Berlin confirms data theft after Rhysida ransomware attack claims

By George Bailey   Published: 08/31/26   Updated: 08/31/26   3 min read
Berlin confirms data theft after Rhysida ransomware attack claims

What Berlin Confirmed

Berlin's city administration confirmed that attackers stole data and attempted to extort the city after the Rhysida ransomware gang listed the incident on its leak site.

Public reporting says the affected departments were disconnected on August 14, while the public extortion claim arrived later. That lag is useful context because it shows the familiar gap between internal discovery, containment, and public understanding of the real scope.

Why The Claimed Data Matters

Rhysida claimed to have roughly 5.79 terabytes of data, or about 1.44 million files. Threat-actor claims are not the same thing as verified impact, but the categories reportedly involved are serious enough to drive immediate concern: government, legal, financial, HR, infrastructure, health, and mapping records, plus references to plaintext credentials, vaults, and senior-official access.

That combination makes this more than a headline about disruption. It is a live reminder that once attackers reach administrative or shared records at municipal scale, incident response turns into a prolonged trust, notification, and continuity exercise.

What Public-Sector Defenders Should Notice

The most useful lesson is not that another city was hit. It is that municipal environments carry unusually broad data concentration and operational interdependence. A breach in one administrative lane can rapidly become a cross-department problem even when highly sensitive functions such as elections remain unaffected.

That means public statements about what was not impacted should be read alongside the harder question: which connected departments, records, and privileged workflows still need validation before anyone can speak confidently about the blast radius.

What Teams Should Do Next

Use this incident as a practical model for scoping and communications discipline.

Source Context

CyberExperts used BleepingComputer's reporting as the primary source for this article and preserved the details that matter most to operators: the confirmed data theft, the Rhysida claim, the scale of the alleged file set, the department disconnections, and the distinction between broad administrative impact and functions reportedly outside scope.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading