On 4 September 2026, shortly after an auction deadline expired at 15:35 local time, the Rhysida operation published the first package of data taken from Berlin’s state administrative network: about 1.44 million files. A second package containing access credentials followed on 6 September. The exfiltration had run from 7 to 12 August. Two Senate departments, for transport and environment and for urban development and housing, were disconnected from the network on 14 August and stayed offline for more than a week.
Rhysida had listed the city on 28 August with a minimum bid of 30 bitcoin, about €2 million. Governing Mayor Kai Wegner said Berlin would not be blackmailed. The Senate chancellery confirmed the refusal on 3 September. The volume was put at 5.79 terabytes by the attackers, 5.26 by one monitoring firm, and at least 755,121 files were confirmed accessible by the consultancy HiSolutions.
What A State Administration’s File Share Holds
Reporting of the published contents lists 46,522 contracts, 5,941 credential files, about 80,000 administrative-offence proceedings, personnel records, geodata, emergency and CBRN plans and bank account numbers. Election infrastructure was reported unaffected. The corpus filed at 26-0825 what a state register nobody can leave means for the people in it; here the register is a city’s, and the 80,000 proceedings are residents who did not choose to be in a Senate department’s files.
The Refusal, Priced
The corpus recorded at 22-1024 what followed when Medibank refused and at 24-0624 when the NHS declined. The pattern holds. Refusal is the right policy for a government, the data is published, and the people in it absorb the cost while the institution keeps its principle. Berlin promised risk-based notification of affected persons under the GDPR and urged citizens to file police reports, which is the shape of the remedy available.
The Way In
HiSolutions, citing the federal cybersecurity agency, reported the initial access as a fake-CAPTCHA campaign in the ClickFix family, in which a user is instructed to paste a command. The same technique appears in the Brevo file at 26-0914 the following week, delivered from a different direction. Attribution to Rhysida rests on the group’s own listing and on reporting from security circles; Berlin officials have not named the group in public. The Berlin criminal police and prosecutors are investigating.
Compiled from the Senate chancellery’s statements, HiSolutions’ analysis and contemporaneous German and English reporting, listed below. Volume figures differ by source and are given with theirs. The contents list is from reporting of the published data, not from inspection. Attribution is the leak-site listing plus reporting. Graded high. Corrections: corrections@forensicpost.com.
- 30 Bitcoin or leak: ransomware gang extorts Berlinheise
- Rhysida Publishes Berlin Government Data After €2m ExtortionInfosecurity Magazine
- Aktuelle Lage nach dem IKT-Vorfall im Landesnetz BerlinSenatskanzlei Berlin
- Cyberangriff auf das Berliner LandesnetzHiSolutions Research