Berlin Cyberattack Exposes German Critical Infrastructure Data
A Rhysida cyberattack on Berlin exposed 5.8 TB of data, including information linked to critical infrastructure and potentially defense-related facilities.
The Rhysida ransomware group has published approximately 5.8 terabytes of data stolen from Berlin's state administration, with German authorities investigating whether the leak includes information relevant to critical infrastructure, defense facilities and the Bundeswehr. The attackers accessed systems between August 7 and 12, 2026, and released the stolen material after Berlin refused a ransom demand of 30 Bitcoin, valued at approximately €2 million.
The Federal Office for Information Security, known by its German abbreviation BSI, has warned that the disclosure could increase security risks for affected organizations and individuals. German authorities currently assess the attack as financially motivated rather than politically directed, but the information released could still have national security implications independent of the attackers' original motive.
5.8 TB stolen from two Berlin government departments
The attackers gained access to parts of Berlin's state network from August 7 through August 12 without immediate detection. The administration identified the intrusion on August 14 and publicly disclosed it on August 17.
The breach affected the Senate Department for Urban Development, Building and Housing and the Senate administration responsible for mobility, transport, environment and climate protection. Berlin temporarily disconnected the affected departments from the state network while forensic investigations proceeded, before restoring their connections later in August.
Rhysida claimed possession of approximately 1.44 million files totaling about 5.8 TB. Material identified in reporting includes personnel files, employment records, evaluations, timesheets, operational documents and recruitment-related information.
The group demanded 30 Bitcoin and threatened to release or sell the information if Berlin did not pay. The Berlin Senate rejected the demand, and the stolen material subsequently appeared on Rhysida's dark-web infrastructure.
Leak may include defense and wartime infrastructure information
The potential security implications extend beyond the exposure of personal government records.
German reporting indicates that some of the compromised material concerns facilities that would require protection during a defense contingency. Reported examples include hospitals, fuel depots, emergency power installations, heating plants, electrical substations, water facilities and defense-industry sites.
Tagesschau reported that material concerning prisons, water utilities, defense companies, the Bundeswehr and Berlin's interior administration may also be among the leaked files. German authorities were still assessing the dataset as of September 5, meaning the complete scope and operational value of the exposed information remain unconfirmed.
The Bundeswehr's Operational Command indicated that authorities were evaluating possible security consequences and would implement measures required to preserve military security following that assessment. Information is being exchanged among the relevant authorities through Germany's national cyber defense structures.
Federal authorities are also involved in the investigation. The Federal Office for Information Security, Federal Criminal Police Office and Federal Office for the Protection of the Constitution are supporting Berlin, while findings are being consolidated through Germany's National Cyber Response Centre. Federal government systems were not known to have been compromised as of September 5.
Rhysida has targeted governments and critical sectors since 2023
Rhysida is an established ransomware operation rather than a newly identified actor.
The U.S. Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation and Multi-State Information Sharing and Analysis Center documented Rhysida activity against government, healthcare, education, manufacturing and information technology organizations in a joint cybersecurity advisory. The agencies tracked the ransomware's operational activity from May 2023 and recommended measures including multifactor authentication, network segmentation and rapid remediation of known exploited vulnerabilities.
Reuters reported in August that Rhysida had claimed nearly 280 victims worldwide, including government institutions, businesses, healthcare organizations and educational institutions. Previous prominent victims attributed to the group include the British Library and the Chilean Army.
The available evidence nevertheless requires a distinction between cybercrime and state-sponsored cyber operations.
Berlin authorities have said they have no evidence establishing links between Rhysida and the Russian state, although connections to Russia have not been categorically excluded. BSI currently assesses the Berlin operation as financially motivated.
That distinction does not eliminate the intelligence value of the stolen information. Once operational, infrastructure or defense-related documents become publicly available or circulate among third parties, actors other than the original ransomware group can potentially exploit them.
Berlin breach comes amid pressure on German infrastructure security
The breach comes as Germany confronts a broader series of physical and cyber threats against infrastructure.
German authorities have investigated sabotage incidents involving electricity infrastructure, transport networks and other strategic facilities. In early September, authorities were investigating deliberate disruptions at power infrastructure in Brandenburg and North Rhine-Westphalia, while other recent incidents have increased concern about Germany's exposure to hybrid threats.
The Berlin incident differs because authorities have not attributed it to a foreign government. Its significance for national resilience instead comes from the possibility that a criminal intrusion created a secondary intelligence vulnerability by releasing information about infrastructure and organizations relevant to German security.
The incident also illustrates the overlap between civilian administration and defense preparedness. Municipal and regional authorities hold planning, infrastructure, personnel and facility information that can become security-relevant during military mobilization, civil protection operations or a national defense contingency.
Germany implemented its NIS2 legislation on December 6, 2025, expanding cybersecurity registration and incident-reporting obligations for covered companies and authorities. The Berlin breach is likely to intensify scrutiny of how government networks handling information connected to critical infrastructure are segmented and protected.
Stolen data creates phishing and election-security risks
BSI has separately warned that the leaked information could support targeted phishing attacks against people and organizations connected to the compromised departments. Personal and organizational information can make fraudulent communications more convincing and provide attackers with additional material for follow-on intrusions.
The timing creates another concern. Berlin will hold elections to its House of Representatives on September 20, 2026, and BSI has warned about the potential use of stolen documents in hack-and-leak operations in which authentic material can be selectively released, altered or presented without context to influence political debate.
Berlin's election authorities have said that, based on the information available, the election environment itself has not been affected, including preparations, voting procedures and the process leading to publication of preliminary results.
The immediate investigation will therefore focus not only on how Rhysida entered the Berlin network, but also on exactly which documents left government systems and who or what they concern. For Germany's security authorities, identifying defense-related and critical-infrastructure information within 1.44 million files will determine whether a financially motivated ransomware attack has produced longer-term national security exposure.
Berlin cyberattack: Key questions
How much data did Rhysida steal from Berlin?
Rhysida obtained approximately 1.44 million files totaling about 5.8 TB from two Berlin Senate administrations. The unauthorized data transfer occurred between August 7 and 12, 2026.
Did the Berlin cyberattack expose Bundeswehr information?
German reporting indicates that the leaked dataset may contain information concerning the Bundeswehr, defense companies and infrastructure relevant to a defense contingency. Authorities were still reviewing the files as of September 5, so the complete extent of military-related exposure has not been established publicly.
Is Rhysida linked to Russia?
German authorities have not established a connection between Rhysida and the Russian state. BSI currently assesses the Berlin attack as financially motivated, although Berlin officials previously said connections to Russia could not be completely excluded.
Why does the Berlin data leak matter for German defense?
The potential exposure of information concerning fuel depots, emergency power systems, water facilities, hospitals and defense-industry sites creates a security issue beyond ransomware itself. Such infrastructure supports civilian resilience and can also become relevant to military mobility, logistics and continuity of government during a defense contingency. The precise operational sensitivity of the leaked Berlin material remains under assessment.
7. NEWSLETTER BLURB
A ransomware attack on Berlin has developed into a broader German security issue. Rhysida published 5.8 TB of stolen government data, and authorities are now examining whether the leak exposed information concerning defense companies, the Bundeswehr and infrastructure that would require protection during a defense contingency.