Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The Berlin state government has confirmed that a ransomware attack by the Rhysida group exfiltrated data from the Senate Department for Mobility, Transport, Climate Protection and Environment and the Senate Department for Urban Development, Construction and Housing between August 7 and 12, 2026. Disconnection of the affected departments from the Landesnetz — the shared backbone linking roughly 600 infrastructure sites across the city-state — did not occur until August 14: seven days after exfiltration was first detected. This structural delay transformed a containable security incident into a metropolitan-scale data crisis, with publication of the stolen materials on September 4–5 and a crisis unit activated just 15 days before the September 20 elections.
- Exfiltration confirmed between August 7 and 12, 2026; departments remained connected to the Landesnetz until August 14, creating a seven-day containment gap.
- Rhysida published the data on its leak site on August 28 and listed it for auction on September 4–5 with an opening price of 30 bitcoin, valued at approximately $77,622 by Reuters or roughly $2.3 million by SecurityWeek.
- The Berlin government, represented by Mayor Kai Wegner and Interior Senator Iris Spranger, explicitly refused to pay the ransom and activated a central crisis unit to review the stolen data.
- Authorities ruled out compromise of the September 20, 2026 election system; the investigation is led by the state criminal police, the public prosecutor, federal security agencies, and the BSI.
The Timeline That Doesn't Add Up: Why Seven Days Became the Core Problem
Forensic investigations identified August 7, 2026 as the date exfiltration was first detected from the Senate Department for Mobility, Transport, Climate Protection and Environment. Systems continued operating on the Landesnetz for another seven days, until disconnection was ordered on August 14. According to Florian Hauer, State Secretary for Digital Affairs, data was exfiltrated for roughly a week before the intrusion was discovered.
This sequence is not a mere technical footnote. The Landesnetz is not an isolated administrative network: it connects roughly 600 sites spanning government, police, fire services, and hospitals. The decision to disconnect two departments from shared infrastructure of this magnitude requires political and technical approvals that, in Berlin's case, stretched timelines beyond the threshold for effective containment. Rhysida's operational pattern — prolonged access, silent exfiltration, leak-site publication with a countdown — exploits precisely this asymmetry between attacker speed and governance sluggishness.
Berlin's first public disclosure came on August 17–18. Rhysida posted the city on its leak site on August 28. Official confirmation of data theft followed on August 31. The data auction launched on September 4–5. Each step widened the exposure surface, but the root cause remains that August week of maintained connectivity.
What Was Exposed: Between Group Claims and Limits of Official Confirmation
Rhysida claimed exfiltration of 5.79 TB of data, approximately 1.44 million files, personal information of 12,076 individuals, and 46,500 contracts. These figures, reported by BleepingComputer, SecurityWeek, and The Hacker News, have not been independently confirmed by the Berlin government. Authorities activated a central crisis unit to review and assess the stolen data but have not released their own tally of compromised volumes.
The group also asserted it stole classified data from the Bundesrat, Germany's upper house of parliament. This claim remains unverified. The Berlin government has limited its confirmations to the two identified senate departments, without extending the scope to federal institutions or other entities connected to the Landesnetz.
The distinction between ransomware claims and official verification is operationally significant. Organizations managing incidents under a no-payment policy, like Berlin, depend on their own forensic audit capacity to size the legal and communications response. Without independent volume confirmation, the state government is proceeding on a conservative basis, treating every potentially exposed datum as effectively compromised until proven otherwise.
The Ransom Refusal and the Public Entity's Trade-off
"The State of Berlin will not be blackmailed" — Mayor Kai Wegner and Interior Senator Iris Spranger, joint statement
The Berlin government refused the 30-bitcoin ransom demanded by Rhysida. The decision, announced publicly by Mayor Wegner and Senator Spranger, frames the incident as "an extremely serious crime and an attack on the state itself." The Interior Senator added: "regardless of the amount demanded or the method of extortion, we will not allow this extortion to take place in the federal capital and in Berlin."
The refusal aligns with the German and broader European line of non-negotiation with ransomware actors. The actual cost of this choice, however, is measured in data publication. Rhysida listed the materials for auction at an opening price of 30 bitcoin; the dollar equivalent varies significantly across sources. Reuters values it at approximately $77,622. SecurityWeek puts it at roughly $2.3 million. The discrepancy likely reflects different bitcoin valuations at different times or different interpretations of the auction mechanism, but authorities have not clarified it.
For a public entity, the trade-off is structural: the non-payment principle preserves institutional integrity and deters future attacks, but exposes citizens to publication of their data without guarantees of control over subsequent distribution. Berlin's crisis unit is working precisely on this front, reviewing stolen data to notify affected parties and prepare legal defenses.
The Electoral Context and the Absence of Vote Compromise
The attack landed 15 days before the September 20, 2026 elections for the Berlin House of Representatives. The timing raised questions about possible operational or informational influence on the vote. Authorities ruled out this hypothesis with precise statements. Senator Spranger stated there is "no evidence that election data has been compromised" and that "the technical environment supporting the upcoming elections for the Berlin House of Representatives is considered secure."
The investigation is conducted by the state criminal police (Landeskriminalamt), the public prosecutor, federal security agencies, and the Federal Office for Information Security (BSI). The BSI's involvement signals the event's national relevance, beyond local competence.
The Rhysida group, active since 2023 according to leak-site monitoring, has claimed roughly 280 global victims. In Germany, The Hacker News reports nine identified victims, including Stuttgart (May 2026) and Welthungerhilfe (June 2025). Geographic attribution of the group — Russian-speaking areas or Eastern Europe per analysis sources — is not confirmed by public technical evidence.
Why It Matters
The Berlin incident documents a governance pattern more than a single technical failure. The Landesnetz is designed for interoperability among essential services: the same architecture that enables coordination among government, emergency services, and healthcare creates propagation surfaces that containment procedures cannot rapidly segment. The seven-day gap is not the product of individual negligence but of the decision-making structure that governs critical networks in democratic contexts.
For other European public entities, the case offers a concrete operational precedent: the ransom refusal avoided funding a criminal group, but did not prevent data publication. The actual measure of citizen protection depends on disconnection speed and forensic backup quality, not on the ethical stance on payment. Berlin chose the second line; the cost reads in the 12,076 individuals (per unverified claim) potentially exposed and a crisis unit still active two weeks before the vote.
The dossier does not specify the initial access vector used in this attack, nor any lateral movement within the Landesnetz prior to containment. It does not document specific remedial measures applied after August 14 nor the exact nature of exposed data beyond the administrative typology of the departments involved.
Information verified against cited sources and current as of publication.
Sources
- https://www.devdiscourse.com/article/technology/3973190-cybersecurity-crisis-berlin-departments-hit-by-ransomware?amp
- https://whbl.com/2026/09/05/berlin-launches-crisis-response-after-hackers-publish-stolen-data/
- https://www.globalbankingandfinance.com/berlin-launches-crisis-response-hackers-publish-stolen-data/
- https://tech-insider.org/berlin-ransomware-isolation-gap-rhysida-2026/
- https://www.escudodigital.com/en/cybersecurity/berlin-refuses-ransom-demand-after-state-network-cyberattack.html
- https://tech-insider.org/berlin-confirms-data-theft-rhysida-ransomware-2026/
- https://www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/
- https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
- https://www.securityweek.com/berlin-wont-pay-extortion-group-claiming-data-theft/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.