Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
exploitRansomwareWorld

Rhysida Ransomware Attack on Berlin Government

By ogwatermelon
August 31, 2026 5 Min Read
0
August 31, 2026

Berlin’s state government has confirmed that it is the target of a major ransomware and data extortion campaign. Consequently, threat actors claiming affiliation with the Rhysida ransomware group have added the German capital to their public leak site, claiming to have stolen 5.79 terabytes of data. The Senate Chancellery says Berlin will not pay the ransom, and forensic teams are still assessing the full scope of the breach. Data exfiltration occurred between August 7 and August 12, 2026, with the attackers leveraging the city’s state administrative network for an estimated week before detection.

What Happened: Rhysida Ransomware Group Targets Berlin State Government

Berlin disclosed the cybersecurity incident on August 17, 2026, when the Senate Chancellery confirmed that two departments had been isolated from the state administrative network following the discovery of unauthorized access. Furthermore, forensic work subsequently established that data had been exfiltrated over a five-day window between August 7 and August 12. The Senate Department for Mobility, Transport, Climate Protection and Environment was among the portfolios with confirmed data outflows during that period.

The scope of the breach only became public on August 28, 2026, when a Rhysida-linked leak site post appeared naming “Berlin, Germany” as a victim. The post, indexed by ransomware live-monitoring services, claimed 5.79 terabytes of data and approximately 1.44 million files were stolen. File categories in the posting included maps, geodata, and administrative records. No ransom figure was published in the Rhysida entry. Der Spiegel subsequently identified Rhysida as the group responsible, citing security sources involved in the response.

Governing Mayor Kai Wegner convened a special Senate session and confirmed that Berlin would not negotiate with or pay the extortionists. Interior Senator Iris Spranger stated that the election environment for the September 20 Abgeordnetenhaus vote remains secure and that no data is believed to have left the areas relevant to the election. All Senate departments were reconnected to the state network on August 23, though forensic work and full network scanning remain ongoing.

Technical Details of the Berlin Ransomware Attack

Rhysida is a ransomware-as-a-service operation that first appeared in 2023 and has since been linked to the financially motivated threat cluster formerly associated with the Vice Society ransomware group. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) issued a joint advisory (AA23-319a) documenting Rhysida’s established routes for initial access. These include:

  • Valid accounts on external-facing remote services, particularly VPN access points without multi-factor authentication (MFA) enabled by default
  • Zerologon (CVE-2020-1472), a privilege-escalation vulnerability in Microsoft’s Netlogon Remote Protocol that Microsoft patched in August 2020 but which continues to be exploited in unpatched environments
  • Phishing campaigns that serve as an entry point into victim networks

Rhysida’s double-extortion model involves encrypting victim systems and threatening to publish stolen data if a ransom is not paid. The group does not publish a standard ransom demand publicly in all cases; instead, private negotiations occur between the operators and the victim organization. The publication of the Berlin entry on the leak site followed this pattern, with the group apparently choosing to list the victim publicly after the initial disclosure rather than including a stated demand in the post.

The attack on Berlin’s state network is consistent with Rhysida’s pattern of targeting government and critical infrastructure entities. According to ransomware.live monitoring data, Rhysida has listed 280 victims as of late August 2026, nine of them in Germany, including the Stuttgart city administration in May 2026 and the aid organization Welthungerhilfe in June 2025. The Port of Seattle, operator of Seattle-Tacoma International Airport, was also listed in September 2024.

Business and Operational Impact

The Berlin ransomware incident caused significant disruption to state government operations. The practical consequences included:

  • Housing benefit applications and payments were unavailable while the two affected departments remained isolated from the state network
  • Multiple Senate departments were taken offline as a precautionary measure between August 14 and August 23
  • Forensic investigation and network scanning are ongoing, with the full scope of data exposure still being determined
  • The Senate Chancellery has acknowledged that personal or non-public data cannot be excluded from the exfiltrated material
  • As of late August, Berlin’s state data protection commissioner had not issued public guidance to affected individuals

The Rhysida leak site post identified eleven file categories, the largest of which contains 124,823 maps and geodata files. Combined, the listed categories account for approximately a quarter of the total file count claimed by the attackers. The discrepancy between the claimed 5.79 terabytes and the itemized categories suggests the full inventory of stolen data has not yet been publicly disclosed by the threat actors.

Mitigation and Recommendations

Organizations can take concrete steps to defend against Rhysida-style attacks. The CISA-FBI-MS-ISAC advisory recommends prioritizing remediation of known exploited vulnerabilities and enabling MFA across all external-facing services as foundational controls.

Immediate Actions for Defenders

  1. Audit all external-facing services for valid accounts and enforce MFA, particularly on VPN gateways and remote desktop solutions
  2. Apply the CVE-2020-1472 (Zerologon) patch immediately; this vulnerability remains a documented Rhysida entry vector despite being three years patched
  3. Review authentication logs for unusual geographic patterns, particularly on privileged accounts
  4. Segment networks to prevent ransomware spreading between departments and systems
  5. Implement phishing-resistant authentication for email and identity providers

Government and Critical Infrastructure Organizations

State and local government entities should apply particular scrutiny to inter-departmental network trust relationships. Berlin’s attack demonstrated how compromise of one department’s network can expose data from other portfolios. Treat TACACS, jump hosts, and network management infrastructure as first-class forensic assets. Monitor for unusual outbound data transfers and implement data loss prevention controls on sensitive file categories such as maps, geodata, and administrative records.

Bottom line: The Berlin government breach shows that ransomware groups continue to target government networks successfully, often leveraging known vulnerabilities and weak authentication on external services. Applying patches, enforcing MFA on all remote access paths, and segmenting networks remain the most effective defenses against groups like Rhysida that have an established track record of exploitation.

Incident Summary

Incident: Berlin state government ransomware attack by Rhysida
Attack Date: Data exfiltration between August 7–12, 2026; publicly disclosed August 17
Threat Actor: Rhysida ransomware group (linked to Vice Society / Storm-0832)
Initial Access: Valid accounts on VPN; Zerologon (CVE-2020-1472); phishing
Data Stolen: ~5.79 terabytes; ~1.44 million files (claimed by attacker)
Confirmed Affected: Senate Department for Mobility, Transport, Climate Protection and Environment; multiple Senate departments
Ransom Status: Berlin refused to pay; no public ransom demand stated
Patch Status: N/A — patch CVE-2020-1472 on all unpatched Windows domain controllers
Severity: High — government data breach with confirmed exfiltration

References

  1. The Hacker News, “Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network,” August 28, 2026, https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html, accessed August 31, 2026
  2. Berlin Senate Chancellery, press statement, August 2026, https://www.berlin.de/rbmskzl/aktuelles/pressemitteilungen/2026/pressemitteilung.1708208.php, accessed August 31, 2026
  3. CISA, FBI, MS-ISAC Joint Advisory AA23-319A, “Ransomware Actors Linked to Vice Society Releasing Ransomware via Rhysida Ransomware-as-a-Service,” November 2023, https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a, accessed August 31, 2026
  4. ransomware.live, Rhysida victim listings, https://www.ransomware.live/id/QmVybGluLCBHZXJtYW55QHJoeXNpZGE, accessed August 31, 2026
  5. BleepingComputer, “Manchester Airports Group says hackers stole travelers’ data,” August 27, 2026, https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/, accessed August 31, 2026

Tags:

ExploitRansomwareWorld
Author

ogwatermelon

Follow Me
Other Articles
Previous

PaperCut Releases Second Emergency Patch After Attackers Bypass Initial Fixes

Next

Socket Uncovers 19 Malicious Chrome and Edge Extensions Stealing Crypto Wallets and Credentials

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.