// 1 CRITICAL · 1 ZERO-DAY · 4 CVE · 4 EXPLOIT IN THE LAST 24H
The Rhysida ransomware group claimed responsibility for a cyberattack on the Berlin state government on August 28, 2026, auctioning 5.79 TB of allegedly stolen data for a starting bid of 30 bitcoin. Berlin authorities refused to pay the ransom. State parliamentary elections are scheduled for September 20, 2026.

The Rhysida ransomware group claimed responsibility for the attack on the Berlin state government on August 28, 2026, offering 5.79 TB of allegedly stolen data for auction with a starting price of 30 bitcoin. Berlin authorities refused to give in to the extortion attempt. State parliamentary elections are set for September 20, 2026.

Key Takeaways
  • Rhysida posted the claim on its Tor site under the title "Berlin, Germany," auctioning the data with a starting bid of 30 bitcoin (approximately $77,622) and a timer of roughly 7 days.
  • Data exfiltration occurred between August 7 and August 12, 2026; the network was publicly isolated on August 17. Senate departments were reconnected on August 23.
  • Mayor Kai Wegner and Interior Senator Iris Spranger declared: "The state of Berlin will not submit to extortion."
  • Authorities confirmed that election infrastructure was not compromised. The figures of 5.79 TB, 1.44 million files, and 12,076 exposed individuals come from the group's claim and have not been independently verified.

Incident Timeline: From Detection to Reconnection

According to forensic investigators' reconstruction reported by Security Affairs, data exfiltration began on August 7, 2026. Internal detection occurred on that same date. The network was publicly isolated on August 17.

By August 23, all Senate departments had been reconnected. The ransom demand arrived on Thursday, August 27, around 17:30, according to RBB24. The group is described as "known to the Senate" by local German sources.

The interval between detection on August 7 and isolation on August 17 raises questions about response times, which authorities have not commented on in detail. The forensic investigation determined the effective exfiltration window.

The Auction Mechanism and the Figures at Stake

Rhysida adopted an auction mechanism instead of a classic direct ransom demand. The starting price of 30 bitcoin, equivalent to approximately $77,622 according to Reuters, is accompanied by a timer of roughly 7 days.

This method, cited by Reuters via Internazionale and confirmed by Devdiscourse, introduces a competitive dynamic among potential buyers. The timer creates additional time pressure compared to the traditional model.

A discrepancy in sources is worth noting: RBB24 headlined a figure of roughly 2 million euros in bitcoin, unverified in the body of the article. Reuters reported 30 bitcoin ($77,622). Authorities have not confirmed any figure.

Rhysida's claim includes 5.79 TB of data, approximately 1.44 million files, 12,076 individuals with allegedly exposed personal information, 16,389 email addresses, 11,963 phone numbers, and 148 IBANs. The Berlin government stated that the examination of the actual extent of the breach is still ongoing.

"The state of Berlin will not submit to extortion" — Kai Wegner, Mayor of Berlin, and Iris Spranger, Interior Senator, press conference after special Senate meeting

Group Profile and Historical Context

Rhysida emerged in 2023 and has claimed approximately 280 attacks, according to eCrime.ch cited by Reuters with confirmation from Ransom-DB. In Germany, the group had nine documented victims prior to this compromise.

A 2023 FBI/CISA advisory documents the group's historical patterns: initial access via compromised VPNs, exploitation of the Zerologon vulnerability, phishing campaigns, and lateral movement using legitimate system tools. These patterns are not confirmed as the vectors for the Berlin attack.

The specific initial access vector for the Berlin incident has not been made public. Sources indicate "Russia or Eastern Europe" as the hypothesized area of origin by researchers, not as a certainty. The name "Rhysida" is an operational label, not an identification of individuals.

Next Steps

Berlin authorities have ruled out paying the ransom. Election infrastructure was declared uncompromised by Senator Spranger, with support from security officials: "Nach jetzigem Stand sind dort keinerlei Daten abgeflossen und die Wahlumgebung ist sicher nach Angaben unserer Sicherheitsbeauftragten."

The government continues to operate with departments reconnected. The investigation into the actual extent of the breach is ongoing. It is not known whether the data was actually sold at auction or if the auction is a pressure mechanism.

Authorities have not indicated whether individuals whose data is allegedly exposed will be contacted individually. The examination of the actual extent of the breach will determine subsequent communications.

Source Context and Limitations

This article relies on journalistic sources: Security Affairs as the primary source, Reuters via Internazionale and Devdiscourse for auction data, and RBB24 for local German details.

The figures of 5.79 TB, 1.44 million files, and 12,076 exposed individuals derive exclusively from Rhysida's claim, not independently verified by authorities. No primary incident response source is available; technical data comes from the group's claim and journalistic sources.

Berlin state parliamentary elections are scheduled for September 20, 2026. The phrase "three weeks before the vote" is an editorial calculation based on the event date (August 28) and the election date.

Information has been verified against cited sources and updated at the time of publication.

Sources


Sources and references
  1. securityaffairs.com
  2. internazionale.it
  3. devdiscourse.com
  4. rbb24.de
  5. infosectoday.io
  6. blog.rankiteo.com