Full Report
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
Analysis Summary
# Incident Report: Rhysida Ransomware Attack on Berlin City Administration
## Executive Summary
The Berlin city administration has confirmed a major data breach and extortion attempt following a ransomware attack by the Rhysida group. The attackers claim to have exfiltrated 5.79 TB of sensitive data, including critical infrastructure assessments and personnel records, and are threatening to leak the information unless a ransom is paid. The city has officially refused to pay, and federal authorities are currently investigating the scope of the compromise.
## Incident Details
- **Discovery Date:** August 14, 2026
- **Incident Date:** Approximately August 7 – August 12, 2026
- **Affected Organization:** Berlin City Administration (specifically the Senate Department for Mobility, Transport, Climate Protection, and the Environment)
- **Sector:** Government / Public Sector
- **Geography:** Berlin, Germany
## Timeline of Events
### Initial Access
- **Date/Time:** Estimated August 7, 2026
- **Vector:** Not explicitly disclosed (Historical Rhysida tactics include malicious Teams installers and credential abuse).
- **Details:** Attackers gained access to the administrative network and specific Senate Department environments.
### Lateral Movement
- **Details:** Attackers moved from initial entry points to reach the Senate Department for Mobility, Transport, Climate Protection and the Environment and potentially higher-level administrative repositories.
### Data Exfiltration/Impact
- **Date:** August 7 – August 12, 2026
- **Details:** Exfiltration of 5.79 TB (1.44 million files). Stolen data includes 148 IBANs, plaintext credentials, password vaults, payroll info, classified Bundesrat records, and security assessments of Berlin’s water supply.
### Detection & Response
- **Discovery:** Mid-August; Senate departments disconnected on August 14, 2026.
- **Public Disclosure:** The Rhysida gang listed Berlin on their leak site on August 28, 2026.
- **Response Actions:** Berlin Mayor confirmed a "no-pay" policy; State Criminal Police (LKA) and federal agencies initiated a forensic investigation.
## Attack Methodology
- **Initial Access:** Unknown (Likely compromised credentials or social engineering/malicious installers).
- **Persistence:** Not specified in report.
- **Privilege Escalation:** Likely, given the theft of senior official credentials and password vaults.
- **Credential Access:** Extraction of plaintext credentials, database accounts, and password vaults.
- **Lateral Movement:** Movement across Senate Department networks.
- **Collection:** Automated gathering of SQL database dumps, email archives, and mapping records.
- **Exfiltration:** Standard Rhysida exfiltration tools/scripts to move 5.79 TB of data.
- **Impact:** Data theft and extortion; threat of GDPR-related fines and public exposure.
## Impact Assessment
- **Financial:** Potential GDPR non-compliance fines; costs associated with forensic recovery and system hardening.
- **Data Breach:** High. 5.79 TB of data including PII (phone numbers, emails, IBANs), payroll, and sensitive government documents.
- **Operational:** Disconnection of Senate department networks from the state network.
- **Reputational:** High public visibility; exposure of critical infrastructure security assessments (water supply).
## Indicators of Compromise
- **Network indicators:** (Not disclosed in the article; typically involves connections to Rhysida onion leak sites).
- **File indicators:** Rhysida typically appends the `.rhysida` extension to encrypted files (though this report focuses on the exfiltration/extortion phase).
- **Behavioral indicators:** Large-scale data transfers (5.79 TB) originating from administrative servers.
## Response Actions
- **Containment:** Isolation of affected Senate departments from the state network on August 14.
- **Eradication:** Investigation by State Criminal Police Office and federal security agencies.
- **Recovery:** Ongoing forensic analysis to determine the full extent of the theft; verification of election system integrity (confirmed secure).
## Lessons Learned
- **High-Value Targets:** Government administrative networks remain primary targets due to the sensitivity of data (GDPR leverage).
- **Credential Security:** The theft of plaintext credentials and password vaults highlights a critical failure in credential management and encryption at rest.
- **Network Segmentation:** While departments were eventually isolated, the breadth of data stolen suggests insufficient internal segmentation between administrative units.
## Recommendations
- **Enforce MFA:** Ensure Multi-Factor Authentication is mandatory for all administrative and remote access points.
- **Credential Hygiene:** Prohibit the storage of plaintext credentials and implement robust, hardware-backed password management solutions.
- **Egress Monitoring:** Implement Data Loss Prevention (DLP) and anomaly detection to identify and block massive outbound data transfers (TB-scale exfiltration).
- **Zero Trust Architecture:** Limit lateral movement by implementing strict micro-segmentation between different city departments.