Home › Intelligence › Brief
BREACH BRIEF🔴 Critical Ransomware

Rhysida Ransomware Gang Leaks 6 TB of Berlin Government Data After Ransom Refusal

Rhysida exfiltrated ~5.8 TB of Berlin state‑administration files and published them after the government declined a 30‑Bitcoin ransom. The leak includes personal, payroll, credential, and classified data, underscoring the need for continuous incident‑response evidence and control‑mapping for audit readiness.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Rhysida Ransomware Gang Leaks 6 TB of Berlin Government Data After Ransom Refusal

What Happened – The Rhysida ransomware group breached Berlin’s state‑administration network in late August 2026, exfiltrated roughly 5.8 TB of data (≈1.44 million files) and, after the government refused a 30‑Bitcoin ransom, published the dump on a dark‑web leak site. The leak includes personal data of over 12 k individuals, payroll and HR records, plaintext credentials, classified‑material handling documents, and vulnerability analyses of critical infrastructure such as the water supply.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuously‑validated incident‑response and recovery control that can detect, contain, and document ransomware activity in real time.
  • Highlights the importance of evidence‑ready logging and forensic data to satisfy audit requirements across frameworks (e.g., NIST CSF 2.0) and to prove due‑diligence to regulators.
  • Shows that a robust control‑mapping capability can translate raw incident data into the control objectives auditors expect, enabling rapid evidence collection and defensible reporting.

Who Is Affected – Public‑sector bodies, municipal administrations, critical‑infrastructure operators, and any organization handling classified or personal data in Germany (and potentially EU partners).

Recommended Actions

  • Activate and test your incident‑response playbook; verify that detection, containment, and eradication steps are documented and exercised.
  • Ensure immutable logging is enabled for privileged accounts and that logs are retained in a tamper‑evident store for forensic analysis.
  • Conduct a gap analysis against the “incident response and recovery” control objective, map findings to your framework of record, and collect the required evidence in a centralized Trust Center.

Technical Notes – The attack vector was a ransomware payload delivered via a compromised administrative system (specific delivery method not disclosed). The group exfiltrated data over several weeks, then posted the dump on a dark‑web site. No CVE identifiers were released, but the breach involved plaintext credentials for systems such as GebäudAtlas, PAYONE, and Z_ADMIN accounts. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/198545/cyber-crime/berlin-ransomware-leak-exposes-state-secrets.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →