Rhysida's Berlin Breach: Inside a 5.79 TB Extortion Listing
Rhysida claims 5.79 TB and 1.44 million files from Berlin's state network, with a 30 BTC demand. What the listing says, what it means, and why the group targeted a city government

On 28 August 2026, a leak site added an entry titled simply "Berlin, Germany". Behind that heading sat a claim of 5.79 terabytes and roughly 1.44 million files taken from the German capital's state network, a ransom demand of 30 bitcoin, and a seven-day countdown.
Berlin's Governing Mayor confirmed the extortion attempt after an emergency Senate session and said the state would not be blackmailed. Der Spiegel reported the attribution the same evening. The city has since confirmed that data was stolen, though it has not endorsed the group's description of what was taken.
That distinction runs through everything below. Berlin has confirmed a theft. Every figure and every category in the inventory comes from the people who did it, and they have an obvious interest in the number being large.
A countdown that started a week early
Our own collection caught something the public reporting has largely passed over.
The 28 August entry was not Rhysida's first post about Berlin. On 21 August, a week earlier, the group published a placeholder titled "Coming soon" carrying the same 5.79 TB figure and the same category-by-category breakdown, with no victim named.

Rhysida group naming the exact breach severn days earlier
Seven days later the name went on it.
That gap is a negotiation, conducted in public. The teaser tells the victim that the material is real and itemised, and tells them privately who it belongs to, while giving the wider world nothing to report on yet. It is a deadline with a demonstration attached, and it ran in parallel with a second seven-day window that Berlin will find harder to explain.
The other seven days
Berlin's government detected suspicious data leaving its network around 7 August. The affected departments were disconnected from the Landesnetz on 14 August.
A week separates those dates, and the size of the archive suggests it was a productive one. Isolation decisions in government networks are slow for understandable reasons, since cutting a department off stops it working, and nobody wants to halt a city's administration over an alert that might be noise. The cost of taking the time to be sure is measured in terabytes.
What the group says it holds
The listing is unusually specific. Rather than the customary boast about volume, it reads like an index: maps and geospatial data, legal and complaints files, financial records, contracts, HR, government oversight correspondence, classified-handling material, infrastructure documentation, files containing credentials, health and insurance records, and address databases.
It claims to have extracted 16,389 email addresses, 11,963 phone numbers, names for 12,076 individuals and 148 IBANs. It cites more than 5,000 personnel files, more than 5,000 administrative-offence cases, payroll data, mail-log database dumps spanning 2020 to 2026, and 3,226 documents held under non-disclosure agreements.

Rhysida announcement of breaching Berlin government data

A screenshot of Rhysida undergound website
Three items stand apart from the rest.
Plaintext credentials, including a building-management system, a payment database and individual password stores belonging to named staff. Credentials are not the same kind of loss as records: a personnel file describes something that already happened, while a working password describes something that has yet to happen.
Committee protocols from the Bundesrat, with correspondence about declassification, alongside material governed by Germany's classified-information handling rules. If confirmed, that moves the incident out of data protection law and into a different statute entirely.
Vulnerability analyses of Berlin's water supply. This is the one that changes the character of the whole listing.
The KRITIS problem
Germany treats water as critical infrastructure under its KRITIS framework. A vulnerability analysis of a metropolitan water system is a document describing, in detail, where that system is weak.
Data about people creates a duty to notify and, eventually, a bill. Data about infrastructure creates a hazard that persists for as long as the weaknesses do, and it cannot be resolved by paying anyone, because a copy sold once has been sold permanently.
Its inclusion in the listing is a message rather than a merchandising decision. It tells the recipient that refusing has consequences beyond a fine.
The legal violation map
The most revealing part of the listing is not a category of data at all.
Rhysida included what amounts to a compliance assessment of its own victim: specific citations to GDPR Articles 32, 9 and 33, to German criminal and classified-information statutes conditional on the classification being confirmed, and to the KRITIS obligations under the BSI Act.
Extortion groups have always implied regulatory consequences. Setting them out article by article, in the victim's own legal system, is a different exercise. It converts a technical incident into a case file and hands it to the regulator, the press and the political opposition simultaneously.
It also says something about who wrote it. This listing was composed by someone who understood German administrative law well enough to cite it correctly, which is not a common attribute among affiliates.
Who Rhysida are, and why Berlin
Rhysida appeared in May 2023 and operates as ransomware-as-a-service, leasing tooling to affiliates and splitting proceeds. By September 2026 close to 295 organisations had appeared on its leak site, 54 of them in the preceding twelve months. Initial access typically comes through phishing followed by Cobalt Strike, or through remote access services left without multi-factor authentication. CISA published an advisory on the group in 2023.
Its record is a matter of public record and includes the Chilean Army, the British Library, and a US hospital operator whose attack disrupted 17 hospitals and 166 clinics. Government, healthcare and education dominate its victim list, with education and healthcare leading by count and around half of victims based in the United States.
Which brings us to the question worth asking, and to an answer less satisfying than the incident deserves.
Berlin was almost certainly not selected for its politics. Rhysida is financially motivated and its affiliates work opportunistically, and a European capital administration matches the sector profile the group already favours. The likeliest explanation is that someone found a way in and only then discovered what they had.
The extortion, though, was designed for Berlin specifically. The staged reveal, the statutory citations, the water-supply analyses placed near the top of the inventory — none of that is generic. Whoever wrote the listing understood that a city government cannot be pressured the way a company can. A company fears its customers and its share price. A government fears its parliament, its regulator and its newspapers, and the listing was built to reach all three.
Berlin declined to pay. On the evidence of the last three years, that is the right decision and it will be an expensive one.
What to take from it
Detection is not containment. Berlin saw the outflow and still lost a week deciding what to do about it. Whatever your organisation's isolation procedure is, the useful question is who is permitted to invoke it at two in the morning without waiting for a meeting.
Credential stores travel with the documents. A file share holding personnel records will also hold a spreadsheet of passwords, and the second is what turns one breach into the next one.
Infrastructure documentation deserves separate handling. Risk analyses and emergency plans sit in ordinary shared drives at most organisations, and they are worth more to an attacker than almost anything filed beside them.
Regulators now read leak sites. When a group publishes a statutory analysis of its victim alongside the data, the disclosure conversation has already started without you.