Key Takeaways

  • Rhysida claims to have extracted as much as 5.79 TB of data from Berlin’s state administrative network and is auctioning the information for 30 BTC.
  • The Berlin Senate Chancellery confirmed an extortion attempt, and authorities stated they will not pay the demand.
  • Potentially exposed credentials, contracts, and administrative records could create follow-on risks for public agencies, contractors, and other partners.

Rhysida has claimed responsibility for an August 2026 attack on Berlin’s state administrative network, turning the incident into a highly public extortion campaign just weeks before the city’s September elections.

The financially motivated ransomware operation is attempting to auction the allegedly stolen information through its leak site. Its starting price is 30 BTC, worth roughly €2 million at the time of the demand. Security reporting indicates Rhysida claims to have stolen about 5.79 TB of data, although Berlin authorities have not fully confirmed the volume or contents.

Ransomware operators routinely inflate claims to increase pressure, so attacker-provided metrics do not equate to independently verified breach assessments. However, the Berlin Senate Chancellery confirmed an extortion attempt occurred, and city officials indicated that authorities will not give in to the demand.

Rhysida’s listing reportedly includes a countdown designed to force a rapid decision. The group claims the material covers tens of thousands of contracts, administrative offense files, passwords, and login credentials, potentially including email addresses, contact details, and authentication data.

Restoring affected servers addresses only part of the problem. Once credentials and sensitive records have been copied outside a government network, clean backups cannot retrieve them. Attackers can sell the information, publish it, or use it to support phishing, business-email compromise, and additional intrusion attempts.

The risk may also spread through Berlin’s supplier ecosystem. Government contracts often contain names, contact channels, and operational details connecting agencies with outside businesses. If Rhysida’s claims prove accurate, contractors could face convincing messages that appear to reference legitimate projects or established relationships. A password exposed in one system could also open another if it has been reused.

The timing of the extortion attempt adds political pressure ahead of Berlin's September elections. An attacker does not need access to voting infrastructure to create confusion, attract attention, or undermine confidence in public administration.

Rhysida has been active since 2023 and has previously been associated with attacks on the British Library and healthcare providers. A joint advisory from CISA, the FBI, and the MS-ISAC documented the operation’s use of compromised VPN and Citrix access, along with legitimate administrative utilities used to move through victim environments. That “living off the land” approach can make malicious activity harder to distinguish from routine administration.

Defending against these tactics requires stronger identity controls. Rapid credential rotation, phishing-resistant multifactor authentication, and tighter oversight of remote-access systems can reduce the value of stolen passwords. Network segmentation can contain lateral movement, while offline or isolated backups support recovery when encryption occurs.

The BSI highlighted growing ransomware pressure and targeted attacks on authorities responsible for public security and foreign affairs in its 2024 assessment of Germany’s IT security environment. Public networks frequently combine legacy applications, shared services, contractors, and large numbers of users, creating a broad identity and access-management challenge.

Zero Trust principles can help narrow that exposure. NIST SP 800-207 recommends treating access as a continuing decision based on identity, device condition, and context rather than assuming activity inside a network is trustworthy. Implementing these architectures typically involves creating smaller access zones, improving telemetry, and enforcing fewer standing privileges.

Berlin authorities must now establish how Rhysida entered, what the intruders accessed, and whether network persistence remains. Such investigations often draw on incident-response and managed detection capabilities available from providers such as Mandiant, CrowdStrike, and Palo Alto Networks, working alongside internal government teams.

Refusing payment removes one source of criminal revenue, but the response effort continues. Berlin faces the extended task of validating Rhysida’s claims, notifying affected parties where appropriate, replacing exposed credentials, and monitoring for secondary attacks. Ransomware resilience increasingly depends on limiting data theft and downstream identity abuse, rather than relying solely on restoring encrypted machines.