Berlin’s city administration confirmed on August 31, 2026 that data was stolen in a ransomware intrusion, three weeks before the German capital elects its state parliament.

The Rhysida ransomware group claims it exfiltrated 5.79 TB across roughly 1.44 million files from Berlin’s administrative network, and has demanded 30 bitcoin — close to $2.3 million at current rates — with a countdown before it begins publishing.

Berlin’s answer, from Mayor Kai Wegner and Interior Senator Iris Spranger in a joint statement: “The state of Berlin will not submit to extortion.”

The intrusion timeline

The compromise ran from August 7 to August 12, 2026, affecting Berlin’s city administration and the Senate Department for Mobility, Transport, Climate Protection and the Environment. The affected departments were disconnected from the state network on August 14.

Rhysida’s entry method has not been disclosed. Officials note the investigation is ongoing and the full extent of the theft is undetermined — meaning the confirmed scope may yet move in either direction from the attacker’s claim.

State Criminal Police, prosecutors, and federal security agencies are investigating.

What Rhysida says it holds

The claimed inventory is unusually broad even by the standards of government ransomware victimology:

  • Government, legal, financial, contractual, and HR records
  • Plaintext credentials and password vaults
  • 148 IBANs and thousands of names, email addresses, and phone numbers
  • Personnel files and payroll information
  • Identity documents and material described as classified
  • Over 3,200 nondisclosure agreements
  • Critical-infrastructure assessments of Berlin’s water supply

Two items on that list are categorically different from the rest.

Plaintext credentials and password vaults turn a data theft into a persistent access problem. If credential material for state systems is in the archive, the incident does not end when the leak is published — every account represented in that data is a live re-entry path until it is rotated, and rotating credentials across a state administration’s full system estate is a months-long undertaking that has to happen while the systems remain in service.

Critical-infrastructure assessments of the water supply are not extortion leverage in any commercial sense; no ransom pricing model values them. They are, however, precisely the material a state actor conducting pre-operational reconnaissance against European water infrastructure would want, and they will be free to anyone who wants them the moment the leak site publishes. The trajectory of water-sector targeting through 2026 — including the joint NSA/FBI advisory on AI-assisted PLC exploitation against water systems earlier this month — makes that a genuinely consequential secondary harm from a financially motivated crime.

The election timing

Berlin votes for its House of Representatives on September 20, 2026. An attack on state government systems in mid-August, disclosed at the end of August, with a publication countdown running into September, sits directly on top of that.

Spranger says there is no evidence election data was compromised, and that the technical environment supporting the election is considered secure. German state elections run on paper ballots with manual counting, which structurally limits what a network intrusion can do to the vote itself.

The exposure is not to the count. It is to the information environment around it. A 5.79 TB dump of state government material released in the first half of September gives anyone who wants it a large volume of authentic-looking internal documents to mine, quote selectively, or salt with fabrications in the final weeks of a campaign. The 2017 Macron leaks demonstrated the template: the value of a government document dump in an election period is not what it proves, it is that its sheer volume makes verification impossible on the timeline that matters.

Whether Rhysida intends that outcome is doubtful. Rhysida is a financially motivated ransomware-as-a-service operation with a long record of hitting public sector and healthcare targets — the British Library, Insomniac Games, Chilean Army systems, multiple US municipalities and hospitals. The election proximity is best read as pressure engineering: the group understands that a government facing an election has an unusually strong incentive to make a problem disappear quickly.

Berlin declined to pay anyway, which is the right answer and the one that makes the next three weeks harder.

Why “we won’t pay” is still the correct call

The reasoning holds even with the water-infrastructure material in play:

  • Payment does not delete data. It buys a promise from a criminal enterprise not to publish, and follow-on extortion of previously-paid victims is well documented across the ecosystem.
  • A government that pays becomes a priority target. The signal propagates to every affiliate immediately.
  • The credential rotation and infrastructure review have to happen either way. Paying does not remove a single item of remediation work.

What paying would buy is time — and the fact that Berlin refused it means the remediation clock is now the only thing standing between the city and publication.

The practical work now

For Berlin, and for every public administration reading this as a preview:

Rotate everything, on the assumption that the vault claim is true. Credential material in an exfiltration archive should be treated as compromised regardless of whether the attacker has demonstrated it.

Notify the individuals in the payroll and personnel files ahead of publication. GDPR obligations are running, and Rhysida has explicitly used GDPR exposure as pressure. Getting notification out ahead of the leak is both compliance and damage control.

Brief the water utility operators directly and immediately. The infrastructure assessments concern facilities Berlin does not itself operate. Those operators need to know what is about to become public about their systems before it becomes public.

Segment the state network as if this will recur. The intrusion moved from an entry point to a Senate department and required disconnecting departments from the state network to contain — which describes a flat enough environment that containment meant amputation.

Rhysida’s countdown runs into September. Berlin’s election is on the 20th.

Sources

Rhysida’s claims regarding data volume and contents are the threat actor’s own; Berlin has confirmed data theft occurred but not the scope.