Ransomware Roulette: Why Rhysida’s Berlin Attack Is More Than Just a Data Breach
The Berlin state government is in the crosshairs of the notorious Rhysida ransomware group, a mere three weeks before the city heads to the polls. In a bold move, the attackers claim to have exfiltrated 5.79 terabytes of sensitive administrative data, yet local officials have taken a firm public stance, refusing to capitulate to the extortion demands. The convergence of a high-stakes election and a sophisticated cyberattack creates a chilling scenario that highlights the fragility of public infrastructure.
As the digital dust settles, this incident serves as a stark reminder that in the world of cybersecurity, the aftermath of a data breach is often more complex than the initial intrusion. With forensic teams still sifting through the rubble and a threat actor known for aggressive leak tactics lurking in the shadows, we are witnessing a live case study in modern crisis management. Here is what we know about the attack, the group behind it, and the concerning timeline that has security experts raising their eyebrows.
The Berlin Breach: The Attack and The Ransom Demand
Berlin’s state government confirmed this week that it is grappling with a significant extortion attempt following an August cyberattack on the city-state’s administrative network. The ransomware group Rhysida claimed responsibility on its dark web leak site on August 28, posting an entry titled simply “Berlin, Germany.” In the posting, the threat actors claim to have stolen a staggering 5.79 terabytes of data, encompassing roughly 1.44 million files, which allegedly includes personal information on 12,076 individuals.
According to the leak site, the alleged dataset includes sensitive government records and internal communications. The group also claims that the material could involve violations of GDPR, German classified-information rules, criminal law, and KRITIS/BSIG requirements—the German regulations governing critical infrastructure. It is crucial to note that these are Rhysida’s claims and have not been independently verified by authorities or third-party security researchers.
However, the timing makes this attack especially sensitive. Berlin will elect its state parliament on September 20, less than a month after the breach was discovered. An attack on government systems just before a vote is bound to raise questions about electoral integrity and public trust, even if no direct connection to the voting infrastructure has been established.
Defiant Stance: "We Will Not Submit to Extortion"
Interior Senator Iris Spranger has moved to reassure the public, stating that the election itself remains secure and that, so far, the attackers haven’t taken any election-related data. Security officials supporting the assessment corroborate this claim. Broadcaster RBB first reported on Thursday that Berlin had received ransom demands, prompting a swift and decisive response from the city’s leadership.
“The state of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Interior Senator Iris Spranger said in a joint statement on Friday, a strong rebuke issued just before the ransomware group claimed the attack on their Tor data leak site. This position follows long-standing advice from US federal agencies, which warn that paying a ransom doesn’t guarantee data recovery and, more dangerously, encourages further attacks. Saying no to the ransom, however, is one thing; dealing with the consequences if the attackers make good on their threat to publish the stolen data is another.
The Timeline Scrutiny: A Week of Vulnerability
Berlin first disclosed the compromise on August 17, isolating the Senate Department for Mobility, Transport, Climate Protection and Environment—along with a second unnamed department—from the network. While the immediate priority was containment, forensic investigators later found that the actual data exfiltration happened much earlier than the public disclosure. The timeline reveals that the affected department flagged an initial outflow internally on August 7, yet the network wasn’t cut off until a full week later.
That gap between first internal detection and actual network isolation is the kind of detail that tends to get scrutinized hardest once the immediate crisis passes. In high-stakes environments, the speed of response is almost as critical as the strength of the perimeter defenses. For security researchers, this week-long window represents a missed opportunity to mitigate the scale of the data loss.
Who is Rhysida?
Rhysida isn’t a new name to anyone tracking ransomware against government targets. The group has claimed roughly 280 victims since emerging in 2023, according to tracking services cited by Reuters, including nine in Germany alone and headline targets like the British Library and Chile’s army. Roughly half its victims sit in the US, with the UK, Canada, and Italy rounding out the next tier, a spread that suggests Rhysida isn’t picking targets based on geography so much as opportunity.
A joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center, first published in November 2023, lays out exactly how Rhysida typically gets in. Their modus operandi includes compromised VPN credentials at organizations without multi-factor authentication, exploitation of the Zerologon vulnerability (a critical privilege escalation flaw that Microsoft patched back in 2020), and old-fashioned phishing attacks. None of these entry points are exotic or new, which is precisely the point; Rhysida doesn’t need novel techniques when so many organizations still haven’t closed gaps that have been publicly known for years.
Their success is a testament to the fact that even government entities, despite their resources, often struggle to maintain strict security hygiene across sprawling networks. The use of known Common Vulnerabilities and Exposures (CVEs) like the Zerologon vulnerability suggests that patch management remains a critical weakness in the public sector.
The Election Security Question and Public Trust
While officials have asserted the election's security, the psychological impact of this data breach cannot be understated. The presence of a ransomware group operating within government infrastructure right before a vote is a destabilizing factor. It raises questions about the integrity of public data and the government’s ability to protect its citizens' information.
Berlin reconnected all Senate departments to the network on August 23, but forensic teams are still checking the systems for traces of the malware or persistent backdoors. The state’s data protection commissioner and Germany’s federal cybersecurity agency, the BSI, are actively following the investigation. As of publication, neither Berlin’s data protection office nor the Senate Chancellery had given specific advice to the roughly 12,000 people whose data Rhysida claims to have stolen.
To the public, this silence can be deafening. If you are among the affected individuals and haven’t received any official message yet, don’t assume that means you’re safe. Investigators are still working to establish exactly what the attackers accessed and took, and in the coming weeks, we may see a wave of "credential stuffing" attacks against those individuals if their passwords were included in the leak.
Conclusion: A Lesson in Ransomware Economics
The Rhysida attack on Berlin is a textbook example of how cybercriminals are leveraging political calendars to increase pressure on their victims. While the government’s refusal to pay is commendable and aligns with federal guidelines, the battle is far from over. The true test will be how effectively they manage the potential leak and support the 12,000 individuals caught in the crossfire.
For the cybersecurity community, this incident reinforces a grim reality: proactive defense is the only viable strategy. Relying on detection alone, as the week-long timeline gap shows, is a dangerous gamble. As Berlin prepares to vote, the dark cloud of Rhysida hangs over them, serving as a potent reminder that in the digital age, a nation's security begins with its network vulnerabilities.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon