Rhysida Ransomware Gang Leaks 6 TB of Berlin Government Data After Ransom Refusal
Rhysida exfiltrated ~5.8 TB of Berlin state‑administration files and published them after the government declined a 30‑Bitcoin ransom. The leak includes personal, payroll, credential, and classified data, underscoring the need for continuous incident‑response evidence and control‑mapping for audit readiness.
ADTP Breach Watch· September 7, 2026· Security Affairs
SeverityCritical
Type🏛️ Ransomware
ConfidenceHigh
ReportedSep 7, 2026
Government & Public SectorPublic sector agenciesCritical‑infrastructure operatorsAny organization handling classified or personal data in Germany/EUMalware
What happened
In late August 2026 the Rhysida ransomware group compromised Berlin’s administrative network, stole roughly 5.8 TB of data across 1.44 million files, and, after a 30‑Bitcoin ransom was refused, posted the dump on a dark‑web leak site. The dataset contains personal identifiers, payroll records, plaintext credentials, classified‑material handling documents, and critical‑infrastructure vulnerability analyses.
Why it matters for trust and compliance
The breach illustrates why a continuously‑validated incident‑response and recovery control, backed by immutable logging and a centralized evidence repository, is essential for audit readiness and regulatory compliance.
Provides a defensible audit trail of detection, containment, and remediation actions.
Enables rapid mapping of incident evidence to the incident‑response control objective across multiple frameworks.
Who is affected
Public sector agenciesCritical‑infrastructure operatorsAny organization handling classified or personal data in Germany/EU
Recommended actions
Activate and test your incident‑response playbook; ensure all steps are documented.
Enable immutable logging for privileged accounts and store logs in a tamper‑evident repository.
Map the incident‑response control objective to your framework of record and collect supporting evidence in a Trust Center.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.