The Rhysida ransomware group has claimed a major breach of Berlin’s state government network, posting a listing on its Tor leak site on August 28 that asserts 5.79 TB of stolen data across roughly 1.44 million files. Berlin’s government has confirmed data theft from at least two Senate departments and says it will not pay the group’s 30 BTC (~$2.3 million) ransom demand — but the incident’s real lesson for infrastructure defenders is in the timeline, not the ransom math: forensic investigators found exfiltration occurred between August 7 and 12, while the affected network segment wasn’t isolated until August 14 — a full week after internal detection.

What Happened

Berlin’s Senate Department for Mobility, Transport, Climate Protection and Environment, along with a second department, sit on the Berliner Landesnetz — a shared connectivity backbone linking roughly 600 administrative and public-sector locations across the city-state. That shared-network architecture is the crux of the incident: when one segment is compromised, containing it requires either automated micro-segmentation or a manual authorization chain running through the bureaucracy that operates the network. Berlin relied on the latter, and the decision chain took seven days from initial internal flagging to actual isolation.

The suspected initial access vector, per multiple outlets citing Berlin officials, involves compromised remote-access credentials — VPN or an externally exposed remote service — though the government has not published a confirmed attack chain or a CVE. There is no evidence of a specific unpatched vulnerability driving initial entry; this reads as a credential-and-remote-access compromise rather than an exploit-based intrusion.

Notably, Rhysida appears to have prioritized exfiltration over encryption: the group pulled data and left rather than deploying an encryptor across the estate, which is consistent with the double-extortion playbook favoring publication threats over operational disruption when the target is unlikely to pay for a decryptor.

Data Exposed

Rhysida’s claimed breakdown, per its leak-site listing: 124,823 mapping/geodata files, 77,939 legal and complaint files, 55,553 financial files, 46,522 contracts, 27,299 HR files, 13,142 government supervisory files, and 8,110 infrastructure files — the last category reportedly including vulnerability assessments of Berlin’s water supply system. The group also claims plaintext credentials, 16,389 email addresses, 11,963 phone numbers, and personal data tied to 12,076 named individuals, along with 148 IBANs.

Berlin’s government has not independently verified Rhysida’s figures but has stated it cannot rule out that personal and non-public data was included in what was taken. Given the infrastructure-vulnerability-assessment claim, defenders should treat this less as a generic PII breach and more as a potential targeting dataset for follow-on attacks against municipal water systems — the same category of OT target that’s already drawn nation-state-linked intrusion attempts against U.S. water utilities this year.

Who’s Behind It

Rhysida is a Ransomware-as-a-Service operation active since mid-2023, believed to operate primarily out of Russia and Eastern Europe, with a track record of targeting public-sector, healthcare, and education victims — it previously claimed breaches of the British Library and Chilean Army, among others. The group runs a “Vengeance” auction-style leak site: stolen data is offered for sale to the highest bidder if the victim doesn’t pay within the ransom window, which creates a second monetization path even when a target refuses to negotiate.

The timing — roughly three weeks ahead of a Berlin state election — has also been noted by regional reporting as a possible pressure tactic, though there’s no confirmed link between the group and any politically motivated actor; RaaS affiliates are financially, not ideologically, driven in the overwhelming majority of documented cases.

Impact

Direct impact to city services appears limited so far — Berlin has not reported disruption to public-facing systems, consistent with an exfiltration-focused intrusion rather than an encryption event. The bigger exposure is downstream: leaked credentials and personal data enable follow-on phishing and account-takeover against Berlin employees and residents, while the claimed water-infrastructure vulnerability files — if genuine — could inform targeting of OT/ICS assets that are a known priority target for both criminal and state-aligned actors this year.

Mitigation and Response Guidance

For organizations running shared or multi-tenant government/enterprise network backbones:

  • Pre-authorize network isolation playbooks. A seven-day gap between “we saw anomalous outflow” and “we cut the segment off” is the actual root cause here, not the initial access vector. If isolating a compromised segment requires a multi-day approval chain, that chain is your biggest attack-surface item.
  • Deploy automated micro-segmentation or software-defined perimeter controls on shared administrative networks so a single compromised department can be quarantined without a manual, cross-agency sign-off process.
  • Enforce MFA on all VPN and remote-access services, and monitor for anomalous authentication patterns — most Rhysida intrusions documented to date start with abused remote access rather than novel exploitation.
  • Treat any internally-flagged data outflow as presumptively hostile until proven otherwise; the cost of an unnecessary isolation is far lower than the cost of a week of continued exfiltration.
  • If your organization holds OT/ICS vulnerability assessments or infrastructure documentation, store and access-control that category separately from general administrative file shares — it has materially higher downstream risk if leaked than typical HR or contract data.

Berlin has stated it will not pay and is coordinating with the State Criminal Police Office, public prosecutor’s office, and federal security agencies. No public technical incident report or CVE has been published as of this writing.

Sources: Help Net Security, BleepingComputer, The Hacker News, Security Affairs, Tech Times