Rhysida Ransomware Gang Leaks 6 TB of Berlin Government Data After Ransom Refusal
What Happened – The Rhysida ransomware group breached Berlin’s state‑administration network in late August 2026, exfiltrated roughly 5.8 TB of data (≈1.44 million files) and, after the government refused a 30‑Bitcoin ransom, published the dump on a dark‑web leak site. The leak includes personal data of over 12 k individuals, payroll and HR records, plaintext credentials, classified‑material handling documents, and vulnerability analyses of critical infrastructure such as the water supply.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a continuously‑validated incident‑response and recovery control that can detect, contain, and document ransomware activity in real time.
- Highlights the importance of evidence‑ready logging and forensic data to satisfy audit requirements across frameworks (e.g., NIST CSF 2.0) and to prove due‑diligence to regulators.
- Shows that a robust control‑mapping capability can translate raw incident data into the control objectives auditors expect, enabling rapid evidence collection and defensible reporting.
Who Is Affected – Public‑sector bodies, municipal administrations, critical‑infrastructure operators, and any organization handling classified or personal data in Germany (and potentially EU partners).
Recommended Actions
- Activate and test your incident‑response playbook; verify that detection, containment, and eradication steps are documented and exercised.
- Ensure immutable logging is enabled for privileged accounts and that logs are retained in a tamper‑evident store for forensic analysis.
- Conduct a gap analysis against the “incident response and recovery” control objective, map findings to your framework of record, and collect the required evidence in a centralized Trust Center.
Technical Notes – The attack vector was a ransomware payload delivered via a compromised administrative system (specific delivery method not disclosed). The group exfiltrated data over several weeks, then posted the dump on a dark‑web site. No CVE identifiers were released, but the breach involved plaintext credentials for systems such as GebäudAtlas, PAYONE, and Z_ADMIN accounts. Source: Security Affairs