A major ransomware attack against Berlin’s government network has escalated into a sprawling data breach after the Rhysida ransomware group published stolen government files and later released an additional package containing access credentials.
Berlin officials say Rhysida claimed to have obtained approximately 5.7 terabytes of data from portions of the city’s administrative network. The attackers demanded 30 Bitcoin, worth approximately €2 million at the time, and threatened to publish the material if Berlin refused to pay.
Berlin refused.
The stolen files were subsequently released, forcing the German capital to launch an extensive forensic review aimed at identifying exposed information, determining which citizens, employees and businesses may be affected, securing potentially compromised systems and meeting its obligations under European data protection law.
The incident has now moved well beyond the operational disruption normally associated with ransomware. Berlin is confronting the consequences of a large-scale disclosure of government information that may contain personal data, confidential records and credentials capable of creating continuing security risks long after the original attack.
Rhysida Says It Took Approximately 5.7 TB of Berlin Government Data
Berlin disclosed in late August that a group identifying itself as Rhysida had claimed responsibility for the cyberattack and was attempting to extort the state government.
The attack affected two Senate administrations: the administration responsible for mobility, transport, climate protection and the environment, and the administration responsible for urban development, building and housing.
According to Berlin, the attackers claimed to possess approximately 5.7 terabytes of stolen data.
Reuters previously reported that Rhysida described the material as including contracts, emails, telephone numbers, passwords and classified information. The exact contents and scale of the dataset remain under forensic examination by German authorities.
An independent analysis published by German technology writer Jan Kammerath went considerably further, reporting approximately 1.44 million files and describing material that appeared to include legal complaints, financial information, employee records, phone numbers, bank account details, payroll information, disciplinary records, signatures and passport scans.
Those granular figures have not been independently confirmed by Berlin and should be treated separately from the information officially released by the city.
What Berlin has confirmed is serious enough: personal data belonging to government employees, residents and businesses may be among the information compromised in the attack.
Berlin Refused the €2 Million Ransom
Rhysida offered the stolen material for sale and set a minimum bid of 30 Bitcoin, which Berlin estimated at approximately €2 million.
The government publicly rejected the demand.
Berlin’s position was that it would not submit to criminal extortion, even with the possibility that sensitive information could be released.
That decision created the scenario governments and businesses increasingly face during double-extortion ransomware attacks. Encrypting systems is only one source of leverage. Attackers first steal information and then threaten to expose it, sell it or use it for additional attacks if their victim refuses to pay.
When a victim restores its systems without paying, the attacker may still retain enormous leverage through the stolen information.
That appears to be what happened in Berlin.
The Stolen Files Were Published
After Berlin refused to pay, the stolen data was published.
On September 5, the Berlin Senate Chancellery said authorities were examining the released files with “great urgency” and established a central coordination unit under Berlin Chief Digital Officer Florian Hauer.
The unit is coordinating the review, examination and assessment of the exfiltrated information and helping the affected Senate administrations identify and assist affected citizens, employees and businesses.
The response includes Berlin’s State Criminal Police Office, the affected Senate administrations, the state’s data protection authority, information security officials and other security agencies.
Federal authorities are also involved.
Berlin said the investigation includes IT forensic specialists reviewing both the affected systems and the published information. Officials are prioritizing the analysis according to risk, particularly where leaked information could affect security-sensitive government agencies or institutions.
Then Another Data Package Appeared
The incident escalated again during the night of September 5 into September 6.
Berlin announced that the attackers had released another package of information.
This time, the city specifically confirmed that the new material included access credentials.
The Senate Department for Urban Development, Building and Housing responded by reviewing security measures introduced after the first publication and tightening some of those controls as a precaution.
Berlin warned that the additional safeguards could temporarily restrict access to certain specialized government applications.
The disclosure of credentials materially changes the risk analysis associated with a breach. A leaked document creates a confidentiality problem. A working username, password, token, certificate or other authentication secret can create an avenue for another intrusion.
That means organizations responding to ransomware cannot assume the security event has ended simply because the original attackers have been removed from the network.
The Data Breach May Affect Far More Than Government Employees
One of the most difficult parts of Berlin’s response is determining who appears in the stolen files.
A government file server does not contain information only about government employees.
It can contain communications with residents, contractors, property owners, businesses, applicants, consultants, attorneys, government partners and numerous other individuals who have interacted with an agency over many years.
Berlin has acknowledged this problem.
The city says its review will cover employees as well as other people named in the compromised files. When affected individuals are identified, the responsible Senate departments intend to notify them on a risk-based basis and in accordance with the GDPR and Berlin data protection law.
Berlin has also advised people who discover that their information has been published or is being misused for fraud or identity theft to report the matter to police.
The GDPR Breach Notification Problem
The Berlin incident is also a useful example of how complicated GDPR breach response becomes after a large-scale data exfiltration event.
Article 33 of the GDPR generally requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to people’s rights and freedoms.
Article 34 creates a separate obligation. Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, the controller generally must communicate the breach to those individuals without undue delay.
Those rules sound relatively straightforward when an organization knows exactly which database was compromised and can immediately identify the affected records.
A breach involving millions of files is different.
Investigators first have to determine what was actually taken. Then they have to identify which files contain personal data, determine the categories of data involved, connect those records to identifiable people, assess the risks associated with each category of information and determine which people require notification.
A passport scan creates a different risk from an ordinary business email. Bank account information raises different concerns from an internal work schedule. Credentials require a different response from an address or telephone number.
The GDPR anticipates some of this uncertainty. Article 33 allows information about a breach to be provided to regulators in phases when everything cannot be supplied at the same time.
That can be essential in ransomware incidents where the investigation continues for days or weeks after the controller first becomes aware of the attack.
Publication Makes the Privacy Risk More Severe
Data exfiltration and public disclosure are not the same event from a risk perspective.
When criminals steal information but have not released it publicly, an organization may not know whether anyone beyond the attacker has obtained the data.
Publication changes that calculation.
Once information is available through a criminal leak site, the original organization loses meaningful control over future distribution. Files may be downloaded, copied, repackaged and redistributed through other channels.
Even if the original leak site disappears, copies may remain elsewhere indefinitely.
That can increase the risk of identity theft, phishing, impersonation, financial fraud, credential-stuffing attacks, social engineering and targeted attacks against employees or government systems.
It also makes remediation considerably harder. An organization can reset a password. It cannot reset a person’s passport number, employment history, signature or previously confidential personnel record with the same ease.
Credential Exposure Creates a Second Security Problem
The September 6 announcement that the new material contains access credentials deserves particular attention.
Credential exposure can turn a historical breach into an active attack surface.
Incident response teams must determine whether the exposed credentials remain valid, which systems they can access, whether passwords were reused elsewhere, whether certificates or authentication tokens need to be revoked and whether attackers have attempted to use the information since publication.
Organizations also need to examine authentication logs for suspicious access that may initially appear legitimate because the attacker is using a valid account.
This is one reason credential rotation, multifactor authentication, least-privilege access and effective identity and access management can become critical parts of ransomware containment.
What Is Rhysida?
Rhysida is a ransomware operation that emerged publicly in 2023 and has targeted government agencies, healthcare organizations, educational institutions and private businesses in multiple countries.
The group has become associated with double-extortion attacks in which data is stolen before systems are encrypted.
Victims that refuse payment may then face publication of their information.
The group has previously been associated with attacks against prominent institutions including the British Library, demonstrating how disruptive the combination of ransomware and data theft can become for large organizations with extensive historical records.
As with many ransomware operations, determining precisely who operates the infrastructure and where individual participants are located can be difficult. Attribution claims should therefore be treated carefully unless established by law enforcement.
Why Data Inventory Matters During a Breach
The Berlin attack exposes another problem that often receives less attention than malware or network security: organizations cannot efficiently assess a breach if they do not know what information they possess.
Data mapping, retention controls and record classification can significantly affect the speed of incident response.
An organization with a reliable understanding of where personal information is stored, which systems contain sensitive data, who owns those systems and how long information is retained has a substantial advantage when investigating an intrusion.
Without that visibility, incident responders may have to analyze enormous collections of unstructured files individually before determining who is affected.
Data minimization matters for the same reason.
Information that was legitimately collected ten years ago but no longer serves a business or legal purpose can still become part of a breach today if it remains sitting on a file server.
Every unnecessary copy creates additional exposure.
Ransomware Is Increasingly a Privacy Incident
The traditional distinction between cybersecurity and privacy is becoming less useful during major ransomware incidents.
The initial problem may be unauthorized system access. The consequences quickly become privacy issues when attackers copy personal data.
At that point, the response requires more than restoring servers.
Organizations may need forensic investigators, security engineers, privacy counsel, data protection officers, communications teams, insurers and law enforcement working from the same incident record.
They need to determine what was accessed, what left the environment, whose information was involved, which jurisdictions apply, whether regulators must be notified, whether individuals must be contacted and what steps can reduce continuing harm.
The Berlin government is now working through that process at an unusually large scale.
What Organizations Can Learn From the Berlin Breach
The final scope of the Berlin incident is still being determined, and it may take considerable time before authorities know exactly how many people and records were affected.
But several lessons are already apparent.
- Ransomware preparedness needs to account for data theft, not only system encryption.
- Organizations should know where sensitive and personal information is stored before an incident occurs.
- Data retention policies reduce the volume of historical information available to an attacker.
- Exposed credentials should be treated as an immediate security risk and rotated or revoked where appropriate.
- Incident response teams need a process for identifying affected individuals and determining notification obligations.
- Security, privacy, legal and compliance teams should coordinate breach response rather than operate as separate functions.
- Organizations should maintain records showing what happened, what information was affected, how risks were assessed and what remedial steps were taken.
Berlin’s Investigation Is Far From Over
The release of the stolen files does not mark the end of the Berlin cyberattack.
In many respects, it marks the beginning of the more difficult phase.
Authorities now have to analyze an enormous dataset, identify sensitive government information, determine which individuals and businesses appear in the files, assess the risks created by the publication and notify affected people when required.
The September 6 release of additional credentials shows why that work cannot be treated solely as a retrospective investigation. Information disclosed by the attackers may create new security risks while investigators are still trying to understand the original breach.
For privacy and security teams, Berlin provides a stark example of what happens when ransomware, data exfiltration, credential exposure and GDPR breach obligations converge in a single incident.
The malware may start the crisis. The stolen data determines how long it lasts.