensically validated disclosure days or weeks later.
