HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Ransomware

Rhysida Ransomware Group Claims 5.79 TB Data Theft from Berlin State Government Ahead of Election

Berlin’s state government confirmed a ransomware extortion attempt after Rhysida announced the theft of 5.79 TB of data, including personal and classified records. The incident highlights the need for SOC 2‑aligned incident‑response controls and continuous audit evidence.

Verisq™ Intelligence · 📅 August 29, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

Rhysida Ransomware Group Claims 5.79 TB Data Theft from Berlin State Government Ahead of Election

What Happened — The Rhysida ransomware gang announced on its leak site that it exfiltrated roughly 5.79 TB of data (≈1.44 million files) from Berlin’s state‑government administrative network. The stolen material allegedly includes personal data for 12,076 individuals, payroll and personnel files, plaintext credentials, and documents classified as state secrets. Berlin officials have publicly refused to pay the ransom.

Why It Matters for Compliance & Audit Readiness

  • A ransomware‑driven data breach directly tests the “Security” principle of SOC 2: incident‑response, logical‑access controls, and evidence of timely detection.
  • Continuous control mapping and immutable audit evidence are essential to demonstrate that the organization had effective safeguards and a documented response plan before the attack.
  • Verisq’s Control‑Mapping capability lets you align your incident‑response and data‑protection controls to SOC 2 criteria and automatically collect the logs and tickets needed for a defensible audit trail.

Who Is Affected — Public‑sector bodies (state governments), critical‑infrastructure stakeholders, and any third‑party service providers handling Berlin’s data.

Recommended Actions

  • Verify the scope of the breach against your asset inventory; map affected assets to SOC 2 “Security” controls (CC6.1, CC6.2, CC6.3).
  • Gather and preserve logs, forensic images, and communication records as continuous evidence for audit readiness.
  • Review and harden privileged‑access management, especially for systems cited (GebäudAtlas, PAYONE, Z_ADMIN).
  • Update your incident‑response playbook and conduct a tabletop exercise focused on ransomware extortion.

Source: Security Affairs

Technical Notes

  • Attack vector: ransomware malware deployed against the government’s administrative network (attack vector code = MALWARE).
  • Data types exfiltrated: PII (emails, phone numbers, IBANs), payroll, personnel files, classified documents, infrastructure vulnerability analyses.
  • No specific CVE or vulnerability disclosed; the group leveraged likely phishing or credential‑theft to gain initial access.
📰 Original Source
https://securityaffairs.com/198064/cyber-crime/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →