The State of Berlin confirmed on 28 August 2026 that it was facing an extortion attempt after an incident on its state network. The confirmation followed a claim by the Rhysida group that it had obtained stolen data. Berlin refused to pay and continued its investigation with state and federal security authorities.
The story needs to be read in layers. The incident on the state network, the data outflow and the extortion attempt are established by the authorities. The attacker’s identity, the exact volume and the list of documents attributed to the group must still be separated from the criminals’ statements and media reporting.
What Berlin confirmed in late August
Berlin’s 28 August statement says that forensic work identified additional data outflows in the area of the Senate Department for Mobility, Transport, Climate Protection and the Environment. Authorities place those outflows between 7 and 12 August, before the affected administrations were separated from the network on 14 August. They also say that personal or other non-public information may be involved, without publishing a detailed list.
The same statement confirms Berlin’s position on the extortion demand: the state will not pay. At that point, Berlin did not disclose the amount demanded or the identity of those responsible. Rhysida’s name came from the group’s claim and press reports; it should not be rewritten as a final judicial attribution.
Two Senate administrations, concrete service disruption
The investigation concerns two Senate administrations: the department responsible for mobility, transport, climate and the environment, and the department responsible for urban development, construction and housing. Their disconnection had concrete but localized effects. The Friedrichshain-Kreuzberg district office reported, for example, that traffic orders and technical special-use requests linked to construction could not be viewed or processed when the procedures depended on the first department.
That distinction matters. This was not only a story about allegedly stolen files: a technical dependency can delay a public procedure. But a disruption in selected workflows does not mean that every Berlin service or the election environment was compromised. Continuity needs to be measured procedure by procedure, with clearly communicated fallback channels.
What Rhysida claims, and what it does not prove
In its 3 September update, Berlin said that Rhysida claimed the attack and alleged possession of 5.7 terabytes of data. The alleged attackers offered the data in an auction with a minimum bid of 30 bitcoin, described in the statement as approximately two million euros. Berlin warned that publication could follow on 4 September.
Those figures describe a claim and an extortion demand; they do not automatically describe the number of people affected, the nature of the files or whether they can be used. Tagesschau later referred to a dataset of roughly 1.44 million files and 5.8 terabytes, along with information attributed to the Chaos Computer Club and other media. That reporting shows why the incident matters, but Berlin’s own position remains that forensic analysis and data classification are continuing.
After publication, assess before alarming people
On 4 September, Berlin said the stolen data had been published and that IT forensics working for the state were examining it. The authorities first need to establish which collections are authentic, which people or companies can be identified, and which accounts or processes need to be secured. A file list, screenshot or total quoted by a criminal group is not enough to conclude that a specific account, infrastructure asset or public procedure is exposed.
This approach also protects public services. Teams can keep essential procedures running on isolated systems, preserve evidence, revoke the access that is actually affected and separate data analysis from production recovery. Berlin said there was no current evidence that the state network remained infiltrated; that means the investigation is still active, not that every risk has disappeared.
Practical steps for staff, residents and suppliers
People who deal with the two administrations should be cautious of messages that reuse a real case, address, procedure or exchange to request a code, payment or new document. Open the administration’s website or phone number from a known source. Do not search for the files on the Dark Web or redistribute them: doing so adds legal and operational risk without helping identify the people actually affected.
If personal data is published or used for fraud, Berlin advises filing a police report, including through the Berlin police online portal. Staff should follow their administration’s instructions, change any secret reused on another service and report unusual requests. Suppliers and companies working with the affected services should verify changes to contact or payment details through a second channel and review accounts held by authorized staff.
The link with Soclyde
Soclyde does not protect Berlin’s state network, classify the published files or replace the authorities’ investigation and continuity work. Its narrower value is helping a team or individual generate a separate secret for each service, keep it in an encrypted vault and quickly identify the access that needs to be rotated when a partner environment is affected.
That separation limits cascading damage. It does not make administrative data unexposed and it does not replace MFA, backups, network segmentation or incident response. It simply prevents one uncertain leak from becoming confirmed access to other accounts through password reuse.
Key takeaways
Berlin confirmed an extortion attempt and a data outflow connected to two Senate administrations. Rhysida, the stated volumes and the reported document types must remain claims or items under review until official analysis establishes the scope. The priority is to keep essential procedures running, identify the people actually affected and remove reused secrets.
To prepare that rotation without scattering passwords, read our secure password generator guide or contact Soclyde.



