On 7 August 2026, an official inside Berlin's Senate Department for Mobility, Transport, Climate Protection and Environment noticed data leaving the department's systems and flagged it internally. The department did not isolate its network connection. According to Berlin's own account of the incident, the outflow continued for six more days, while a second Senate department lost data over the same window. The city-state, which governs one of Germany's sixteen federal states, did not disconnect the affected departments from its network until 14 August, a full week after the first internal signal that something was wrong.
Berlin publicly disclosed the compromise on 17 August, three days after isolation, saying forensic investigators had confirmed a breach of the state administrative network. At a press conference on 19 August, Governing Mayor Kai Wegner said the incident was serious but that, based on information available at the time, no sensitive data had left the network, an assessment later work would contradict. All Senate departments were reconnected on 23 August, with scanning and investigation continuing. On 28 August, the ransomware group Rhysida posted an entry to its dark web leak site titled simply "Berlin, Germany," claiming to have stolen 5.79 terabytes of data across roughly 1.44 million files.
Rhysida's own account of what it took, reportedly, is extensive: personal data on 12,076 individuals, including more than 16,000 email addresses and 148 bank account numbers; more than 5,000 personnel files and 5,000 administrative-offence files; payroll and leadership records; plaintext passwords and credentials for internal systems, including privileged Z_ADMIN accounts; disciplinary proceedings, court documents and parliamentary committee protocols; passports and identity cards drawn from personnel files; and vulnerability analyses of Berlin's water supply. Officials have not independently confirmed the scope or contents the group describes. Berlin has refused to negotiate. "The state of Berlin will not submit to extortion," Mayor Wegner and Interior Senator Iris Spranger said in a joint statement, a position that aligns with longstanding guidance from the FBI and CISA against paying ransomware demands.
The timing compounds the exposure. Berlin elects its state parliament on 20 September, weeks after the breach became public, and officials have had to publicly reassure voters that no election-related systems or data were touched. Rhysida is not a new entrant: the group has claimed roughly 280 victims since 2023, including the British Library, Chile's army and, closer to home, the city of Stuttgart earlier this year. Housing benefit applications and payments across the two affected departments were unavailable for the sixteen days the network was down, an operational cost layered on top of whatever the stolen data ultimately enables.
The defences that failed here were not weak by conventional standards. Berlin's state government runs security operations, a state data protection commissioner and access to Germany's federal cybersecurity agency, all of which were engaged once the breach was confirmed. What it did not have was a control that stopped the exfiltration itself once someone inside the department had already noticed it happening. The published federal advisory on Rhysida's tradecraft describes a group that typically gets in through compromised VPN credentials at organisations without multi-factor authentication, an unpatched Zerologon vulnerability, or plain phishing, none of them exotic. Berlin has not disclosed which route was used against it. What is known is that the gap between the first internal flag and network isolation ran to six days, and that the data reportedly taken during that window included credentials for privileged administrative accounts.
A bulk export of files at the volume Rhysida describes, gigabytes moving out of a government network inside a compressed window, is an execution event. Before a transfer of that size and shape is allowed to leave a monitored system, GoFirm sends a real-time push notification to the named security authority responsible for that network, on their registered device, requiring biometric confirmation before the transfer proceeds. The same control applies to the privileged Z_ADMIN-style credentials Rhysida claims to have taken: before those accounts can authenticate from an unrecognised session, the named administrator must confirm biometrically, out of band, that the login is theirs.
An attacker holding a valid password, a cloned VPN session or a Zerologon-derived token has none of that. A stolen credential, however convincing it looks to the system reading it, cannot produce a live biometric confirmation on the named administrator's own device through a separate channel. The execution boundary holds regardless of how the credential was obtained.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Khandelwal, S. 2026. Berlin refuses to pay hackers who stole data from the city's state network. The Hacker News, 28 August 2026.
2. Paganini, P. 2026. Rhysida ransomware group targets Berlin government ahead of vote. Security Affairs, 29 August 2026.
3. CISA, FBI, MS-ISAC. 2023. #StopRansomware: Rhysida ransomware. CISA Advisory AA23-319A, 15 November 2023.
Back to Blog
Case Studies·4 min read
Berlin's staff flagged the data leaving on day one. The network stayed live for six more days.
By GoFirm
