Data Leak
Incident
Rhysida extortion over Berlin administrative network compromise
Updated 31.08.2026 16:30
Case score 79
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 79
- Main story score
- 74
- Related evidence lift
- +5 / 20
- Contributing updates
- 1
- Context updates
- 0
Top contributors
- Data Leak Public leak-site extortion claim with large alleged data theft and sensitive Berlin government exposure. main
- Incident Confirms the underlying compromise, timing, isolation actions, and ongoing investigation for the same Berlin event. contributes
Members 2
First seen 29.08.2026 00:30
Latest activity 31.08.2026 16:30
Overview
Berlin has confirmed a compromise of its **administrative network** and is facing **Rhysida** leak-site extortion after the group publicly posted a Berlin entry on August 28. Available evidence ties related data outflow to mid-August activity, and the public claim asserts **5.79 TB** of data and about **1.44 million files**, including personal information on **12,076 individuals**.
Berlin says it will **not pay** the attacker, affected departments were isolated and later reconnected, and forensic scanning is still underway. Officials say there is no evidence election data was compromised, but the exact scope of stolen material and what may ultimately be published remain unconfirmed.
Latest development Open development history Rhysida leak site posts Berlin, Germany entry A Rhysida darknet leak-site entry titled "Berlin, Germany" was added on August 28 and claimed 5.79 terabytes of data, around 1.44 million files, and personal information on 12,076 individuals; no ransom figure appeared in the entry.
-
Berlin administrative network data leak after Rhysida claim
Rhysida first turned the case into a public extortion matter by posting **Berlin** on its leak site after a **mid-August** discovery of the intrusion. The initial leak-site claim set up the publication threat that now hangs over the city’s administrative network.
-
Berlin cuts the affected department off from the network
The Senate Chancellery said the affected department was cut off from the network on August 14, seven days after the first outflow report.
Attackers using **Rhysida** leak-site extortion are pressuring **Berlin's administrative network** after the city confirmed a compromise and the group posted a public leak claim on August 28. Available evidence places related data outflow in mid-August, with forensic work tying additional exfiltration to August 7-12 and officials isolating affected departments as the investigation widened. Rhysida's leak-site entry identified the victim as **Berlin, Germany** and claimed **5.79 TB** of data and about **1.44 million files**, turning the intrusion into a public publication threat.
The claimed haul spans government, legal, financial, HR, infrastructure, health, mapping, email, database, and credential-related material, including **148 IBANs**, plaintext credentials, password-vault content, SQL dumps, and personnel records. The attackers also asserted that personal information on **12,076 individuals** was involved, but Berlin has not publicly confirmed the full scope of the stolen data or every department named in the leak-site material. Officials have said there is no evidence election data was compromised and that the technical environment for the upcoming Berlin House of Representatives election remains secure.
Berlin says it will **not pay** the attacker, and the State Criminal Police Office, the public prosecutor's office, and federal security agencies are investigating. One affected department was cut off from the network on August 14, all Senate departments were reconnected on August 23, and forensic scanning of the state network has continued. The immediate picture is a confirmed network compromise, an active extortion demand backed by a public leak claim, and unresolved uncertainty over what data was actually taken and what may still be published.
Signals
Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context
Affected surface
Data exposure
Threat actor context
3 listedMalware context
1 familiesTechnical intelligence
Existing Case dataMember happenings
Data Leak
Berlin administrative network data leak after Rhysida claim
Exploit
No Known Public Exploit
Data Type
Passwords
Data Type
Government IDs
Data Status
Claimed/Sample Only
1 more in details
Data Leak
Berlin administrative network data leak after Rhysida claim
Exploit
No Known Public Exploit
Data Type
Passwords
Data Type
Government IDs
Data Status
Claimed/Sample Only
1 more in details
Incident
Berlin's state government hit by data theft breach
Extortion
Data Theft Extortion
Incident
Ongoing
Patch
No Patch
Incident
Berlin's state government hit by data theft breach
Extortion
Data Theft Extortion
Incident
Ongoing
Patch
No Patch