SOCLYDE logo
Current languageEN
Cybersecurity newsRansomwarePublic servicesExtortion

Berlin: what the rhysida extortion confirmation actually establishes

Berlin’s administration confirmed an extortion attempt in late August 2026. Here is what is established, what remains under review, and how to protect public services.

By Soclyde Editorial Team

Agent checking an isolated workstation in a Berlin public service office

In summary

  • Berlin confirmed an extortion attempt on 28 August 2026 after an incident on its state network; Rhysida’s attribution remains a reported claim, not a public judicial finding.
  • Two Senate administrations were isolated after data outflows observed between 7 and 12 August; the exact content and scope remain under investigation.
  • After the data publication announced for 4 September, the priority is service continuity, forensic analysis and risk-based notification of affected people.

Explore next

Soclyde resources

Article contents

The State of Berlin confirmed on 28 August 2026 that it was facing an extortion attempt after an incident on its state network. The confirmation followed a claim by the Rhysida group that it had obtained stolen data. Berlin refused to pay and continued its investigation with state and federal security authorities.

The story needs to be read in layers. The incident on the state network, the data outflow and the extortion attempt are established by the authorities. The attacker’s identity, the exact volume and the list of documents attributed to the group must still be separated from the criminals’ statements and media reporting.

What Berlin confirmed in late August

Berlin’s 28 August statement says that forensic work identified additional data outflows in the area of the Senate Department for Mobility, Transport, Climate Protection and the Environment. Authorities place those outflows between 7 and 12 August, before the affected administrations were separated from the network on 14 August. They also say that personal or other non-public information may be involved, without publishing a detailed list.

The same statement confirms Berlin’s position on the extortion demand: the state will not pay. At that point, Berlin did not disclose the amount demanded or the identity of those responsible. Rhysida’s name came from the group’s claim and press reports; it should not be rewritten as a final judicial attribution.

Two Senate administrations, concrete service disruption

The investigation concerns two Senate administrations: the department responsible for mobility, transport, climate and the environment, and the department responsible for urban development, construction and housing. Their disconnection had concrete but localized effects. The Friedrichshain-Kreuzberg district office reported, for example, that traffic orders and technical special-use requests linked to construction could not be viewed or processed when the procedures depended on the first department.

That distinction matters. This was not only a story about allegedly stolen files: a technical dependency can delay a public procedure. But a disruption in selected workflows does not mean that every Berlin service or the election environment was compromised. Continuity needs to be measured procedure by procedure, with clearly communicated fallback channels.

What Rhysida claims, and what it does not prove

In its 3 September update, Berlin said that Rhysida claimed the attack and alleged possession of 5.7 terabytes of data. The alleged attackers offered the data in an auction with a minimum bid of 30 bitcoin, described in the statement as approximately two million euros. Berlin warned that publication could follow on 4 September.

Those figures describe a claim and an extortion demand; they do not automatically describe the number of people affected, the nature of the files or whether they can be used. Tagesschau later referred to a dataset of roughly 1.44 million files and 5.8 terabytes, along with information attributed to the Chaos Computer Club and other media. That reporting shows why the incident matters, but Berlin’s own position remains that forensic analysis and data classification are continuing.

After publication, assess before alarming people

On 4 September, Berlin said the stolen data had been published and that IT forensics working for the state were examining it. The authorities first need to establish which collections are authentic, which people or companies can be identified, and which accounts or processes need to be secured. A file list, screenshot or total quoted by a criminal group is not enough to conclude that a specific account, infrastructure asset or public procedure is exposed.

This approach also protects public services. Teams can keep essential procedures running on isolated systems, preserve evidence, revoke the access that is actually affected and separate data analysis from production recovery. Berlin said there was no current evidence that the state network remained infiltrated; that means the investigation is still active, not that every risk has disappeared.

Practical steps for staff, residents and suppliers

People who deal with the two administrations should be cautious of messages that reuse a real case, address, procedure or exchange to request a code, payment or new document. Open the administration’s website or phone number from a known source. Do not search for the files on the Dark Web or redistribute them: doing so adds legal and operational risk without helping identify the people actually affected.

If personal data is published or used for fraud, Berlin advises filing a police report, including through the Berlin police online portal. Staff should follow their administration’s instructions, change any secret reused on another service and report unusual requests. Suppliers and companies working with the affected services should verify changes to contact or payment details through a second channel and review accounts held by authorized staff.

Soclyde does not protect Berlin’s state network, classify the published files or replace the authorities’ investigation and continuity work. Its narrower value is helping a team or individual generate a separate secret for each service, keep it in an encrypted vault and quickly identify the access that needs to be rotated when a partner environment is affected.

That separation limits cascading damage. It does not make administrative data unexposed and it does not replace MFA, backups, network segmentation or incident response. It simply prevents one uncertain leak from becoming confirmed access to other accounts through password reuse.

Key takeaways

Berlin confirmed an extortion attempt and a data outflow connected to two Senate administrations. Rhysida, the stated volumes and the reported document types must remain claims or items under review until official analysis establishes the scope. The priority is to keep essential procedures running, identify the people actually affected and remove reused secrets.

To prepare that rotation without scattering passwords, read our secure password generator guide or contact Soclyde.

Frequently asked questions

What is confirmed about the incident affecting Berlin’s state network?

Berlin confirms an incident on its state network, data outflows between 7 and 12 August, the isolation of two Senate administrations and an extortion attempt. The state has not publicly confirmed that every dataset cited by Rhysida was stolen or that the group has been definitively identified by the courts.

Were Berlin residents’ data stolen?

Berlin says personal data belonging to employees, residents and companies may be involved, without having publicly established the individual scope. Authorities say they are reviewing the published files and will notify identified people according to risk.

What should staff, residents and suppliers do if they receive a suspicious message?

Do not download or redistribute published files. Verify any request with the administration through a known channel, never send a code or document under pressure, and report fraudulent use of your data to the police. Staff should also replace reused secrets and follow their administration’s instructions.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading