Berlin Confirms Data Theft Following Rhysida Ransomware Attack Claim
City administration confirms extortion attempt after ransomware gang publishes city on data leak site

Key Takeaways
- Berlin city administration confirmed data theft following Rhysida ransomware attack claim
- Rhysida ransomware gang listed Berlin on their data leak site
- Extortion attempt confirmed by city administration
- Sensitive government data potentially exposed
- Incident reflects ongoing ransomware threat to government infrastructure
Quick answers
- What happened?
- Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. The incident marks another government target in the ongoing ransomware threat landscape.
- What should defenders do?
- Berlin city administration and other government entities should implement robust backup procedures, network segmentation, and enhanced monitoring. Incident response plans should be activated, and systems should be hardened against ransomware infiltration. Regular security assessments and patch management are recommended to reduce attack surface.
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. According to reports, the Rhysida ransomware group has published Berlin on their data leak site, suggesting that stolen data from the city's administration systems has been compromised. The confirmation comes as the city administration acknowledges the breach and faces an extortion attempt. The incident highlights the growing threat of ransomware attacks targeting government infrastructure. BleepingComputer reported on the development, noting that the Rhysida gang's appearance on the data leak site indicates potential exposure of sensitive government data. The exact scope and sensitivity of the stolen data remain unverified, but the confirmation marks a significant security incident for the German capital's municipal systems. City administrators are likely implementing security measures to mitigate further compromise and address the extortion attempt.
Security Details
Rhysida ransomware gang listed Berlin on their data leak site, indicating stolen data from city administration systems. The attack vector and initial compromise method remain under investigation. No specific CVEs or software vulnerabilities have been publicly attributed to this incident yet.
Mitigation
Berlin city administration and other government entities should implement robust backup procedures, network segmentation, and enhanced monitoring. Incident response plans should be activated, and systems should be hardened against ransomware infiltration. Regular security assessments and patch management are recommended to reduce attack surface.
Sources
BleepingComputer
Berlin confirms data theft after Rhysida ransomware attack claims
Aug 31, 2026 · 13:30
Original link
Related Security News

Bitget Reports $388M Loss Following Exploitation of Third-Party Security Product Flaw
Bitget disclosed that an attacker stole approximately $388 million by exploiting a vulnerability in a third-party security product integrated into the exchange's infrastructure. The threat actor used the flaw to obtain high-level internal credentials, which were subsequently used on September 24 to issue fraudulent withdrawal commands to Bitget's wallet system. The exchange confirmed that most user funds remain secure, though the full extent of exposure is under investigation.




