Berlin Refused Rhysida’s Ransom and the Leaks Kept Coming
Update, 6 September 2026: Berlin says Rhysida published a further package of stolen data overnight. The city’s Senate Chancellery confirmed that the later release contained access credentials, forcing additional safeguards that may cause short-term restrictions to public services.
The Leak Did Not Stop With the First Data Dump
This follows the first publication of data stolen during the ransomware incident. Security authorities and contracted forensic specialists are examining the material, while a central crisis response coordinates verification, containment and notifications to affected people and organisations.
The presence of access credentials changes the immediate operational risk. Berlin has not published a complete credential inventory, but defenders cannot wait for one before rotating exposed secrets, reviewing privileged sessions and checking whether the leaked material can support follow-on access.
Berlin also warned that additional protective measures may temporarily restrict services. That is not merely a recovery inconvenience. It shows how a data leak can force new containment work after systems are restored, especially when published files may reveal credentials or internal operating details.
Rhysida advertised 5.79 TB and roughly 1.44 million files. Berlin has confirmed publication and the presence of credentials in the later package, but it has not independently confirmed the full volume, file count, completeness or every category claimed by the criminals.
What defenders should do with the new evidence
- Rotate credentials based on plausible exposure, including service accounts, recovery codes and administrative secrets.
- Review authentication logs for use of credentials that appeared in the affected environment.
- Warn finance and procurement teams about supplier impersonation, invoice fraud and requests to change payment details.
- Keep Berlin’s confirmed facts separate from Rhysida’s claims about archive size and content.
- Prepare risk-based notifications that explain the exposed data, likely misuse and specific protective actions.
Update sources
- State of Berlin: further data publication after the cyberattack, published 6 September 2026 at 18:03 Europe/Berlin.
- Reuters: Berlin launches crisis response after hackers publish stolen data, published 5 September 2026.
Berlin has confirmed that attackers stole data from a Senate department and attempted to extort the city. Officials refused to pay. The Rhysida ransomware group now claims it took 5.79 TB containing 1.44 million files, but the gang’s inventory has not been independently verified.
The distinction is essential. The Berlin government has confirmed a cyber incident, data theft and an extortion attempt. It has not confirmed every category or quantity advertised by the criminals.
What Berlin has confirmed
Berlin’s Senate Chancellery said unauthorised access affected the Senate Department for Mobility, Transport, Climate Protection and the Environment. The incident led to data being removed from the department’s systems and used in an extortion attempt.
The city said it would not pay a ransom. Berlin’s State Criminal Police Office, public prosecutors and federal agencies are investigating. Officials have not published a final count of affected files, people or systems, and the investigation remains active.
Berlin also said there was no evidence that election data was affected. That statement narrows one politically sensitive risk, but it does not settle the broader scope of the stolen administrative information.
What Rhysida claims
Rhysida claims the archive contains 5.79 TB across roughly 1.44 million files. The group has described material involving payroll, password vaults, 148 IBANs and government, legal, financial, infrastructure, health, mapping and water-security information.
Those are attacker claims, not an official breach inventory. Criminal groups have an incentive to exaggerate volume, sensitivity and completeness to increase pressure on victims and attract buyers. Samples or filenames can demonstrate access to some material without proving the advertised archive is complete.
The risk extends beyond leaked documents
Administrative datasets become more dangerous when combined. Payroll records can support employee impersonation. IBANs and supplier information can make payment-redirection attempts more convincing. Mapping and infrastructure documents may reveal operational relationships that are not obvious from public sources.
Password-vault material would be especially consequential if it contains active credentials, recovery codes or export files. Berlin has not confirmed that such material was stolen, so defenders should not treat the claim as fact. The claim is still important enough to justify targeted credential rotation and access review while the investigation continues.
Refusing payment does not end the incident
Berlin’s refusal removes one source of profit, but it does not retrieve the data. Extortion groups can publish information, sell access, approach employees or partners directly and reuse stolen relationship data for fraud.
The practical response therefore has two tracks. Investigators need to determine how the attackers entered, what they accessed and whether persistence remains. At the same time, affected departments must prepare for secondary abuse of identities, supplier relationships, payment details and internal documents.
What organisations should learn
- Separate confirmed facts from criminal claims in every stakeholder update.
- Rotate credentials based on likely exposure, not only on proof that a complete vault was stolen.
- Warn finance and procurement teams about supplier impersonation and payment-detail changes.
- Monitor for direct contact with employees, contractors and affected partners.
- Preserve evidence before rebuilding systems or restoring large data sets.
- Review whether sensitive administrative files were concentrated in locations with overly broad access.
The BlackTree view
The headline number is 5.79 TB, but the strategic issue is trust. A city government coordinates payments, infrastructure, staff and public services through records that attackers can reuse long after systems are restored.
Berlin’s refusal to pay is a defensible position. It also makes transparent scoping and rapid notification more important. The public needs to know which claims are verified, which remain criminal advertising and which defensive actions should happen before that uncertainty is resolved.
Sources
- State of Berlin press release on the cyberattack and data theft, published 28 August 2026. The primary source provides a date but no publication time.
- BleepingComputer: Berlin confirms data theft after Rhysida ransomware attack claims, published 31 August 2026 at 09:30. The page does not display a timezone.


