
A ransomware attack usually makes headlines when systems go down.
But the more dangerous moment can come later — when the attacker starts publishing what was stolen.
That is what makes the Rhysida attack on Berlin’s state network particularly interesting from a cybersecurity perspective.
This was not simply a case of files being encrypted and a ransom being demanded. The incident evolved into a data-exfiltration, extortion and public-disclosure crisis, with the attackers claiming possession of around 5.79 TB of data across approximately 1.44 million files. Berlin refused the ransom demand, and stolen data was subsequently published.
The Timeline
7–12 August 2026 — Data exfiltration
Berlin later determined that additional data had been transferred out of the environment during this period. The authorities have confirmed that the exfiltration occurred before the affected networks were isolated.
14 August — Network isolation
Two Senate administrations — Mobility, Transport, Climate Protection and Environment, and Urban Development, Building and Housing — were isolated from the Berlin state network as a security measure.
17 August — Incident publicly acknowledged
Berlin officially announced the IT security incident and established an IT crisis response structure. LKA Berlin, the Berlin Public Prosecutor’s Office and Germany’s BSI were brought into the investigation and forensic response.
23 August — Systems reconnected
The two affected administrations were reconnected to the state network after additional security measures. Increased monitoring and forensic investigation continued.
26 August — More data loss discovered
Forensic investigation identified additional data exfiltration. Berlin stated that personal or other non-public information could not yet be ruled out.
28 August — Rhysida claims responsibility
Rhysida publicly claimed the attack and reportedly demanded 30 Bitcoin, approximately €2 million, in exchange for the stolen data. Berlin made its position clear: it would not pay the ransom.
3 September — Publication threat
Berlin warned that the stolen information could be published. The government acknowledged that the dataset could potentially contain information belonging to employees, citizens and companies.
4 September — Data published
The ransom deadline passed and the stolen data was reportedly published. Berlin immediately began intensive forensic analysis of the released material and started preparing to identify and notify affected individuals.
5 September — Central response unit established
Berlin created a central coordination unit led by its Chief Digital Officer to coordinate analysis of the leaked information, support affected administrations and communicate with security authorities.
6 September — Another data package appears
A further package was published. Importantly, Berlin stated that it included access credentials, prompting the affected administration to strengthen protective measures.
What Was Allegedly Stolen?
This is where the story becomes much more serious.
Rhysida claimed approximately:
5.79 TB of data
1.44 million files
Reported categories include financial information, contracts, legal records, HR information, geodata, infrastructure-related files and files allegedly containing passwords.
However, there is an important distinction:
These figures and categories were claims made by the attackers.
Berlin is still conducting its own forensic assessment of the published material. Therefore, the exact scope and sensitivity of the entire dataset should not automatically be treated as independently verified.
The Real Cybersecurity Problem
The interesting part of this incident is that ransomware encryption may not be the biggest risk.
The bigger issue is:
Data exfiltration.
Once sensitive information leaves the organisation, restoring servers does not restore confidentiality.
The attack effectively becomes:
Initial compromise → Lateral movement → Data discovery → Exfiltration → Extortion → Publication → Secondary attacks
And the final stage can continue long after the original intrusion has been contained.
Leaked credentials can enable another intrusion.
Leaked employee information can enable phishing.
Leaked personal information can enable identity fraud.
Leaked infrastructure information can support reconnaissance.
That is why the 6 September disclosure of access credentials is particularly significant.
What Berlin Did Right
There are several important elements in the response.
Isolation: The affected administrations were separated from the state network.
Forensics: Investigation continued even after systems were reconnected.
Cross-agency response: LKA, prosecutors, BSI and other security authorities were involved.
No ransom payment: Berlin maintained its position that it would not be blackmailed.
Post-leak analysis: Once the information was published, the response shifted toward identifying affected people and assessing the actual impact.
Credential protection: Additional measures were introduced after credentials appeared in the subsequent data package.
What Organisations Should Learn
The biggest lesson is simple:
Ransomware protection cannot stop at backup and recovery.
Backups answer:
How quickly can I restore my systems?
They don’t answer:
What happens if the attacker already copied my data?
That requires a different control strategy.
Monitor outbound data movement.
Detect unusual access to sensitive repositories.
Implement strong identity controls and MFA.
Segment critical environments.
Limit privileged access.
Continuously monitor compromised credentials.
Have a tested incident-response and breach-notification process.
And most importantly:
Assume that ransomware can become a data-breach incident.
The Leadership Lesson
The Berlin incident demonstrates something that every CISO should communicate to leadership:
Cyber resilience is not the same as system recovery.
A company can restore every server, bring every application back online and still have a major security incident on its hands.
Because the attacker may still possess:
the data.
And once that data is published, the organisation moves from incident recovery to long-term exposure management.
That is the evolution of ransomware.
Yesterday’s question was:
“Can we recover our systems?”
Today’s question is:
“What did the attacker take — and what can they do with it?”
And that is why the Rhysida–Berlin incident is worth watching beyond the ransomware headline.
The investigation is still ongoing, and Berlin has explicitly warned that not every claim circulating online has been verified.
The ransomware attack may have started in August.
The security consequences could last for years.



