At 15:35 on Friday, 4 September 2026, a countdown on a Tor site reached zero and the Rhysida group released 1,439,893 files — 5.79 terabytes — taken from two Berlin Senate administrations: the one responsible for urban development, building and housing, and the one for mobility, transport, climate protection and the environment. The group had listed the data a week earlier at a starting price of 30 bitcoin, roughly two million euros. Berlin’s Governing Mayor and its Interior Senator had answered the same day, in one sentence: the state of Berlin will not be extorted.
That was the right answer, and I would give it to any client. It is also the point where this case stops being a crime story and becomes an engineering one. Not paying is cheap when two properties hold: you can restore your operations without the attacker’s help, and the data they took cannot hurt you more than the ransom would have. Berlin had the first property, more or less. It did not have the second, and everything that has been published since — personnel files, passwords in Word documents, an analysis of the vulnerabilities of the city’s water supply, a folder on chemical, biological, radiological and nuclear contingency planning — is the price of that gap. This article is about the two properties, why the second one is the harder to build, and what an organisation that decided years ago not to be extorted actually has to have done.
Twenty-eight days, in order
The dates matter because they show where the controls were and were not. According to the Senate’s own statement, the data left the network between 7 and 12 August. On Friday 14 August the state’s IT service centre, the ITDZ, noticed irregularities — by one press account, a domain controller behaving abnormally — and the two administrations were cut off from the Berlin state network that same day. The public learned of it on Monday 17 August. For nine days the two departments could be reached by landline; internet, external e-mail, home office and the specialist procedures behind them were gone, and with them the processing of housing benefit for more than fifty thousand households. Reconnection came over the weekend of 22–23 August; online housing-benefit applications returned on 29 August.
On 28 August the extortion became public: Rhysida’s listing, the seven-day countdown, the auction price, and the Senate’s refusal. Until the countdown expired, the Senate’s working estimate of what had been taken was around two hundred thousand files. The publication on 4 September was seven times that.
Two of those intervals deserve attention. Five days of exfiltration went unnoticed. And the alarm, when it came, came from the network operator rather than from the two administrations — for a reason that turns out to be the structural centre of the case.
The attacker logged in, and the playbook is public
Rhysida is not an elite operation. It is a ransomware-as-a-service franchise active since May 2023, and the United States’ cyber security agency published its playbook in November 2023, with an update in 2025: initial access through external-facing remote services — typically a VPN — with valid stolen credentials where multi-factor authentication is missing, through the 2020 Zerologon vulnerability where it is still unpatched, or through a phishing e-mail; then living off the land with the tools already on the network, escalation to domain administrator, exfiltration, encryption, and a leak site with a countdown. Its previous public-sector victims read like a syllabus. The British Library, October 2023: entry through a remote access server without multi-factor authentication, about 600 gigabytes exfiltrated, a 20-bitcoin demand refused, the data published, a rebuild that took more than a year. The City of Columbus, Ohio, July 2024: 6.5 terabytes claimed, auctioned at — the same figure — 30 bitcoin, no bids, 3.1 terabytes published.
How the affiliates got into Berlin is, as of this writing, not forensically confirmed. The account reported in the Berlin press is a phishing link clicked in the transport administration. Whether that or a credential on a remote access point turns out to be true, the point stands: the attacker logged in. Nothing about this playbook is novel, which means nothing about the defence is novel either. Multi-factor authentication on every external door, privileged accounts separated from the ones that read mail, a patched domain, and an eye on outbound traffic — the CISA advisory says as much in its mitigations, and so did the forensic report on Südwestfalen-IT, the municipal IT provider whose seventy-two municipalities were offline for months after October 2023, where the entry was again a VPN without a second factor.
The reason these attacks keep working in public administrations is not that the attackers are clever. It is that the defenders are fragmented, underfunded and not measured on these properties — which is a management finding, not a technical one, and the rest of this article is about it.
Extortion moved from availability to confidentiality
For its first two decades ransomware was a problem of availability. The attacker encrypted your systems and sold you the key; tested backups and a rehearsed restore made the demand irrelevant. Since about 2019 the leverage has moved to confidentiality. The attacker copies your data first, encrypts second, and negotiates over publication — and against publication, a backup does nothing at all.
That shift has a consequence that is still not widely understood in boardrooms: the controls that make you resilient to the old attack are irrelevant to the new one. Restoration is about copies you keep. Leak resistance is about data you do not keep, cannot be reached, or would not matter.
- Retention and minimisation. A file that was deleted when its purpose ended cannot be published. The Berlin dump contains scans of identity documents, sick notes and birth certificates of employees’ children — documents whose retention period, if anyone had set one, expired long ago.
- Classification that the file system enforces. A protection label is worthless unless it decides who can open the file. A meeting protocol of 24 February 2026 found in the leak records the affected administrations’ own assessment: digital handling of classified material “in the strict sense” was not possible in Berlin’s public administration because the required infrastructure had not been deployed. The material was stored anyway, on ordinary shares that a domain administrator could read.
- No secrets in documents. Passwords in Word files were found in the dump; the state revoked VPN credentials and suspended home office after the publication, which tells you those credentials were live.
- Egress you measure. 5.79 terabytes over five days is a sustained copy of roughly a hundred megabits per second, around the clock, out of an office network. That is not a needle in a haystack. It is a haystack leaving the building.
A note on encryption: encrypting data at rest under your own keys is a sovereignty control, and a good one — I have argued it is what makes control real. It does not stop this attack. An attacker with a domain administrator’s credentials reads files the way the administrator does: decrypted. The controls that matter against exfiltration are the four above, plus the one that decides whether one phished laptop can reach two ministries’ file servers at all.
A network is as secure as its least consolidated island
Berlin’s E-Government Act of 2016 gave the city a single ICT provider, the ITDZ, and obliged every authority to take basic services from it. Ten years on, the consolidation it ordered has not happened. By the count of the Greens’ digital-policy spokesperson in the state parliament, three institutions have completed migration; 233 sites are in planning, nine in implementation, 38 not planned at all, and around 210 will not be finished within the current budget period. Two-thirds of Senate administrations and state authorities, the Tagesspiegel reports, are responsible for their own IT security. The two administrations that were breached were among them: never migrated, running their own systems on a shared network.
That arrangement explains the detection story. The ITDZ operates the state network’s cyber defence centre, with a security operations centre and a security information and event management system. It saw the anomaly because the anomaly crossed its network. It could not have prevented it, because the endpoints, identities and file servers where the attack lived were not its to harden. A shared network with self-administered islands has exactly the security of its weakest island, and the attacker gets to choose which one.
The Senate’s own seventh implementation report on the E-Government Act, dated 27 March 2026 with a reporting cut-off of 31 December 2025, is candid about the state of the rest. On business continuity management: in 2025 the roles the concept requires were “largely unfilled” in the authorities, and the guideline meant to replace the old emergency-management directive still awaited formal adoption. On the state network’s IT security programme, whose purpose is NIS-2 implementation: the results “did not fully meet the requirements derived from NIS-2, the BSI and national architecture guidelines”, and “no realisation plans exist yet for the programme-wide measures”. On the security operations centre: a round-the-clock operation “is prepared and can be carried out once commissioned” — in other words, not running. Meanwhile the 2026/27 double budget cut digitalisation funding by fifty million euros, according to the Tagesspiegel, and outside experts had told the parliament’s committees in December 2023 and again in December 2025 that the state’s security posture was poor.
None of this is unique to Berlin. The BSI’s 2025 situation report counts municipalities alongside SMEs and IT service providers among the most frequent ransomware targets, and the federal NIS-2 implementation law that entered into force on 6 December 2025 binds the federal administration only: each Land must regulate its own. Berlin did so by a binding determination letter of 30 May 2025, published in its official gazette. A decree that applies NIS-2 to a network for which no realisation plan exists is the compliance-first pattern I described for DORA: the paperwork arrives before the engineering, and the audit — here, the attacker — finds the gap.
Every corrected reassurance costs more than the breach
The Senate’s statements followed a pattern I have seen in almost every incident I have been close to, and which deserves a plainer name than the crisis-communication literature gives it: the reassurance reflex.
On 18 August the Senate Chancellery said that data had flowed out of the building administration but that it was data “freely accessible via open data”. On 23 August: as far as is currently known, no sensitive data has flowed out. On 28 August, confronted with the auction listing — 46,500 contracts, some 80,000 files from administrative-offence proceedings, about 6,000 files with credentials — the statement changed to: it cannot be excluded that personal or non-public data are affected. On 4 September the state’s Chief Digital Officer said that only material of the lowest of four classification levels, “for official use only”, had been taken. By 6 September journalists had found the CBRN contingency-planning folder, the water-supply vulnerability analysis, lists of facilities to be protected in an emergency, and the personnel files.
Columbus went through the identical sequence in 2024. Its mayor said the leaked data was “encrypted or corrupted” and of no use to anyone; a security researcher showed reporters that it was neither; the city sued the researcher, then dropped the suit; and about half a million people were eventually notified. The mechanism is the same in both cases, and it is not dishonesty. It is that an organisation which does not have an inventory of what it holds cannot make a true statement about what was stolen. It reaches for the most comforting sentence that has not yet been contradicted, and each contradiction costs more trust than the breach itself did — with employees, with citizens, and with an election three weeks away.
The engineering answer is unglamorous: an inventory and classification of data by share and by system, maintained, so that the first statement can be “we know what was on those servers, and this is what it means for you”. The Senate now has a steering unit going through 1.44 million files to find out, weeks after the attacker did.
The decision is made before the demand arrives
Whether to pay is not a decision you get to make well in the week the countdown runs. It was made by the state of your architecture months or years earlier, along two axes. Can you restore without them? Berlin could, in nine days for the network and about two weeks for the benefits. How much can the data hurt? In Berlin’s case: a great deal, for a long time — the personnel files do not expire, and the infrastructure analyses will be read by people who were not their intended readers.
Move an organisation along the first axis and the encryption part of the demand becomes noise; that is what tested restore buys, and after Südwestfalen-IT and the British Library nobody in public IT should still need convincing. Move it down the second axis and the publication threat becomes noise too. That is the harder, less visible programme, and it is the one Berlin — and, in my experience, most organisations that consider themselves prepared — has not run.
For a financial entity under DORA these are not advice; they are obligations with deadlines — an initial incident notification within four hours of classification and at most twenty-four of becoming aware, tested recovery, managed concentration risk. Public administration in Germany has no such clock at Land level yet. Its citizens would be well served by one.
What this means for a European organisation in 2026
Three conclusions travel beyond Berlin.
First, if your organisation runs shared infrastructure with self-administered units — a group with subsidiaries, a university with faculties, a hospital with departments, a Land with Senate administrations — your security is the security of the least-managed unit, and consolidation is not an IT preference but a control. The E-Government Act was right in 2016. The failure was that it was never enforced.
Second, prepare for the attack you will actually get. It will not encrypt you first; it will copy you first. Budget for retention, classification and egress monitoring with the same seriousness as for backups, and rehearse the leak the way you rehearse the restore. Frontier models have made the copying side cheaper still: the long tail of shares nobody has looked at in years is now worth an attacker’s minute.
Third, decide now what you will say. The refusal to pay is the easy sentence. The sentence that is hard to earn is “we know what they took, and here is what it means for you” — and it is only available to organisations that knew what they held before anyone took it.
Berlin’s refusal was correct. What it cost was decided long before 28 August, by everything that had not been built. That is the real lesson, and it applies to every organisation that has ever said it would not pay.
Sources and further reading
- Der Regierende Bürgermeister Kai Wegner und Innensenatorin Iris Spranger: „Das Land Berlin lässt sich nicht erpressen“ (opens in a new tab) — Senatskanzlei Berlin, 2026
- Cyberattack on the state network: data may be made public (opens in a new tab) — Berlin.de, 2026
- Hackerangriff: Was der Cyberangriff auf die Berliner Verwaltung bedeutet (opens in a new tab) — Der Tagesspiegel / dpa, 2026
- Wohngeld kann ausgezahlt werden: Berliner Senatsverwaltungen sind nach Hackerangriff wieder online (opens in a new tab) — Der Tagesspiegel, 2026
- Berliner Senat bestätigt Erpressung: Wegner weist Ultimatum von Hackern zurück (opens in a new tab) — Der Tagesspiegel, 2026
- Berlin cyberattack: hackers leak highly sensitive data across dark web (opens in a new tab) — Euronews, 2026
- Hackerangriff auf Berliner Verwaltung: Der Daten-Leak war ein Anschlag, die Reaktion des Senats ein Skandal (opens in a new tab) — Der Tagesspiegel, 2026
- Cyberattacke auf Berlin könnte größere Folgen haben als bisher gedacht (opens in a new tab) — heise online, 2026
- Rhysida-Datenleck ist der GAU für Berlin und Betroffene (opens in a new tab) — Borns IT- und Windows-Blog, 2026
- Nach dem Hack: Berlin muss seine IT endlich zentral organisieren (opens in a new tab) — Stefan Ziller, Abgeordnetenhaus von Berlin, 2026
- 7. Umsetzungsbericht E-Government-Gesetz Berlin und IKT-Zukunftsbericht (Stichtag 31. Dezember 2025) (opens in a new tab) — Senatskanzlei Berlin, Abgeordnetenhaus von Berlin, 2026
- E-Government-Gesetz Berlin (EGovG Bln), § 24 IKT-Dienstleister (opens in a new tab) — Land Berlin, 2016
- #StopRansomware: Rhysida Ransomware (AA23-319A) (opens in a new tab) — CISA, FBI and MS-ISAC, 2023
- Learning lessons from the cyber-attack: British Library cyber incident review (opens in a new tab) — British Library, 2024
- Researcher sued for sharing data stolen by ransomware with media (opens in a new tab) — BleepingComputer, 2024
- Südwestfalen-IT: Forensik-Bericht liefert Erkenntnisse zu Ransomware-Angriff (opens in a new tab) — Südwestfalen-IT, 2024
- Die Lage der IT-Sicherheit in Deutschland 2025 (opens in a new tab) — Bundesamt für Sicherheit in der Informationstechnik, 2025
- NIS-2 für die Landes- und Kommunalverwaltung (opens in a new tab) — Bundesamt für Sicherheit in der Informationstechnik, 2025
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 33 and 34 (opens in a new tab) — Official Journal of the European Union, 2016
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) (opens in a new tab) — Official Journal of the European Union, 2022