Berlin's state administrative network was breached on 7 August 2026. Data left the Senate Department for Mobility, Transport, Climate Protection and Environment that day and continued flowing until affected departments were disconnected on 14 August.
Governing Mayor Kai Wegner has put it plainly: the state of Berlin is being blackmailed. The city will not pay.
The sequence
| Date | Event |
|---|---|
| 7 August | Breach; first data outflow detected |
| 7–12 August | Further exfiltration |
| 14 August | Affected departments isolated from the network |
| 17 August | Public disclosure |
| 19 August | Press conference |
| 23 August | All Senate departments reconnected |
Housing benefit applications and payments were unavailable while departments were disconnected — a week in which people who needed money from the state could not apply for it. That is the real cost of the response, and it was the correct decision anyway.
The attackers have since published stolen data to a leak site.
Every number comes from the attacker
This is the part to hold onto.
The figures in circulation — 5.79 terabytes, 12,076 individuals, 1.44 million files across 11 categories, of which 124,823 are maps and geodata — are the attackers' claims. Berlin has not published its own accounting of what was lost.
The Senate Chancellery's position is only that personal or other non-public data cannot be excluded from what was taken.
An extortion group's inventory of its own haul is marketing. It is produced by the party whose leverage increases with the number, published on a site whose purpose is to pressure a victim into paying, and it is not audited by anyone. It may well be accurate. It is not evidence.
We made the same point about a viral scam where every circulating total traced back to the people promoting it. The principle does not change because the victim here is a government: when only one party publishes figures, and that party benefits from the figures being large, the figures are a claim.
The geodata detail is the odd one
124,823 maps and geodata files is the largest single category claimed, which is not what anyone expects from a city administration breach.
If accurate, it reflects what a state government actually holds — cadastral records, utility routing, planning data, infrastructure surveys. That is unglamorous material with a long shelf life and obvious value to anyone doing physical reconnaissance, and it does not expire the way credentials do.
Attribution and what it rests on
Der Spiegel attributed the attack to Rhysida, corroborated through leak-site monitoring. It has not been officially confirmed.
The joint CISA/FBI advisory on Rhysida describes its usual routes in: valid accounts on external-facing services — particularly VPNs without multi-factor authentication — exploitation of Zerologon, and phishing. None of those has been confirmed as the route here.
Interior Senator Iris Spranger has said no sensitive data relevant to the 20 September elections was compromised.
On refusing to pay
Berlin has given no detailed public reasoning, and it does not really need to. Payment buys a promise from a criminal group not to publish data it has already copied, and the data has been published regardless.
What refusal costs is visible and immediate; what it saves is diffuse and never attributable. A government that pays creates a budget line for the next group, and the only way that calculus ever changes is if enough victims absorb the visible cost. Berlin has.
What is not established
- How much data was actually taken. Berlin has published nothing.
- The ransom amount. No figure disclosed by either side.
- How they got in.
- Official attribution. Rhysida is widely reported, not confirmed.
- The full extent of personal data exposure, which remains under examination.