Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Berlin Data Leak: What Rhysida Published, and What Is Still Unresolved
Sep 22, 2026
12 Mins Read
Moon
Summarize with:

Berlin Data Leak: What Rhysida Published, and What Is Still Unresolved

This post consolidates what has been confirmed by the State of Berlin, what remains the threat actor’s own claim, and what the published file listing itself shows.

In August 2026, the Rhysida extortion group breached Berlin’s state network and copied roughly 1.44 million files from two of the city-state’s Senate administrations. Berlin disconnected the affected departments on August 14, refused a ransom demand of 30 BTC, and on September 4 the group released the archive to public access on its Dark Web leak site.

What came out was not a single database export but a bulk capture of everyday working directories and mailboxes: personnel and legal case files, identity-document scans, payroll material, planning archives, and thousands of certificates and credential files. Weeks later, the forensic evaluation and the notification of affected people are both still running, which is what makes this worth revisiting rather than filing away.

Dark Web listing of the alleged leak

Dark Web listing of the alleged leak

Key Takeaways

  • Scope: Two Berlin Senate administrations were affected, not the entire state administration. Berlin’s own account describes the material as predominantly unstructured data from shared and personal employee directories rather than data drawn from specific line-of-business applications
  • Volume: The leak-site catalogue lists 1,439,893 files totaling 5.26 TB, while the actor claims 5.79 TB. The 5.8 TB figure repeated across most coverage is the actor’s own number rounded up
  • The core problem is secrets, not documents: The archive carries thousands of certificate and private-key stores, dozens of password-manager databases, and hundreds of files whose names advertise plaintext credentials
  • Attribution remains formally open: Berlin has confirmed that data was stolen and that it received an extortion demand, but officials have not publicly attributed the attack or verified the claims about the volume or contents of the stolen material
  • Refusing to pay did not reduce the exposure: It converted an extortion problem into a credential-reuse and notification problem that is still running weeks later

What Happened

Date Event
Aug 7-12, 2026 The main part of the data outflow occurred in this window, according to Berlin’s forensic findings.
Aug 14 The IT systems of the two affected administrations, urban development, building and housing (SenStadt) and mobility, transport, climate protection and environment (SenMVKU), were precautionarily disconnected from the state network to prevent further spread. Both remained severed until August 23, stalling housing benefit and family support payments.
Aug 28 The threat actor claimed the intrusion publicly, and Berlin confirmed that criminals were attempting to extort the city. The State Criminal Police Office, the public prosecutor’s office and federal security agencies opened investigations.
Aug 31 – Sep 3 The Senate Chancellery named the two affected departments, stated that a group using the name Rhysida had claimed responsibility and claimed roughly 5.7 TB of stolen data, and said there was then no evidence the state network remained infiltrated.
Sep 4 The auction, opened at 30 BTC, ended after several days, and the data was released. Berlin activated a central crisis unit to assess the material and coordinate notification of affected citizens and businesses.
Sep 5 Germany’s Federal Office for Information Security warned of an elevated cyber threat, specifically a phishing wave and the risk of disinformation ahead of the September 20 state election.
Sep 6-7 A further trove containing stolen login credentials appeared online and triggered a separate investigation.
Sep 14 Berlin’s public information page was updated to state that the election environment had been examined and that the state election was not considered at risk.
Sep 20 The state election was held.

What the Published Listing Actually Contains

SOCRadar’s Dark Web Team analyzed the published path listing for this leak-site entry. All figures below are aggregate counts derived from file and folder naming. No leaked file contents were opened, and no identifiers, paths or hostnames are reproduced here.

Composition

The archive behaves like a bulk capture of network file shares and mailboxes across two administrations rather than a database export. Office documents dominate, with roughly 367,000 PDFs, around 257,000 Word files and roughly 57,000 spreadsheets. Mail is the second pillar: more than 166,000 individual mail objects plus approximately 2,200 mailbox archive files, corresponding to several hundred user accounts. Bulk geospatial and land-use planning material accounts for another block of roughly 100,000 files and is largely non-personal.

Currency

Filename dates span four decades, but roughly 90,000 files carry dates in 2023 through 2026, with 2025 and 2026 each accounting for more than 23,000. This is a live working environment, not an archived backup set.

The secrets footprint

This is what distinguishes the incident from a conventional records leak:

  • Certificate and private-key stores: Approximately 3,900 certificate and key container files, concentrated in tele-work and IT administration shares and consistent with remote-access and secure-mail use
  • Password-manager databases: Two dozen password-safe files, which corroborates the actor’s claim of captured password safes
  • Plaintext credential files: Several hundred files whose names explicitly describe stored passwords, login details or administrative account lists
  • Internal infrastructure documentation: Server inventories, directory service and firewall documentation, and network diagrams, alongside internal hostnames embedded in Windows shortcut targets

Sensitive content categories

Assessed from structure, the highest-severity clusters are special-category personnel data (occupational health and reintegration records, disability status, payroll and tax certificates), identity-document scans, disciplinary and litigation case files, payment and bank-detail material, and critical-infrastructure planning material relating to water supply contingency and civil protection. Media reporting on the leak has independently described personnel files, pay slips, applications carrying original signatures, and vulnerability assessments of the drinking water supply.

Collection window

Filename activity rises through normal weekday patterns until August 11, 2026, then drops to near zero. That is consistent with the officially reported August 7-12 outflow and the August 14 disconnection, and it points to a single sustained collection run rather than repeated access over months.

Why the Exposure Outlives the Incident

Three effects continue long after systems are restored.

Credential reuse:

A rotated password is a closed door; an unrotated certificate sitting in a public archive is an open one. With thousands of key containers and hundreds of credential files in circulation, every account, remote-access endpoint and secure-mail integration reachable from the affected shares has to be treated as compromised until proven otherwise. Reporting on the second tranche indicates claimed working plaintext credentials for building-management and e-payment systems and for administrative accounts.

Reconnaissance value:

Server inventories and directory documentation lower the cost of a repeat intrusion even after every credential has been rotated, because the internal layout no longer has to be discovered. Rotation closes accounts; it does not un-publish a network diagram.

Notification at scale:

The Berlin data protection authority has advised potentially affected people to change passwords, monitor account and card activity, and treat unusual contact attempts with caution, and identified individuals are to be informed by the responsible Senate administration once the evaluation is complete. The same authority has noted that the exact extent of the data outflow is still under investigation and that individual exposure cannot yet be confirmed in every case. That gap between publication and confirmation is precisely the window targeted phishing exploits, which is why the federal warning paired the leak with an expected phishing wave.

What Is Confirmed, and What Is Not

Confirmed by Berlin: the two affected administrations, the August 7-12 outflow window, the August 14 disconnection and the August 23 reconnection, the extortion attempt, the refusal to pay, the publication on September 4, and the assessment that the material is largely unstructured share and home-directory content rather than application data.

Actor claim only: the total volume, and the itemized counts of email addresses, individuals, passwords, health records and bank identifiers that circulated widely in coverage. The published structure is directionally consistent with those counts, but they remain the actor’s own arithmetic and should be cited as such.

Reported but unconfirmed: the initial access vector. German reporting attributes entry to a phishing mail opened in the transport administration, after which the malware spread unnoticed for weeks until unusual domain controller activity revealed the intrusion. Berlin has not confirmed this account. The actor’s documented pattern in the joint CISA, FBI and MS-ISAC advisory AA23-319A also includes authenticating to internal VPN endpoints with valid stolen credentials at organizations that had not enforced multifactor authentication, along with Zerologon (CVE-2020-1472) and ordinary phishing.

Not established: any political motive. There is no evidence the attack was aimed at influencing the state election, and it is currently assessed as financially motivated, consistent with the ransom demand and auction model.

What Public Sector Organizations Should Take From This

  • Treat exposed secrets as burned, not as leads to investigate: Rotate every certificate, key and account reachable from the affected shares before triage, not after it
  • Inventory where plaintext credentials live: Password briefs, handover documents and administrative account spreadsheets on general-purpose file shares are the single highest-leverage cleanup available in most administrations, and they are what turns a records leak into an intrusion-reuse problem
  • Segment flat networks: A flat, barely segmented state network lets malware that establishes itself anywhere travel as far as the domain controller
  • Close the detection-to-containment gap: In this case roughly a week separated the start of the data outflow from the disconnection of the affected departments
  • Separate critical-infrastructure material from general file shares: Water supply contingency and civil protection planning held in ordinary departmental directories inherits the exposure of everything around it
  • Plan the notification phase in advance: The obligation to inform data subjects arrives while forensic evaluation is still incomplete, and the resulting silence is itself an attack surface that phishing campaigns move into

Berlin’s entry on SOCRadar’s Ransomware Intelligence tracker records the leak-site posting and current status for this case.

Conclusion

Berlin’s refusal to pay was the right call, and it changed nothing about publication. That is the part worth carrying forward: once an actor holds the data, the decision on the ransom only determines who profits, not whether the exposure happens.

What remains is a long-tail problem that no incident-response timeline closes cleanly, because the archive is now permanently in circulation and its most dangerous contents are not the records that trigger notification duties but the certificates, password files and infrastructure documentation sitting in ordinary working directories.

For every other public administration running a flat network and decades of accumulated file shares, the exposure inventory that matters is the one taken before an intrusion, not the one reconstructed from a leak site afterwards.

SOCRadar’s Germany report, sets out the wider threat landscape surrounding the country. Click here to see the threat landscape of Germany.

Frequently Asked Questions About the Berlin Data Leak

Who was affected by the Berlin data leak?

Two Senate administrations: mobility, transport, climate protection and environment, and urban development, building and housing. Employees of those administrations, residents and companies that dealt with them may all appear in the material.

How much data was published?

The leak-site catalogue lists 1,439,893 files and 5.26 TB. The actor claims 5.79 TB. Berlin has confirmed the data theft but has not published a verified inventory.

Were Berlin’s systems encrypted?

Exfiltration appears to have preceded any encryption, and there is no indication that systems were encrypted. This was extortion by publication threat rather than a conventional ransomware outage.

Who is Rhysida?

Rhysida is a Ransomware-as-a-Service extortion operation active since May 2023, associated with attacks on government, education, healthcare and cultural institutions, including the British Library, the Chilean Army and Holding Slovenske Elektrarne. Its leak-site pattern is a fixed countdown and single-buyer auction, followed by free public release when the demand is not met.

Did Berlin pay the ransom?

No. The demand was 30 BTC, roughly 2 million euros at the time, and Berlin stated publicly that it would not submit to extortion. The data was released after the deadline lapsed.

Did the leak affect the September 20 state election?

The responsible bodies examined the election environment and confirmed that the election was not considered at risk. There is also no evidence the attack was politically motivated.

How will affected individuals find out?

Identified individuals are to be informed by the responsible Senate administration once the evaluation of the published packages is complete, in line with German and European data protection law. Berlin maintains a central information page that is updated as the situation develops.

Is it legal to download the leaked files?

No. Acquiring or redistributing the data in order to enrich oneself or harm others is punishable as data handling under Section 202d of the German Criminal Code. This is general information, not legal advice.

What should organizations connected to these administrations do now?

Assume any password, certificate or key associated with the affected administrations may be exposed, prioritize credential and certificate rotation for connected accounts and services, review remote-access and secure-mail integrations that rely on certificates issued for these environments, and heighten monitoring for targeted phishing and business email compromise referencing the affected administrations or named officials.

Methodology

Analysis was performed on the published file path listing only. No leaked file contents or record-level personal data were opened or reproduced, and no identifiers, internal hostnames or file paths appear here. Category figures are keyword and path matches over file and folder names, and indicate presence and scale rather than verified record counts. Volumes and itemized counts attributed to the threat actor are treated as claims unless confirmed by the affected organization.