HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Ransomware

Rhysida Ransomware Gang Claims 5.79 TB Theft from Berlin Government Network

Berlin’s administration confirmed that the Rhysida ransomware group exfiltrated roughly 5.79 TB of sensitive data, including credentials and infrastructure records. The breach underscores the need for robust incident‑response evidence and continuous access‑control monitoring for audit readiness.

Verisq™ Intelligence · 📅 August 31, 2026 · 📰 bleepingcomputer.com
🔴
Severity
Critical
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Berlin Confirms Data Theft After Rhysida Ransomware Attack Claims

What Happened – The Rhysida ransomware gang announced on 28 August that it had exfiltrated ≈5.79 TB of data (about 1.44 million files) from Berlin’s municipal administration. The stolen material includes government, legal, financial, HR, health, and critical‑infrastructure records, as well as plaintext credentials and payment‑system data. Berlin’s authorities have confirmed the breach and are investigating; the city has refused to pay the ransom.

Why It Matters for Trust & Control Assurance

  • The incident illustrates the consequences of insufficient incident‑response planning – a continuous‑control program must document detection, containment, and forensic evidence to satisfy auditors.
  • Credential theft and large‑scale exfiltration highlight gaps in access‑control monitoring; real‑time logging and automated alerts are core evidence for control‑assurance frameworks.
  • The public extortion lever (threat of GDPR‑related leaks) shows why organizations need defensible audit trails that prove timely breach notification and remediation.

Who Is Affected – Public‑sector bodies (state governments, municipal administrations) and any downstream partners that process Berlin’s data (e.g., cloud service providers, payroll processors).

Recommended Actions

  1. Activate your incident‑response playbook; document every containment step and preserve logs for forensic review.
  2. Conduct a rapid credential‑access review – rotate privileged passwords, enforce MFA, and verify that privileged‑account activity is fully logged.
  3. Map the breach to the relevant control objective (incident response & access‑control monitoring) across your framework of record and collect evidence for audit readiness.

Technical Notes – The exact entry vector has not been disclosed; prior Rhysida campaigns have used malicious Microsoft Teams installers. The attackers claim to have exfiltrated plaintext credentials, database dumps, and IBANs. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →