Nadia Dubois
August 30, 2026
13 min read
Berlin’s state government has become the newest name on a ransomware leak site. The Rhysida ransomware group posted an entry titled simply “Berlin, Germany” on its dark web portal on August 28, 2026, claiming to hold 5.79 terabytes of data lifted from the city-state’s IT network, spanning roughly 1.44 million files. The group is demanding 30 bitcoin, worth close to $2.3 million at current exchange rates, and has set a one-week countdown before it says it will start publishing the trove. Berlin’s Governing Mayor has already said the city will not pay.
The claim, first detailed by German outlet Der Spiegel and corroborated by security researchers tracking the leak site, marks one of the largest ransomware claims against a European government body in 2026. It lands during a year already crowded with government and critical-infrastructure breaches, and it raises a specific worry that has less to do with money than with what the stolen files reportedly contain: judicial documents, emergency response plans, and details tied to critical infrastructure facilities.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What Rhysida is claiming about the Berlin breach
Rhysida’s leak-site listing for Berlin lays out a specific set of numbers designed to pressure the city into paying. According to reporting that reviewed the post directly, the group claims 5.79 TB of data and approximately 1.44 million files, with personal information tied to 12,076 individuals. Separately, coverage citing Der Spiegel puts additional figures on the table: nearly 80,000 administrative fine proceedings, more than 46,500 contracts, and close to 6,000 files that reportedly contain login credentials.
None of these numbers have been independently verified by Berlin’s government at the time of writing. That distinction matters. Ransomware crews routinely inflate file counts and data volumes on their leak sites because the listing itself is a <a href="https://bitcomme.com/5-content-marketing-ideas-for-january-2026/” title=”5 Content Marketing Ideas for January 2026″>marketing tool, meant to maximize pressure on the victim during the negotiation window. Still, the range and specificity of the categories Rhysida describes, from fine proceedings to infrastructure documentation, suggests access that went beyond a single database or mail server.
Berlin officials have confirmed a major cyber incident hit the city-state’s IT environment but have not validated the attacker’s specific terabyte or file counts. That gap between attacker claims and official confirmation is standard in the early days of a ransomware disclosure, and it is one reason security teams treat leak-site numbers as an opening claim rather than a settled fact.
Who is Rhysida, and why does this group keep hitting public institutions
Rhysida has built a reputation for going after hospitals, schools, and government bodies rather than sticking to the corporate targets that dominate most ransomware headlines. The group first drew wide attention with attacks on healthcare providers and, later, a high-profile breach of the British Library in 2023. Since then it has been linked to intrusions against multiple government and public-sector networks across Europe and North America, typically pairing file encryption with data theft and a public leak-site countdown.
The group’s playbook is consistent: gain a foothold, move laterally across a network, exfiltrate whatever looks sensitive, encrypt what remains, and then post a partial description of the haul to a Tor-hosted leak site as proof of access. The Berlin listing follows that pattern closely, right down to the one-week countdown clock that ransomware operators use to compress a victim’s decision-making window.
What makes Rhysida notable within the broader ransomware ecosystem is its preference for targets with limited ability to pay quickly or negotiate quietly, such as municipal governments and public healthcare systems. Those organizations often run on legacy infrastructure, operate under strict procurement rules that slow incident response, and face intense public scrutiny the moment a breach becomes known. That combination has made the public sector an attractive hunting ground for extortion-focused groups over the past three years.
Berlin’s public response: no payment, no negotiation
Berlin’s Governing Mayor has publicly stated the city will not be blackmailed, a position that mirrors the standard guidance from law enforcement agencies across the EU and the United States against paying ransomware demands. That stance is consistent with a broader shift among European government bodies in 2026, many of which have adopted formal no-payment policies as ransomware crews have increasingly targeted the public sector specifically because private companies have hardened their defenses and insurance-backed payment processes.
Refusing to pay does not make the exposure disappear. If Rhysida follows through on its stated deadline, the practical result is that whatever data the group actually holds, whether that matches its stated 5.79 TB or is smaller, will most likely be published or sold. Berlin’s government has indicated it is treating the incident as a major cyber event, engaging incident response and working through the notification obligations that come with a breach of this scale under EU data protection rules.
The no-payment stance also puts pressure on Berlin’s technical teams to demonstrate, quickly and credibly, what was actually accessed. Distinguishing between attacker-claimed volume and confirmed exposure is central to any breach notification process under GDPR, which requires proportionate disclosure to both regulators and affected individuals once the scope is understood.
Timeline of the Berlin ransomware incident
| Date | Development |
|---|---|
| Prior to Aug. 28, 2026 | Rhysida gains access to Berlin state government IT network; scope of intrusion not yet publicly detailed |
| Aug. 28, 2026 | Rhysida posts a leak-site entry titled “Berlin, Germany,” claiming 5.79 TB of data and roughly 1.44 million files |
| Aug. 28-29, 2026 | German media, including Der Spiegel, report a 30 bitcoin ransom demand and additional data-category figures (fine proceedings, contracts, credential files) |
| Aug. 29, 2026 | Berlin’s Governing Mayor states publicly that the city will not pay the ransom |
| Aug. 29-30, 2026 | International security press picks up the claim; Berlin authorities confirm a major cyber incident without validating exact attacker-supplied figures |
| Ongoing | Rhysida’s stated one-week countdown continues toward a threatened publication of the stolen files |
What kind of data is reportedly at risk
The categories Rhysida and German media have described point to a wide cross-section of municipal government activity rather than a single narrow system. Administrative fine proceedings, reported at close to 80,000, would typically include names, addresses, and case-specific financial details tied to individuals who have interacted with city enforcement processes. More than 46,500 contracts would likely cover vendor relationships, procurement terms, and potentially commercially sensitive pricing information tied to the city’s suppliers.
The reported presence of nearly 6,000 files containing login credentials is arguably the most operationally dangerous element of the claim. Credential files, if genuine and unencrypted or weakly protected, could allow further lateral movement inside Berlin’s network or attacks against other systems that share reused passwords, well after the initial ransomware incident is contained. Security researchers who track ransomware leak-site listings generally flag credential exposure as a higher near-term risk than static PII, because credentials can be weaponized immediately rather than requiring downstream fraud.
Reports also describe judicial documents and information tied to critical infrastructure facilities among the claimed haul. If accurate, that detail pushes this incident beyond a conventional data-privacy story and into the territory of operational security risk for physical infrastructure, a category regulators increasingly treat as a distinct and more serious tier of exposure under frameworks such as the EU’s NIS2 directive.
Reported breach scope at a glance
| Metric | Rhysida’s claimed figure |
|---|---|
| Total data volume | 5.79 TB |
| Files claimed exfiltrated | ~1.44 million |
| Individuals with exposed PII | 12,076 |
| Administrative fine proceedings | ~80,000 |
| Contracts claimed stolen | 46,500+ |
| Files reportedly containing credentials | ~6,000 |
| Ransom demand | 30 BTC (~$2.3 million) |
| Stated deadline before publication | One week from the Aug. 28 leak-site post |
These figures should be read as attacker-supplied claims pending independent confirmation by Berlin authorities, consistent with how ransomware leak-site postings are typically treated by incident responders and journalists before a victim organization completes its own forensic review.
Why government IT networks keep losing to ransomware crews
Municipal and state IT environments share a set of structural weaknesses that make them disproportionately attractive to ransomware operators. Budgets for public-sector IT security typically compete against a long list of other civic priorities, and procurement cycles for new security tooling or infrastructure upgrades can stretch across multiple budget years. That slow pace leaves legacy systems running well past their supported lifespan, often the exact software versions that ransomware crews have automated tooling to exploit.
Government networks also tend to be sprawling and federated, spanning dozens of departments, agencies, and services that were built or acquired at different times with different security standards. That fragmentation makes network segmentation, one of the most effective defenses against ransomware spreading laterally after an initial foothold, difficult to implement consistently across an entire city-state’s technology footprint.
Finally, public bodies operate under intense transparency and accountability requirements that private companies do not face in the same way. A city government cannot simply decline to comment or delay disclosure the way some private firms attempt to; elected officials answer to voters and regulators on a compressed timeline, which paradoxically gives ransomware crews more leverage. The public pressure that follows a leak-site posting, coupled with the political cost of appearing unable to protect citizen data, is precisely the dynamic groups like Rhysida are counting on when they choose government targets.
How the Berlin claim compares with other 2026 ransomware disclosures
2026 has already produced a string of large ransomware and extortion claims against both public and private organizations. Earlier this month, the Qilin ransomware group claimed responsibility for a breach at the US Bureau of Alcohol, Tobacco, Firearms and Explosives; a federal agency spokesperson later confirmed a system holding investigation-related information had been accessed, though the exact record count was not disclosed publicly. Around the same period, the ShinyHunters extortion group claimed a breach tied to Abbott, alleging roughly 10.9 million email addresses were exposed through a vishing-driven intrusion.
The Cl0p ransomware group also drove one of the year’s broader campaigns, exploiting a vulnerability in PTC’s Windchill software to hit multiple industrial and healthcare-adjacent firms including Shell, GE, and Philips through a shared software supply chain rather than direct network intrusions at each company. What separates the Berlin case from many of these is the target type. Most of 2026’s headline breaches have hit private companies or federal agencies; a full state or city government IT network being claimed wholesale, with judicial and infrastructure-adjacent documents allegedly in scope, is a less common and arguably more consequential category of incident.
The ransom figure itself, 30 bitcoin, sits in the mid-range for 2026 extortion demands, well below the eight- and nine-figure demands reported against larger private-sector victims this year but still a meaningful sum for a municipal budget already stretched across other obligations. Ransomware negotiation trackers have generally noted that public-sector ransom demands tend to be set lower than private-sector demands, reflecting both a lower expected payout probability and the smaller revenue base of government targets compared to large corporations.
The regulatory angle: GDPR and NIS2 exposure
Any confirmed exposure of the 12,076 individuals’ personal data that Rhysida claims to hold would trigger notification obligations under the EU’s General Data Protection Regulation, which requires affected authorities to report qualifying breaches to a data protection regulator within 72 hours of becoming aware of them, and to notify affected individuals directly when the breach is likely to result in a high risk to their rights and freedoms.
The reported presence of critical-infrastructure-related documents adds a second regulatory layer. The EU’s NIS2 directive, which expanded cybersecurity obligations across a wider range of public administration bodies and essential-service operators starting in 2024, sets stricter incident reporting timelines and risk-management requirements for entities whose systems touch critical infrastructure. If any portion of the claimed haul genuinely includes infrastructure-facility information, Berlin’s government would likely need to coordinate disclosure and remediation across both GDPR-focused data protection authorities and NIS2-aligned cybersecurity regulators simultaneously, a more complex compliance path than a typical corporate data breach.
What comes next for Berlin and for other public-sector targets
The immediate question is whether Rhysida follows through on its one-week publication threat once the deadline passes without payment. Ransomware groups do not always publish everything they claim to hold; some quietly extend deadlines to keep pressure alive, while others release only a fraction of the claimed data as proof before losing interest once it becomes clear a victim will not pay. Berlin’s forensic teams will spend the coming weeks working to establish which of Rhysida’s specific figures, the 5.79 TB, the 1.44 million files, the 12,076 individual records, actually match what left the network, a process that in comparable government breaches has historically taken several weeks to months to fully resolve.
For other municipal and state governments watching this unfold, the incident is likely to accelerate conversations already underway about ransomware-specific incident response planning, network segmentation between administrative and infrastructure-adjacent systems, and mandatory credential rotation policies for accounts with access to sensitive document repositories. Public-sector CISOs across Europe have increasingly cited peer government breaches, rather than private-sector incidents, as the trigger that finally secures budget approval for security modernization projects, a shift also reflected in the wave of AI-driven cyberattack warnings that pushed cybersecurity stocks up sharply earlier this year.
Predictions: where the Berlin ransomware case likely heads
- Rhysida will likely publish at least a portion of the claimed data once its stated deadline lapses, both to preserve its credibility with future victims and to maintain leverage in case Berlin reconsiders its no-payment stance.
- Berlin’s officially confirmed figures, once forensic review completes, will probably land below Rhysida’s claimed 5.79 TB and 1.44 million files, consistent with the pattern seen in most large ransomware leak-site claims over the past two years.
- Expect German and EU regulators to open a formal review of Berlin’s incident response under both GDPR and NIS2 frameworks, given the mix of personal data and infrastructure-adjacent documents reportedly involved.
- Other German states and municipalities will likely announce accelerated cybersecurity budget requests in the coming months, citing the Berlin incident directly as justification.
- Rhysida is likely to continue targeting public-sector and healthcare organizations through the remainder of 2026, following the group’s established pattern of favoring victims with limited negotiating leverage over private companies with mature security operations and cyber insurance backing.
What Berlin residents and city employees should do now
Until Berlin’s government confirms the specific scope of exposed data, residents and employees whose information may have passed through city systems, including anyone with an administrative fine record, active municipal contract, or city employment history, should treat unexpected calls, emails, or texts referencing those interactions with heightened suspicion. Ransomware-linked data theft frequently feeds follow-on phishing and social engineering campaigns in the weeks after a leak-site posting, since stolen records give scammers convincing, specific details to reference.
City employees whose credentials may be among the roughly 6,000 files Rhysida claims to hold should assume password rotation and multi-factor authentication enforcement will be mandated across affected systems as part of Berlin’s remediation process, a standard step in ransomware incident response regardless of whether the exact credential count is ultimately confirmed.
The bigger picture for public-sector cybersecurity in 2026
The Berlin incident lands in a year where ransomware groups have increasingly treated public institutions as a preferred target class rather than an occasional opportunistic hit. The combination of legacy infrastructure, fragmented IT governance, compressed disclosure timelines driven by political accountability, and a general reluctance to pay that nonetheless does not stop the initial intrusion, has made cities, states, and federal agencies a recurring feature of ransomware leak sites throughout the year, a pattern also visible in the FulcrumSec extortion claim against Manchester Airports Group and in MAG’s own refusal to pay a ransom demand after its three-airport breach, a stance Berlin has now echoed. Groups tracking ransomware payment trends, including Chainalysis and Coveware, have both noted a continued shift toward public-sector and mid-market targets in 2026 as larger enterprises harden defenses.
What distinguishes the Berlin case is less the ransom amount, which is modest by 2026 standards, and more the described breadth of the claimed data: judicial records, infrastructure documentation, tens of thousands of contracts, and administrative case files all reportedly sitting within reach of a single intrusion. If those categories hold up under Berlin’s own forensic review, the incident will likely become a reference case for how European governments think about network segmentation between citizen-facing administrative systems and the infrastructure-adjacent data that increasingly lives alongside them on the same networks. Security researchers have long recommended the segmentation and zero-trust principles outlined in the NIST Cybersecurity Framework as a baseline for exactly this kind of federated, multi-department network.
Frequently asked questions
What is Rhysida?
Rhysida is a ransomware and extortion group that has targeted healthcare providers, libraries, and government networks since 2023, pairing data theft with encryption and leak-site pressure campaigns. Background on the group’s history is tracked publicly, including on Wikipedia’s entry on the group.
How much data does Rhysida claim to have stolen from Berlin?
The group’s leak-site posting claims 5.79 terabytes of data across roughly 1.44 million files, including personal information tied to 12,076 individuals, according to reporting that reviewed the listing.
How much ransom is Rhysida demanding?
Reports citing Der Spiegel put the demand at 30 bitcoin, worth roughly $2.3 million at current exchange rates, with a one-week deadline before Rhysida says it will publish the data.
Has Berlin’s government confirmed these numbers?
Berlin has confirmed a major cyber incident but has not publicly validated Rhysida’s specific terabyte, file, or record counts, which remain attacker-supplied claims pending forensic review.
Will Berlin pay the ransom?
No. Berlin’s Governing Mayor has stated publicly that the city will not be blackmailed, consistent with law enforcement guidance across the EU and US against paying ransomware demands.
What happens if Berlin does not pay before the deadline?
Ransomware groups typically follow through on at least partial publication of claimed data once a stated deadline passes without payment, though some extend deadlines or release only a portion of what they claim to hold.
What regulations apply to this breach?
Any confirmed exposure of personal data would fall under the EU’s GDPR, which requires notification within 72 hours of a qualifying breach. Reported infrastructure-related documents could also bring the incident under the EU’s NIS2 directive, which sets separate cybersecurity and incident-reporting requirements for entities connected to critical infrastructure.
How does this compare to other 2026 ransomware incidents?
The ransom demand is modest compared to the largest 2026 corporate extortion cases, but the claimed scope, spanning judicial records, tens of thousands of contracts, and infrastructure-adjacent data within a single government network, makes it one of the broader public-sector claims of the year.
![Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026] Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026]](https://tech-insider.org/wp-content/uploads/2026/08/rhysida-berlin-government-ransomware-breach-2026-1.webp)