Berlin's city administration has confirmed a data theft incident after the Rhysida ransomware gang listed the city on their data leak site. The cybercriminals are actively attempting to extort the city government. Rhysida is a ransomware-as-a-service group known for targeting government and public sector entities. The attack resulted in confirmed exfiltration of data belonging to the city. Berlin authorities are responding to the extortion attempt. This incident highlights the continued targeting of European municipal governments by ransomware groups. The Rhysida gang uses double extortion tactics, threatening to publish stolen data if ransom is not paid.
The Rhysida ransomware gang attacked Berlin's city administration, with the intrusion discovered in mid-August 2025 and publicly claimed on August 28, 2025. The threat actor claims to have exfiltrated 5.79 TB of data comprising approximately 1.44 million files from Berlin's administrative network, likely between August 7 and 12. The affected Senate Department for Mobility, Transport, Climate Protection and the Environment was disconnected from the state network on August 14. Exfiltrated data reportedly includes: government, legal, financial, contractual, HR, infrastructure, health, and mapping records; thousands of names, email addresses, phone numbers, and 148 IBANs; plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials; personnel files, payroll information, administrative-offense records, email archives, SQL database dumps, identity documents, and banking information; disciplinary proceedings records; allegedly classified government material including Bundesrat committee records; critical-infrastructure security assessments for Berlin's water supply; and over 3,200 NDA documents. Attackers are leveraging GDPR violations as extortion pressure. The exact initial access vector was not disclosed; in a previous campaign, Rhysida used malicious Microsoft Teams installers. Rhysida has been active since mid-2023 and targets healthcare, government, education, and critical infrastructure sectors.
1. Disconnect compromised network segments immediately upon detection of ransomware activity, as Berlin did by isolating affected Senate departments on August 14. 2. Engage law enforcement agencies (State Criminal Police Office, public prosecutors, federal security agencies) immediately upon confirmation of an attack. 3. Conduct forensic investigation to determine the full scope of data exfiltration and the initial access vector. 4. Do not pay the ransom, as paying does not guarantee data recovery and may invite further attacks. 5. Audit and rotate all potentially exposed credentials, including plaintext credentials, database accounts, and privileged/senior official credentials. 6. Review and secure Microsoft Teams configurations and restrict installation of third-party or unofficial Teams clients to mitigate known Rhysida initial access techniques. 7. Assess and secure critical infrastructure systems (e.g., water supply) referenced in stolen documents. 8. Notify relevant data protection authorities regarding potential GDPR violations caused by the data breach. 9. Monitor the dark web and threat actor leak sites for publication of stolen data. 10. Verify the security of election-related technical environments if applicable. 11. Implement network segmentation to limit lateral movement in future incidents.