threat_intelligence373 wordsRead on Arc Codex

Berlin Government Hit by Rhysida Ransomware Ahead of Election

473/69 Monday, August 31, 2026 The Berlin state government in Germany confirmed that it is responding to a cyberattack and ransom extortion incident after an attack on the city’s administrative network in August 2026. The Rhysida ransomware group claimed responsibility on its leak site on August 28, stating that it had stolen 5.79 TB of data, covering approximately 1.44 million files and personal information belonging to 12,076 individuals. However, these claims have not yet been confirmed by the relevant authorities. The Berlin government stated clearly that it will not pay the ransom demanded by the attackers. The data that Rhysida claims to have stolen includes personal information, email addresses, phone numbers, IBANs, personnel data, administrative offense case files, payroll data, executive information, credentials and plaintext passwords for some systems, government and legal documents, disciplinary process records, litigation files, regulatory documents, NDA documents, Bundesrat committee meeting reports, information related to classified document handling, documents allegedly containing state secrets, vulnerability analysis related to Berlin’s water systems, copies of passports and ID cards from personnel files, as well as contract, finance, HR, infrastructure, health, password store, SQL, and PST files. The incident is particularly sensitive because it occurred less than one month before the Berlin parliamentary election on September 20. However, officials stated that there is no indication that election-related data was stolen and confirmed that the election process remains secure. Berlin first disclosed the incident on August 17, when it disconnected the Senate Department for Mobility, Transport, Climate Protection and Environment and another agency from the network. Forensic analysis later found that data exfiltration had occurred earlier, between August 7 and August 12, with signs of data leakage detected as early as August 7. Berlin reconnected all Senate departments to the network on August 23, while forensic teams continued to examine the systems. The Berlin Data Protection Authority and Germany’s Federal Office for Information Security (BSI) are closely monitoring the investigation. Rhysida is a ransomware group that has been active since 2023 and has claimed hundreds of victims, including government agencies and major organizations in several countries. Previous guidance from CISA, the FBI, and MS-ISAC stated that the group commonly gains access through compromised VPN credentials in organizations without MFA, the Zerologon vulnerability, and phishing.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.