Berlin’s state government has publicly stated that it will not comply with the ransom demands of hackers who breached the city’s administrative network in August 2026. This decision comes after forensic investigations revealed that sensitive data may have been exfiltrated from the network.
Details of the Breach
The breach occurred between August 7 and August 12, 2026, with the Senate Department for Mobility, Transport, Climate Protection and Environment reporting the initial data outflow on August 7. The network was subsequently isolated on August 14. The exact scope of the data taken is still under investigation, but officials have indicated that personal or non-public data could be involved.
Extent of Data Compromised
While the Berlin government has not disclosed the volume of data that was compromised, a post on a leak site claims that approximately 5.79 terabytes of data, including personal information of 12,076 individuals, were stolen. The attackers have categorized this data into eleven different types, with a significant portion consisting of maps and geodata files.
Investigation and Attribution
The investigation into the breach involves the state criminal police, the public prosecutor, and federal security authorities. As of now, no specific group has been officially identified as responsible for the attack. However, reports from Der Spiegel have linked the incident to a group named Rhysida, which has been associated with similar attacks in the past.
Security Recommendations and Future Steps
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have previously issued advisories regarding Rhysida’s tactics, including exploiting valid accounts on external-facing services and utilizing known vulnerabilities such as Zerologon (CVE-2020-1472). They recommend organizations prioritize remediation of known vulnerabilities and implement multi-factor authentication to enhance security. The Berlin government has stated that it is keeping its data protection commissioner and the Federal Office for Information Security informed about the ongoing situation.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








