Berlin’s city administration is dealing with a major extortion campaign following a high-impact Rhysida ransomware attack that resulted in the exfiltration of nearly 6 terabytes of municipal data. The attack, initially detected in mid-August after suspicious activity was spotted within the network of the Senate Department for Mobility, Transport, Climate Protection and the Environment, culminated in the threat actors listing the municipality on their public data leak site on August 28. Berlin Mayor Kai Wegner has confirmed the city will not pay the ransom demand, prompting joint investigations by the State Criminal Police Office (LKA), the public prosecutor’s office, and German federal cyber security authorities.
The Scope and Blast Radius of Exfiltrated Data
The Rhysida operators claim to have stolen 5.79 TB of data—comprising roughly 1.44 million individual files—from Berlin’s administrative networks. The compromised dataset represents one of the most severe administrative spillage events affecting a European capital in recent years. Threat actors accessed records spanning government operations, legal affairs, financial ledgering, human resources, mapping records, public health data, and contractual archives.
Beyond general municipal paperwork, the specific assets exfiltrated expose both individual citizens and critical municipal operations to long-term risk:
- Administrative & Identity Assets: Thousands of names, email addresses, phone numbers, identity documents, administrative-offense files, and 148 IBANs.
- High-Privilege Credentials: Plaintext credentials, payment-system access keys, database accounts, password vaults, and personal credentials belonging to senior government officials.
- Sensitive Government Records: Documents relating to disciplinary proceedings, internal email archives, SQL database dumps, and classified Bundesrat committee records detailing procedures for handling restricted material.
- Critical Infrastructure Documentation: Detailed security assessments covering Berlin’s municipal water supply, as well as over 3,200 documents protected under non-disclosure agreements (NDAs).
The exposure of municipal water supply security assessments elevates this incident from a standard privacy breach to a physical infrastructure security issue. While Senator Iris Spranger assured the public that technical environments supporting the upcoming Berlin House of Representatives election remain secure and show no evidence of election data tampering, the compromise of password vaults and high-level administrative credentials creates an extensive credential-spillover radius across connected state systems.
Rhysida TTPs and the Initial Access Problem
Active since mid-2023, Rhysida operates as an opportunistic Ransomware-as-a-Service (RaaS) model with a penchant for targeting public sector bodies, healthcare entities, educational institutions, and critical infrastructure operators. The group relies on double-extortion tactics, combining full-volume file encryption with the threat of leaking exfiltrated stolen data. To maximize extortion pressure on public sector entities, Rhysida frequently leverages regulatory framework threats—giving Berlin four days to pay while citing potential General Data Protection Regulation (GDPR) fines as leverage.
While the exact entry vector for this breach remains undisclosed, forensic investigations indicate that data exfiltration occurred primarily between August 7 and August 12, prior to the affected Senate departments being isolated from the central state network on August 14. Historically, Rhysida threat actors gain initial footholds through compromised VPN or RDP credentials, unpatched network devices, targeted phishing, or trojanized software—such as malicious Microsoft Teams installers previously observed in campaigns tracked by security researchers.
Once initial access is secured using valid credentials, traditional endpoint protection tools struggle to differentiate legitimate administrative work from malicious activity. Attackers exploit living-off-the-land binaries (LoLBins), administrative tools like PowerShell and PsExec, and open-source utility tools to dump credentials, disable security controls, and navigate laterally without triggering static signature alerts. When threat actors operate with valid high-privilege credentials, automated security prevention rates drop significantly, allowing exfiltration of multi-terabyte datasets over multi-day windows before detection triggers a network isolation response.
Containment and Remediations
Because the breach included stolen password vaults, plain-text login credentials, and database access tokens belonging to senior leadership, containment cannot rely solely on network segment isolation. Municipal security teams must treat all administrative domains linked to the impacted Senate departments as fundamentally untrusted until credential resets and identity architectures are completely remediated.
Defenders managing government or public-sector networks connected to affected German municipal services should prioritize the following immediate actions:
- Global Credential Invalidation: Force enterprise-wide password resets for all accounts associated with the Berlin administrative domain, specifically targeting service accounts, database administrators, and password vault master keys.
- Enforce Phishing-Resistant MFA: Eliminate SMS and push-notification multi-factor authentication in favor of FIDO2/WebAuthn hardware tokens across all VPN, remote access, and administrative control panels to neutralize stolen plaintext credentials.
- Re-evaluate OT/IT Interconnections: Audit network boundaries separating corporate and administrative municipal networks from operational technology (OT) monitoring systems—specifically water distribution networks—to verify strict air-gapping or zero-trust access policies.
- Active Directory Trust Audits: Re-assess cross-forest and cross-domain trusts between the Senate Department for Mobility, Transport, Climate Protection and the Environment and other state entities to prevent lateral credential usage.
Related content
Stolen Credentials on Personal Device Expose Florida DMV Records to ShinyHunters
Security NewsNorth Carolina Ports Cyberattack Disrupts Logistics at Wilmington and Inland Hubs
ResearchWhat Changed in Ransomware Tradecraft This Year
ResearchThe Bureaucracy of Extortion: Where Real Leverage Lies in Ransomware Negotiations
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call