Berlin Refuses to Pay: Inside the Rhysida Ransomware Attack That Stole 5.79 TB of City Data

In a significant escalation of cyber warfare against public institutions, Berlin’s city administration has officially confirmed a major data breach after the notorious Rhysida ransomware gang claimed responsibility for the attack. The German capital is now facing an aggressive extortion attempt, with threat actors threatening to leak 5.79 terabytes of sensitive administrative data if their demands are not met. As the city braces for potential fallout, officials have taken a firm public stance, declaring they will not capitulate to the criminals’ financial demands.

This incident serves as a stark reminder that government entities remain prime targets for ransomware operators looking to exploit critical infrastructure vulnerabilities. The attack, which was initially discovered in mid-August, has prompted a full-scale investigation involving the State Criminal Police Office, the public prosecutor's office, and federal security agencies. With the clock ticking and the attackers leveraging data protection regulations as a weapon, the situation highlights the complex intersection of cybersecurity, public accountability, and international law.

The Attack and Public Acknowledgment

The Berlin city government confirmed the cyberattack after the Rhysida ransomware group listed the municipality on their public data leak site on August 28. The initial intrusion was first detected by forensic investigators in mid-August, but the full scope of the data breach has only now begun to surface. Kai Wergner, the Mayor of Berlin, has been unequivocal in his response, stating firmly that the city will not pay the ransom. This decision aligns with broader government policy but places the administration in a precarious position as the threat actors prepare to release stolen files.

According to the attackers, they successfully exfiltrated an astonishing 5.79 TB of data from the city’s administrative network, which translates to roughly 1.44 million individual files. This volume of data suggests a deep and prolonged penetration of the city’s digital infrastructure. The ransomware operators have claimed possession of a wide array of sensitive information, though the official announcement notes that the investigation is ongoing and the full extent of the data theft has yet to be determined.

A New Tactic: GDPR as a Weapon

In a novel approach to extortion, the Rhysida operators are utilizing European data protection regulations as leverage to increase pressure on the Berlin government. By threatening to expose personal data, the attackers are weaponizing the General Data Protection Regulation (GDPR). If the data includes personal information of citizens or employees, the city could face massive fines from regulatory bodies in addition to the operational disruption caused by the breach. This dual-threat strategy is designed to force the victim into paying by highlighting the financial penalties associated with a data breach, even if the ransom itself remains unpaid.

At the time of writing, the attackers had given the city a four-day ultimatum to pay the extortion fee before the stolen cache is published. This aggressive timeline is a hallmark of the Rhysida operation, which has been active since mid-2023, consistently targeting healthcare organizations, state governments, educational institutes, and other critical infrastructure sectors. The group is known for its "double extortion" tactics—locking systems with malware while simultaneously threatening to leak stolen data to the public.

Scope of the Compromise

Forensic analysis has revealed that the data breach extended beyond the central administrative network. Investigators have confirmed that the threat actor also exfiltrated data from the Senate Department for Mobility, Transport, Climate Protection and the Environment. This specific data exfiltration occurs within a narrow window, likely between August 7 and August 12. In response to the intrusion, officials took the affected Senate departments offline, disconnecting them from the state network on August 14 to contain the spread of the malware and prevent further data loss.

While the news is alarming, Senator Iris Spranger has moved to reassure the public regarding the integrity of the democratic process. Officials have stated that they have found no evidence that election data was compromised. The technical environment supporting the upcoming Berlin House of Representatives election is considered secure, despite the broader compromise of the city’s network. This is a critical distinction, as a breach of electoral systems would represent a significantly more severe threat to national security and public trust.

Attack Vectors and Vulnerabilities

The specific method of entry employed by Rhysida in this particular attack has not yet been publicly disclosed. However, the group’s history provides some insight into their operational tactics. In a previous campaign that was disrupted by Microsoft, the ransomware operators were observed using malicious Microsoft Teams installers to breach their targets. This technique involves social engineering and trojanized software, which often bypasses traditional security measures that rely on signature-based detection. Once the installer is run, it provides the attackers with a foothold to deploy the Rhysida malware and begin the process of lateral movement and privilege escalation.

This attack vector highlights a critical vulnerability in modern cybersecurity: the reliance on valid credentials. Industry research suggests that once attackers are utilizing valid credentials, prevention rates drop sharply. Overall prevention scores can often hide the reality of what happens after initial access is gained. During this post-exploitation phase, attackers can use legitimate tools and credentials to blend in with normal network traffic, making it exceptionally difficult for security teams to detect and block their actions until it is too late.

Implications for Cybersecurity and Public Institutions

The Berlin breach is a textbook example of how cybercriminals are evolving their business models. While the immediate goal is financial gain through extortion, the long-term damage to public trust and the cost of remediation can be devastating. For municipalities and government agencies, the challenge is particularly acute. They manage vast troves of sensitive personal data, operate aging IT infrastructures, and often struggle to recruit the necessary cybersecurity talent to defend against sophisticated threat actors like Rhysida.

Rhysida's focus on "critical infrastructure" and government bodies is a strategic choice. These entities are more likely to have cyber insurance, but more importantly, they are legally and ethically obligated to protect the data they hold, making them more susceptible to GDPR-based extortion tactics. The incident also draws parallels to other recent attacks, such as the data theft confirmed by Coca-Cola in the Fairlife ransomware attack, the major incident following the Qilin breach at the ATF, and the Accenture breach where hackers offered stolen data for sale. These events, along with massive data breaches affecting the French tax authority and the €5 million fine against France's unemployment agency, paint a picture of a global epidemic targeting both private and public sectors.

Conclusion

The confirmation of data theft in Berlin marks a worrying trend in the cybersecurity landscape, where ransomware operators are not just encrypting data but are strategically targeting high-value government targets to maximize public pressure. By refusing to pay and involving federal law enforcement, Berlin is sending a strong signal that it will not fund criminal enterprises, even at the risk of having sensitive data published. However, the incident underscores the urgent need for public institutions to harden their defenses, particularly around identity management and monitoring for compromised credentials.

As the investigation continues, the primary focus will be on mitigating the damage, notifying affected citizens, and ensuring the security of upcoming elections. For cybersecurity professionals, the Berlin attack is a case study in the importance of proactive threat hunting and the need to assume that a breach is inevitable. The resilience of a network is not defined by the absence of attacks, but by the speed and efficacy of its response when a data breach occurs. The world will be watching to see how Berlin navigates the aftermath of this intrusion and what lessons can be learned to protect other cities from a similar fate.