Berlin’s state government confirmed on August 31, 2026, that the Rhysida ransomware group stole data from its administrative network during a five-day window in August — a breach that forensic investigators now trace directly to a seven-day gap between when the city first detected the intrusion and when it finally cut the compromised departments from its central network. That gap, not the ransomware binary itself, is what handed a criminal group claiming ties to Russia access to 1.44 million government files, including water-supply vulnerability assessments, plaintext credential files, and the personal records of 12,076 Berliners.
Governing Mayor Kai Wegner, speaking at an emergency Senate session held at the Rotes Rathaus, told reporters that Berlin would not pay. “The state of Berlin is being blackmailed,” he said. “Berlin has fallen victim to a serious crime.” The ransom demand — reported by German news outlets at 30 bitcoin, roughly €2 million (approximately $2.32 million USD) — will go unpaid. Interior Senator Iris Spranger separately confirmed election systems are secure — the technical environment supporting the September 20 Berlin House of Representatives election is isolated from the compromised network and has not been affected.
The breach surfaced publicly on August 28, when Rhysida posted an entry titled simply “Berlin, Germany” on its dark-web leak site and set a seven-day countdown before threatening to release or auction the data. Berlin’s government acknowledged the extortion attempt the same day, before publicly confirming the data theft on August 31 following emergency Senate deliberations.
Why Seven Days Is Not a Mistake — It’s a Design Problem
The most technically consequential detail in Berlin’s confirmed timeline is not the ransomware group’s identity or the volume of files claimed — it is the interval. Forensic investigators established that data began leaving the network on August 7. The Senate Department for Mobility, Transport, Climate Protection and the Environment detected that outflow on the same day. But neither it nor the also-affected Senate Department for Urban Development, Building and Housing was disconnected from Berlin’s central government network — the Berliner Landesnetz — until August 14, seven days later.
That interval is not anomalous in large public-sector networks. It is, in fact, structurally predictable. The Berliner Landesnetz connects approximately 600 administrative and public-sector locations — government departments, police stations, fire services, and hospitals — under a shared connectivity model designed to enable cross-agency operations. When one segment is compromised, isolating it requires either automated segmentation mechanisms — network architecture that physically or logically separates the affected zone the moment an anomaly is detected — or a manual decision chain that runs through bureaucratic authorization before any cables are pulled. Most large government networks rely on the latter. Berlin’s timeline suggests it did too.
The significance of this gap is not about blame. It is about the operational window it provided. Rhysida’s documented attack methodology, detailed in a CISA, FBI, and MS-ISAC joint advisory, follows a two-phase structure: reconnaissance and lateral movement before encryption, and data staging before the payload detonates. Rhysida actors use phishing emails or stolen VPN credentials — particularly at organizations without multi-factor authentication enabled by default — to establish a Cobalt Strike beacon inside the network. They then use that beacon for command and control, privilege escalation, and lateral movement across systems, staging data for exfiltration before triggering any encryption payload.
That pre-encryption phase is exactly where the seven-day window lives. According to Sophos’s 2025 Active Adversary Report, the median dwell time for ransomware cases — the gap between initial attacker access and ransomware execution — stands at four days in incident-response investigations, down from nine days in 2022. Mandiant’s M-Trends 2026 report puts the broader median at 14 days, falling to nine when organizations detect breaches internally rather than via external notification. Berlin’s seven-day detection-to-containment gap effectively handed Rhysida the full reconnaissance window the industry considers worst-case. The exfiltration in this case apparently preceded any encryption — there is no indication that Berlin’s systems were encrypted. Rhysida extracted what it could and left, suggesting the group prioritized data exfiltration for double-extortion leverage over the disruptive but forensically louder encryption phase.
What Rhysida Claims to Hold
The data breakdown Rhysida published on its dark-web leak site on August 28 — and confirmed by the leak-monitoring service ransomware.live — is, if accurate, one of the most sensitive ransomware payloads claimed against a Western European capital’s government. Berlin has neither confirmed nor denied the scope of those claims; forensic review is ongoing.
Rhysida’s listing breaks down into eleven file categories. The largest single category is 124,823 mapping and geodata files. The most operationally dangerous categories are smaller but more specific: 5,941 files Rhysida describes as containing passwords — including, the group claims, plaintext credentials for a building-management database and a payment-processing system — and 8,110 infrastructure files that include vulnerability assessments of Berlin’s water supply. Credentials in plaintext are immediately actionable by any buyer who acquires the data; water-supply vulnerability assessments in criminal hands represent a documented risk to critical infrastructure that extends well beyond financial harm.
The personal data categories are also extensive. Rhysida claims possession of records on 12,076 named individuals, along with 16,389 email addresses, 11,963 phone numbers, and 148 IBANs (international bank account numbers). The broader file inventory includes 77,939 legal and complaints files, 55,553 financial files, 46,522 contracts and 3,226 non-disclosure agreements, 27,299 HR files, and more than 5,000 personnel and payroll records. Passport and identity scans, SQL database dumps covering 2006 through 2026, and Bundesrat committee protocols also appear in the claimed breakdown.
Berlin’s government has confirmed that “personal data or other non-public data” cannot be ruled out. It has published no figure for how much data actually left the network. The entire itemized account in public circulation originates from Rhysida’s own leak-site post.
Who Rhysida Is and Why the British Library Matters
Rhysida emerged as a ransomware-as-a-service operation in May 2023. Under that model, the group maintains and leases ransomware infrastructure to criminal affiliates, who execute attacks and split proceeds with the operators. As of August 29, 2026, leak-site monitoring showed 280 confirmed Rhysida victims across 39 countries. Nine of those victims are German organizations, including the Stuttgart city administration (attacked May 2026) and the humanitarian aid organization Welthungerhilfe (attacked June 2025). In the first half of 2025, the government sector globally saw a 65% year-over-year increase in ransomware incidents, totaling 208 attacks on government bodies.
The group concentrates heavily on public institutions — education, healthcare, government, and defense — sectors characterized by sensitive data holdings and historically limited cybersecurity investment.
Rhysida’s most instructive prior confrontation is the October 2023 attack on the British Library, which U.K. officials described as “one of the worst cyber incidents in British history.” The library refused to pay. Rhysida published the stolen data. Berlin’s public refusal to pay therefore carries a specific and documented precedent: when Rhysida’s countdown timer expires, the group has demonstrated willingness to release whatever it holds. The countdown began August 28; the auction deadline is expected to fall around September 4, 2026.
Researchers believe Rhysida operates from Russia or the Commonwealth of Independent States. The group’s documentation includes Russian-language communications, and its targeting policy explicitly avoids organizations based in Russia or other former Soviet states — a pattern consistent with ransomware groups that operate under state tolerance, as documented by Cynet’s Rhysida threat profile.
Berlin’s Real-Time Service Disruption
The attack’s visible cost to Berliners was not abstract. From August 14, when the two departments were disconnected from the Landesnetz, through August 23, when they were reconnected, departmental staff lost access to the internet, external email, and shared district databases. Housing-benefit applications and payments were suspended for more than 50,000 households during that period. Some public-facing digital services — including the housing-benefit application portal — remained unavailable into late August.
The human impact of network isolation extends beyond the services that went down. The period between August 7, when the breach was detected internally, and August 14, when the departments were finally cut off, was also the period during which normal government operations continued on a network that attackers were actively moving through. Citizens, staff, and partner agencies continued using systems that were simultaneously being mapped and exfiltrated by Rhysida.
GDPR, NIS2, and the Regulatory Exposure Berlin Now Faces
Berlin’s confirmation that personal data cannot be excluded from the stolen files simultaneously triggered obligations under two overlapping European regulatory frameworks, and the gap between when those obligations began and when public confirmation came is itself a compliance question.
Under GDPR Article 33 and EDPB Guidelines 9/2022, data controllers must notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in risk to individuals. That clock does not start when the breach becomes public — it starts when the controller becomes aware. Berlin’s forensic record shows the Senate Department for Mobility detected a data outflow on August 7. Regulators may determine that August 7 is the relevant awareness date, which would place the 72-hour notification window closing on August 10 — four days before the departments were even disconnected from the network, and three weeks before the August 31 public confirmation. Where the breach poses high risk to individuals, Article 34 additionally requires direct notification to affected persons.
Germany’s Federal Data Protection Act (BDSG) adds a parallel domestic obligation. The NIS2 Directive, which expanded mandatory cybersecurity requirements to public administration entities and essential-service operators beginning in 2024, imposes a three-stage incident-reporting structure under Article 23: a 24-hour early warning, a 72-hour detailed notification, and a one-month final report, with each stage as a separate compliance deadline. Given that Rhysida’s claimed haul includes water-supply vulnerability assessments and other infrastructure records, Berlin’s departments may qualify as essential entities under NIS2’s critical-infrastructure provisions, engaging the more stringent supervisory tier.
The European Data Protection Board’s EDPB Guidelines 9/2022 add a dimension that quietly reinforces Berlin’s no-payment position: the EDPB has clarified that paying a ransom does not extinguish breach-notification obligations and may worsen a finding of inadequate technical and organizational measures under GDPR Article 32. Paying would not have solved Berlin’s regulatory problem — it would have added to it.
The European Commission’s NIS2 amendment proposal (COM(2026) 13 final, January 2026) is the first EU legislative instrument to address ransomware payments in a structured way, requiring entities to disclose, on regulatory request, whether a ransom was paid and to whom. That proposal has not yet been adopted — expected adoption is late 2026 or 2027 at the earliest — but Berlin’s refusal is already consistent with the posture the Commission is working to codify. Academic commentary in the European Journal of Risk Regulation has begun examining whether mandatory disclosure requirements will reshape ransom-payment calculus across European public institutions.
No-Payment as European Policy in Motion
Wegner’s refusal to pay reflects a deliberate posture that Germany’s federal cybersecurity guidance has long recommended and that is accelerating across European governments. Germany’s BSI, which is actively involved in the Berlin investigation, has consistently advised against ransom payments on the grounds that payment funds criminal infrastructure and provides no guarantee of data deletion or decryption. Several European government bodies adopted formal no-payment policies across 2025 and 2026, treating the decision as a policy matter rather than an operational one.
The structural argument against payment, as Wegner made it, is also the regulatory argument: paying would produce no reliable guarantee that Rhysida deletes the stolen files, and the group’s documented behavior — it published the British Library’s data after that institution refused — suggests the double-extortion model treats data publication as the follow-through, not just the threat. If Rhysida releases any portion of the claimed 5.79 TB (approximately 5.4 tebibytes) after the auction deadline passes, Berlin will face a second wave of GDPR Article 34 exposure and citizen notification obligations on top of its ongoing forensic review.
What Comes Next
Berlin’s forensic review of the Berliner Landesnetz is ongoing. Law enforcement investigations by the state criminal police (Landeskriminalamt), the public prosecutor’s office, and federal security agencies including the BSI are active. The state data protection commissioner is being kept informed on a continuing basis. Whether those investigations result in attribution — Rhysida’s operators remain publicly unidentified — depends on international cooperation that, historically, takes months or years in ransomware cases.
For the 12,076 individuals whose personal records Rhysida claims to hold, the official position as of August 31 is still a holding one: forensic work continues, personal data exposure cannot be ruled out, and more information will follow. No date for direct notification to affected individuals has been announced. Under GDPR Article 34, that notification must come where the breach poses high risk — and records containing IBANs, passport scans, and contact details almost certainly clear that threshold.
The more systemic question Berlin’s breach poses is architectural: how many other government networks connecting hundreds of sites across departments rely on manual decision chains to isolate a compromised node — and how many of them have measured what that decision chain costs when an attacker like Rhysida is actively moving through the network while the isolation decision is being made?
(Exchange rate as of September 1, 2026; conversions are approximate.)
Frequently Asked Questions
What data does Rhysida claim to have stolen from Berlin’s government network?
Rhysida’s leak-site listing, confirmed by the monitoring service ransomware.live, claims 5.79 terabytes (TB) of data across approximately 1.44 million files. The claimed categories include personal records of 12,076 named individuals, 16,389 email addresses, 11,963 phone numbers, 148 IBANs, 46,522 contracts, 55,553 financial files, 77,939 legal and complaints files, and 5,941 files described as containing passwords. The listing also claims 8,110 infrastructure files that include vulnerability assessments of Berlin’s water supply. Berlin’s government has confirmed that personal or non-public data cannot be excluded from what was stolen, but has published no independent verification of Rhysida’s specific figures.
Why did it take seven days from initial detection to network isolation — and why does that gap matter?
Berlin’s forensic record shows the Senate Department for Mobility detected a data outflow on August 7, 2026, but both affected departments remained connected to the central Berliner Landesnetz until August 14. That seven-day gap reflects a structural feature of large interconnected government networks: isolating one compromised segment requires either automatic segmentation mechanisms — technical controls that quarantine an affected zone without human approval — or manual authorization decisions that take time to execute. Rhysida’s documented attack methodology uses that pre-isolation window for Cobalt Strike lateral movement, network reconnaissance, and data staging. Sophos’s 2025 Active Adversary Report found the median ransomware dwell time (from initial access to encryption) is now four days — meaning Berlin’s containment gap exceeded the industry’s worst-case benchmark before the departments were cut off.
What are the legal obligations Berlin now faces under GDPR and NIS2 after confirming this breach?
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a qualifying personal data breach. If regulators determine Berlin became “aware” on August 7 — when internal detection occurred — the 72-hour notification window closed on August 10, weeks before public confirmation. Article 34 requires direct notification to affected individuals where the breach poses high risk; the stolen data categories (IBANs, passport scans, contact information) almost certainly meet that threshold. Berlin’s departments likely also face NIS2 Article 23 obligations, which impose a three-stage reporting structure with separate deadlines for public administration entities and essential-service operators.
Is Berlin’s election infrastructure safe, and what happens if Rhysida publishes the stolen data?
Interior Senator Iris Spranger confirmed that the technical systems supporting the September 20 Berlin Abgeordnetenhaus (House of Representatives) election are entirely separate from the compromised Senate administration network and have not been affected. If Rhysida follows its documented behavior after the auction deadline passes — the group published stolen data after British Library refused to pay — Berlin will face a second wave of regulatory exposure: GDPR Article 34 individual notification obligations activate when breach data becomes publicly accessible, adding urgency to the ongoing forensic review. The auction deadline is expected to fall around September 4, 2026.
