Berlin’s state government is dealing with the fallout of a ransomware attack after the Rhysida extortion gang published roughly 6 terabytes of stolen data on the dark web, including material described as touching state administration and national defense records. The leak followed a refused ransom demand of 30 bitcoin, worth close to €2 million at the time, and lands Berlin alongside a growing list of European public-sector bodies hit by the same Russian-speaking group.
Reuters reported that Berlin’s government launched a crisis response on Saturday, September 5, 2026, after the ransomware group released data taken from two government departments. Security Affairs and the threat-intelligence outlet Cyberverso separately identified the actor as Rhysida and detailed the ransom timeline, which ran out on September 4, 2026, before the group dumped the cache online. The incident is one of the more sensitive government breaches Germany has faced this year, both for its scale and for the reported inclusion of defense-related material inside a state government’s IT systems.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What Happened: Berlin’s Government Hit by Rhysida Ransomware
According to Reuters, the cyberattack hit two departments inside Berlin’s state administration rather than the government’s entire network. Officials said on September 5, 2026, that they were reviewing the leaked material “with the highest intensity,” a sign the state was still working out how much sensitive information had actually left its systems. That kind of triage lag is typical in ransomware cases of this size: attackers often exfiltrate data over days or weeks before deploying encryption or making contact, so defenders are usually reconstructing the intrusion timeline after the fact rather than watching it unfold in real time.
Berlin’s state government did not confirm exactly how the attackers first got into its network, and neither Reuters nor Security Affairs reported a specific initial access vector. Rhysida has historically favored phishing campaigns, exposed remote-access services, and stolen credentials as entry points in other publicized cases, but there is no confirmed technical detail tying the Berlin intrusion to any one of those methods. What is confirmed is the outcome: the group claimed responsibility, set a payment deadline, and followed through on its threat to publish data once that deadline passed.
Timeline: From Intrusion to a 6TB Data Dump
Cyberverso’s brief on the incident put the ransom deadline at September 4, 2026. When Berlin’s government did not pay, Rhysida moved to publish the stolen material, and Security Affairs reported the resulting leak at roughly 6TB of data by September 11, 2026. Reuters’ reporting on the government’s crisis response, dated September 5, 2026, sits right at the point where the deadline had just passed and the leak was beginning to surface, which lines up with the standard Rhysida playbook of publish first, negotiate never.
The compressed timeline, roughly a week from confirmed government awareness to a full public data dump, mirrors what other Rhysida victims have described. The group typically gives victims a short window, often just days, and treats a missed deadline as final rather than as an opening for renewed negotiation. That posture puts pressure on victim organizations to make a payment decision quickly, often before forensic investigators have even finished scoping what was taken.
Who Is Rhysida? Inside the Russian-Speaking Extortion Gang
Cyberverso’s coverage described Rhysida as a Russian-speaking extortion operation, consistent with how the group has been characterized since it first drew wide attention in 2023. Rhysida operates on a ransomware-as-a-service model, meaning the core group develops the encryption and leak-site infrastructure while affiliates carry out individual intrusions, splitting proceeds when a victim pays. That structure explains why Rhysida’s victim list spans such different sectors and countries: healthcare systems, cultural institutions, gaming studios, and now a German state government all show up in its portfolio, because affiliates pick targets independently rather than following a single centralized strategy.
The group publicly surfaced in mid-2023 and quickly built a reputation for hitting high-profile, headline-generating targets rather than staying purely opportunistic. A joint advisory from CISA and the FBI on Rhysida, first issued in November 2023, described the group’s double-extortion model: steal data first, encrypt second, then threaten publication if the victim refuses to pay. That advisory also noted Rhysida’s use of legitimate remote-access tools to blend in with normal network traffic, a technique that makes early detection harder for defenders who are watching for obviously malicious software rather than misused admin tools.
What Data Was Exposed, and Why Defense Files Raise the Stakes
Security Affairs’ reporting described the leaked 6TB as including sensitive state administration information alongside material characterized as national defense data. That combination is what separates this incident from a routine municipal breach. State and local governments hold enormous volumes of resident and administrative records, but material tied to defense functions raises different questions: whether any of it touches procurement, infrastructure, or coordination with federal defense agencies, and whether other governments or hostile intelligence services might have an interest in mining a public leak for details they could not obtain through normal channels.
Neither Reuters nor Security Affairs published a specific breakdown of file types, record counts, or which federal or state defense functions might be represented in the cache. Because Berlin’s government has not issued a detailed accounting of exactly what was in the stolen 6TB, outside analysts are largely limited to characterizing the leak by category rather than by content, and any resident of Berlin or contractor who worked with the affected departments should treat the exposure as a live risk until officials say otherwise.
Berlin’s Official Response and Crisis Management
Reuters reported that Berlin’s government activated a crisis response after the leak became public, with officials describing an active review of the released data. The phrase “highest intensity,” attributed to the government’s public statement, points to a mobilization of resources across multiple agencies rather than a single IT team working the issue in isolation. Public-sector breaches of this size typically pull in state data-protection authorities, criminal investigators, and often federal cybersecurity agencies, since the type of data involved and Germany’s data-protection framework determine which regulators need to be looped in and on what timeline.
As of the most recent reporting, Berlin’s government had not disclosed a specific number of affected individuals, a full list of impacted systems, or a timeline for restoring any services that may have been taken offline as a precaution. That silence is not unusual this early in a government breach response, since public disclosure obligations in Germany and the EU generally require accuracy over speed, but it does mean residents and affected parties are, for now, working from incomplete information about their own exposure.
The Ransom Demand: 30 Bitcoin and Why Berlin Said No
Cyberverso reported the ransom figure at 30 bitcoin, valued at roughly €2 million (about $2.4 million) at the time of the demand. Security Affairs directly tied Berlin’s refusal to pay to the subsequent data leak, framing the publication as retaliation for the missed deadline rather than a separate, unrelated disclosure. Governments generally have stronger institutional reasons than private companies to refuse ransom payments: paying sets a precedent that can invite repeat targeting of public agencies, and many jurisdictions treat payments to sanctioned or suspected criminal groups as a legal minefield in their own right.
That calculus does not make the decision costless. Refusing to pay converts a private extortion attempt into a public data breach with defense-adjacent material in circulation, which is a materially different and arguably worse outcome for exposed individuals and institutions than a quiet payment would have been, even though it is the outcome most security agencies recommend. The tension between “never pay” guidance and the real damage of a public leak is exactly what plays out whenever a well-resourced government target calls a ransom gang’s bluff and loses that particular bet.
Berlin Incident at a Glance
| Detail | Reported Figure | Source |
|---|---|---|
| Threat actor | Rhysida (Russian-speaking extortion group) | Cyberverso |
| Departments affected | Two Berlin state government departments | Reuters |
| Ransom demand | 30 Bitcoin (~€2 million / ~$2.4 million at the time) | Cyberverso |
| Ransom deadline | September 4, 2026 | Cyberverso |
| Crisis response announced | September 5, 2026 | Reuters |
| Data volume leaked | Approximately 6TB | Security Affairs |
| Data categories described | State administration and national defense data | Security Affairs |
| Leak confirmed on dark web | By September 11, 2026 | Security Affairs |
Historical Context: Government and Public-Sector Ransomware in Europe
Rhysida is not a new name to European institutions. The group claimed responsibility for the October 2023 attack on the British Library, a widely documented incident that took down major parts of the library’s digital catalog and online services for months and is still cited by UK cybersecurity officials as a case study in how long recovery from a serious ransomware event can take, even for a well-funded public institution. Rhysida has also been linked in public reporting to attacks on US healthcare provider Prospect Medical Holdings and gaming studio Insomniac Games, both in 2023, underlining the group’s willingness to hit targets across very different sectors rather than specializing narrowly.
What makes the Berlin case notable within that pattern is the jump from cultural and healthcare institutions to a sitting state government with reported defense-adjacent material. European governments have increasingly become ransomware targets over the past three years, a trend regularly flagged in threat reports from national cybersecurity agencies across the EU, precisely because state and municipal IT systems tend to run older infrastructure with smaller security budgets than comparably sized private enterprises, while still holding data valuable enough to make extortion worthwhile.
Competitive Comparison: How Rhysida Stacks Up Against Other Active Gangs
Rhysida operates in a crowded field of ransomware-as-a-service groups, each with a slightly different playbook. LockBit, one of the longest-running and most prolific operations, has historically run a large affiliate network and focused heavily on manufacturing and logistics targets before facing repeated law enforcement disruption efforts. Akira, which emerged in 2023 around the same time as Rhysida, has leaned into small and mid-sized business targets and has been flagged by CISA advisories for exploiting VPN appliances without multi-factor authentication as a common entry point. Medusa, per FBI and CISA advisories, has targeted critical infrastructure sectors broadly and has been described in federal guidance as running an aggressive double-extortion model with short payment windows, a trait it shares with Rhysida.
Where Rhysida differentiates itself is in target selection that skews toward headline value: a national library, a well-known game studio, and now a state government all generate outsized media attention relative to the group’s overall operational footprint, which may be part of the point. Public, high-profile leaks put pressure on future victims to pay quickly rather than call the bluff, since Berlin’s experience is now a visible example of what happens when a target refuses.
Ransomware Gang Comparison
| Group | Model | Typical Targets | Notable Trait |
|---|---|---|---|
| Rhysida | Ransomware-as-a-service, double extortion | Public institutions, healthcare, gaming, government | High-profile, headline-driven target selection |
| LockBit | Large affiliate RaaS network | Manufacturing, logistics, enterprise | Long operational history, repeated law enforcement takedowns |
| Akira | Double extortion, RaaS | Small and mid-sized businesses | Frequently exploits VPN appliances lacking MFA, per CISA |
| Medusa | Double extortion, RaaS | Critical infrastructure sectors | Aggressive short ransom deadlines, per FBI/CISA advisories |
Market Impact: Insurance, Vendor Budgets, and Public-Sector Spending
Government ransomware incidents of this profile tend to ripple outward into procurement and insurance markets well beyond the victim itself. Cyber insurers that write policies for municipal and state government bodies typically reassess premium models after a major public-sector claim, and a defense-adjacent data leak specifically tends to trigger closer scrutiny from insurers who write coverage touching critical infrastructure or government contracts. Vendors selling endpoint detection, backup and recovery, and identity security tools to the public sector often see renewed interest from other state and municipal IT departments in the weeks following a high-profile peer incident, a pattern security vendors have described repeatedly after past European government breaches.
For Berlin specifically, the practical cost is likely to extend well past any ransom figure that was refused. Post-breach remediation for a government network of this size typically includes forensic investigation, credential resets across affected departments, legal and regulatory response under German and EU data-protection rules, and potentially years of monitoring costs for individuals whose data appeared in the leak. None of those figures have been disclosed yet, and Berlin’s government has given no public estimate of total remediation cost.
Why Government Agencies Remain Prime Ransomware Targets
Public-sector IT environments share a familiar set of weaknesses that make them attractive to groups like Rhysida. Budgets for state and municipal technology departments are typically set through political processes that prioritize visible services over back-office security investment, which means patching cycles, legacy system replacement, and staff training often lag behind what a similarly sized private company would maintain. Government networks also tend to interconnect many departments and legacy systems that were never designed with modern segmentation in mind, so a single compromised account can sometimes provide a path to much more of the network than intended.
There is also a reputational and political dimension that private companies do not face in the same way. A government breach becomes a matter of public accountability almost immediately, forcing officials to communicate under scrutiny while investigations are still ongoing, which is a different pressure than a corporate breach where disclosure timing is more within the victim’s control. That dynamic partly explains why Berlin’s government moved quickly to describe a crisis response even before it had full clarity on the scope of what had been taken.
Basic Ransomware Hardening Steps Security Agencies Recommend
Federal cybersecurity agencies including CISA have published recurring guidance for government and enterprise networks looking to reduce ransomware exposure. The following is a general checklist drawn from published #StopRansomware guidance, not specific to the Berlin incident, since the initial access vector in this case has not been confirmed.
# General ransomware exposure reduction checklist (per CISA #StopRansomware guidance)
1. Enforce phishing-resistant MFA on all remote access and admin accounts
2. Patch internet-facing VPN, firewall, and remote-access appliances on a fixed cadence
3. Maintain offline, tested backups isolated from the primary network
4. Segment networks so a single compromised account cannot reach all departments
5. Monitor for misuse of legitimate remote-access and admin tools, not just malware signatures
6. Maintain a tested incident response plan with defined ransom-decision authority
7. Log and retain endpoint and network telemetry long enough to reconstruct intrusion timelinesPredictions: What Comes Next for Berlin and for Rhysida
- Berlin’s government will likely publish a more detailed accounting of affected systems and individuals once its internal review concludes, as German and EU data-protection rules generally push toward eventual disclosure even when initial statements are vague.
- Expect scrutiny of whether any defense-related material in the leak reached federal German defense agencies or NATO-adjacent contractors, given how sensitive that categorization is likely to be treated by investigators.
- Other German state and municipal governments will likely face renewed pressure from state auditors and cybersecurity agencies to review their own exposure to the same phishing and remote-access weaknesses Rhysida and comparable groups have exploited elsewhere.
- Rhysida is likely to reference the Berlin leak in future extortion attempts against other government targets as proof that it follows through on publication threats, a tactic ransomware groups commonly use to pressure new victims into faster payment decisions.
- Cyber insurers serving European public-sector clients will likely revisit underwriting terms for government policies that include coverage for defense-adjacent or classified-adjacent data exposure, given how unusual that combination is in a single incident.
What Organizations Can Learn From Berlin’s Response
Berlin’s public crisis-response framing, rather than a quiet internal fix, reflects a broader shift in how European public bodies are expected to handle major breaches. Silence or minimization in the early hours of a confirmed leak tends to erode public trust faster than an admission of an active, unresolved review, even when the review itself has not produced firm answers yet. Security teams at other government bodies watching this incident unfold are likely drawing the same lesson private-sector incident responders learned years ago: the communication strategy during the first 72 hours often matters as much to public perception as the technical remediation that follows.
The refusal to pay, while consistent with standard government guidance against funding ransomware operations, also demonstrates the real trade-off institutions face. Berlin avoided directly financing a criminal group, but it now has 6TB of state and defense-adjacent data circulating publicly, a cost that will likely take considerably longer to fully quantify than the 30 Bitcoin ransom that was refused.
Frequently Asked Questions
What is Rhysida?
Rhysida is a Russian-speaking ransomware and extortion group that operates on a ransomware-as-a-service model, meaning affiliates carry out intrusions and split proceeds with the core group. It first drew wide public attention in 2023 and was the subject of a joint CISA/FBI advisory that year.
What happened in the Berlin ransomware attack?
Rhysida breached two departments within Berlin’s state government, demanded 30 Bitcoin, and published approximately 6TB of stolen data after the government refused to pay by the September 4, 2026 deadline, according to Reuters, Cyberverso, and Security Affairs.
Was any national defense data actually exposed?
Security Affairs described the leaked data as including material characterized as national defense data alongside state administration records. Berlin’s government has not published a detailed breakdown of the leak’s exact contents.
How much was the ransom demand?
Cyberverso reported the demand at 30 Bitcoin, valued at roughly €2 million (about $2.4 million) at the time it was made.
Did Berlin pay the ransom?
No. Security Affairs reported that Berlin’s government refused to pay, which the group cited as the reason for publishing the stolen data.
Has Rhysida attacked other high-profile targets before?
Yes. The group has been linked in public reporting to the 2023 attack on the British Library in the UK, as well as incidents involving US healthcare provider Prospect Medical Holdings and gaming studio Insomniac Games.
How is Rhysida different from other ransomware gangs like LockBit or Medusa?
All operate on similar ransomware-as-a-service, double-extortion models, but Rhysida has stood out for targeting high-profile, headline-generating institutions such as cultural organizations and now a state government, rather than focusing narrowly on one industry sector.
What should organizations do to reduce ransomware risk following incidents like this?
CISA’s #StopRansomware guidance recommends phishing-resistant MFA, regular patching of internet-facing remote access systems, isolated offline backups, network segmentation, and monitoring for misuse of legitimate admin tools rather than relying solely on malware signatures.
Click Here For The Original Source.
