HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Ransomware

Rhysida Ransomware Gang Leaks 6 TB of Berlin Government Data After Ransom Refusal

Rhysida exfiltrated ~5.8 TB of Berlin state‑administration files and published them after the government declined a 30‑Bitcoin ransom. The leak includes personal, payroll, credential, and classified data, underscoring the need for continuous incident‑response evidence and control‑mapping for audit readiness.

Verisq™ Intelligence · 📅 September 17, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Rhysida Ransomware Gang Leaks 6 TB of Berlin Government Data After Ransom Refusal

What Happened – The Rhysida ransomware group breached Berlin’s state‑administration network in late August 2026, exfiltrated roughly 5.8 TB of data (≈1.44 million files) and, after the government refused a 30‑Bitcoin ransom, published the dump on a dark‑web leak site. The leak includes personal data of over 12 k individuals, payroll and HR records, plaintext credentials, classified‑material handling documents, and vulnerability analyses of critical infrastructure such as the water supply.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuously‑validated incident‑response and recovery control that can detect, contain, and document ransomware activity in real time.
  • Highlights the importance of evidence‑ready logging and forensic data to satisfy audit requirements across frameworks (e.g., NIST CSF 2.0) and to prove due‑diligence to regulators.
  • Shows that a robust control‑mapping capability can translate raw incident data into the control objectives auditors expect, enabling rapid evidence collection and defensible reporting.

Who Is Affected – Public‑sector bodies, municipal administrations, critical‑infrastructure operators, and any organization handling classified or personal data in Germany (and potentially EU partners).

Recommended Actions

  • Activate and test your incident‑response playbook; verify that detection, containment, and eradication steps are documented and exercised.
  • Ensure immutable logging is enabled for privileged accounts and that logs are retained in a tamper‑evident store for forensic analysis.
  • Conduct a gap analysis against the “incident response and recovery” control objective, map findings to your framework of record, and collect the required evidence in a centralized Trust Center.

Technical Notes – The attack vector was a ransomware payload delivered via a compromised administrative system (specific delivery method not disclosed). The group exfiltrated data over several weeks, then posted the dump on a dark‑web site. No CVE identifiers were released, but the breach involved plaintext credentials for systems such as GebäudAtlas, PAYONE, and Z_ADMIN accounts. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/198545/cyber-crime/berlin-ransomware-leak-exposes-state-secrets.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →