Home › Intelligence › Brief
BREACH BRIEF 🟠 High Ransomware

Rhysida Ransomware Gang Double‑Extorts Berlin Senate, Demands 30 BTC

The Rhysida ransomware group breached the Berlin Senate, encrypting systems and stealing roughly 5.8 TB of data before demanding 30 BTC. The incident underscores the need for a tested incident‑response program and strong credential controls to satisfy audit and regulatory expectations.

Verisq™ Intelligence · 📅 September 03, 2026 · 📰 databreachtoday.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
databreachtoday.com

Berlin Rejects Rhysida Ransomware Blackmail: Double‑Extortion Hits City‑State Government

What Happened — On 14 August 2026 the Berlin Senate’s network was infiltrated by the Rhysida ransomware gang. The attackers encrypted critical systems, exfiltrated an estimated 5.8 TB of public and non‑public data, and demanded 30 BTC, threatening to publish the data by the following Friday.

Why It Matters for Trust & Control Assurance

  • The episode demonstrates why a documented, continuously‑tested incident‑response program is essential; it provides the procedural backbone and evidentiary trail auditors expect after a ransomware event.
  • Automated collection of logs, forensic snapshots, and backup verification supplies the defensible evidence needed for audit readiness and regulatory reporting.
  • Storing credentials in plaintext violates a core access‑control objective that maps to multiple frameworks, highlighting a control gap that can be closed with a single remediation effort.

Who Is Affected — Government agencies in Germany; any organization that retains plaintext credentials or lacks a tested ransomware response plan.

Recommended Actions

  • Validate that your incident‑response playbook includes ransomware‑specific detection, containment, and evidence‑preservation steps, and run tabletop exercises quarterly.
  • Perform an immediate audit of all credential stores; migrate any plaintext secrets to a managed secret‑management solution with strict access controls.
  • Review backup and recovery procedures to confirm they meet recovery‑time objectives and can be demonstrated to auditors as part of a control‑assurance audit.

Source: DataBreachToday

Technical Notes — Attack vector: ransomware malware deployment followed by credential theft (plaintext storage). Exfiltrated data includes 16 389 emails, 11 963 phone numbers, 148 banking codes, tens of thousands of contracts, judicial documents, and thousands of personnel files. No public confirmation of data leakage has been made yet. Source: same article

📰 Original Source
https://www.databreachtoday.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731 ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →