Berlin’s administration has confirmed that it is being extorted after the Rhysida ransomware group claimed to have stolen data from the city’s computer network.
The attack was detected in mid-August and publicly claimed by the gang on Friday August 28. Berlin mayor Kai Wegner has said the city will not pay a ransom.
The State Criminal Police Office, the public prosecutor’s office and federal security agencies are investigating the breach. Officials have warned that the full scale of the incident has not yet been established.
Rhysida claims 5.79TB of stolen data
Rhysida alleges that it removed about 5.79 terabytes of information, consisting of roughly 1.44 million files. The group has threatened to publish the material and is using alleged breaches of data-protection rules to pressure the Berlin government.
The alleged haul includes government, legal, financial, contractual, human resources, health, infrastructure and mapping records. The gang also claims to possess personal details including names, email addresses and telephone numbers, as well as 148 IBANs.
Other material allegedly taken includes personnel and payroll files, email archives, identity documents, SQL database dumps, banking information and records relating to disciplinary proceedings. Rhysida also claims to have obtained plaintext credentials, database accounts, payment-system data, password-vault information and credentials belonging to senior officials.
The list published by the attackers includes more than 3,200 documents marked as non-disclosure agreements. It also refers to allegedly classified or sensitive government records, including Bundesrat committee documents and information about the handling of classified material.
Among the most sensitive claims are security assessments concerning Berlin’s water supply. The group gave the city four days to pay before threatening to release the stolen files.
Election systems said to be secure
Forensic investigators said data was also taken from Berlin’s Senate Department for Mobility, Transport, Climate Protection and the Environment, probably between August 7 and 12. The affected Senate departments were disconnected from the state network on August 14.
Senator Iris Spranger said officials had found no evidence that election data was compromised. The technical systems supporting the forthcoming Berlin House of Representatives election are considered secure, she said.
Authorities have not disclosed how Rhysida gained access to the network. The ransomware group, which has been active since 2023, has previously targeted healthcare organisations, government bodies, educational institutions and critical infrastructure.
The investigation remains under way, and Berlin has yet to determine precisely what information was accessed or removed.
