CYOPS · Cyber Operations

Berlin’s harder problem started after the data was published

Refusing to pay ended the negotiation and began a different operation: reading 1.4 million files of unstructured shared-drive material to work out who has to be told. Most incident plans stop at recovery.

The decision and what followed it

The State of Berlin refused to pay 30 bitcoin, roughly €2m, to the Rhysida group, and on 4 September the group published what it had taken from the state network [4][2]. Reporting has concentrated on the refusal. The more instructive part of this incident is what the administration has had to stand up since.

Berlin's own account is specific about the intrusion. The substantive data outflow occurred between 7 and 12 August 2026; on 14 August the IT systems of the two affected departments — Mobility, Transport, Climate Protection and Environment, and Urban Development, Building and Housing — were precautionarily disconnected from the state network to prevent further spread [1]. The Senate Chancellery made the incident public on 17 August, with the state criminal police, the Berlin public prosecutor and the federal information security office BSI involved [10][11].

Disruption during the isolation period was concrete rather than abstract. Both departments were reachable only by telephone, and housing benefit services stopped — applications and payments alike — with payments blocked for a reported 50,000 eligible households before services were restored on 24 August [3][5].

What the leaked data actually is

One line in Berlin's citizen information page carries more operational weight than the volume figures. The material is, at current assessment, predominantly unstructured data from shared and personal directories belonging to staff of the affected authorities — not data drawn from specific line-of-business applications [1]. Personal data of state employees, citizens and companies is expected to be present [1].

That distinction determines the shape of the entire response. A breach of a defined application yields a defined record set: a schema, a row count, a population to notify. A breach of departmental file shares yields whatever a decade of officials happened to save, in whatever format, with no index. Berlin's public position is that a complete overview of the leaked data is barely possible given the volume, and that the corpus cannot simply be searched for specific terms [5].

The published volumes are attacker claims and should be handled as such. Figures of 5.79 TB and of close to 1.44 million files circulate; some accounts round to roughly 6 TB [7][9][12]. Berlin has not published an inventory of contents [12]. Claims about particular categories of document in the dump — including assertions by the security journalist Lars Winkelsdorf that the material includes defence-related planning files, and a folder concerning chemical, biological, radiological and nuclear contingency planning — are that journalist's reading of the published data, relayed through reporting, and have not been confirmed by the state [6]. They are recorded here as claims, not as established fact.

The response architecture

What Berlin has built since is worth studying by anyone who writes incident plans for a public body:

  • Dedicated command structures — the state criminal police and the transport department each established a Besondere Aufbauorganisation, the German special-purpose command structure used for major operations, with a task force running between the two departments [2].
  • A crisis unit in the urban development department coordinating all measures, a staff contact point, and an external trusted lawyer engaged as a confidential point of contact for employees on legally sensitive matters [2].
  • A central steering unit to review, verify and assess the published data and to support the work of informing affected citizens and businesses [6][5].
  • Risk-based notification of identified individuals under GDPR and the Berlin data protection act, carried out by the responsible departments as the analysis identifies them [2].

The sequence is the point. Notification obligations cannot be discharged until someone has read the corpus well enough to know who appears in it. With unstructured shared-drive material, that is a manual discovery operation of indeterminate length, conducted on data that is already public and already being read by journalists, researchers and anyone else who cares to download it. The state is racing the audience for knowledge of its own documents.

A figure worth correcting

Several accounts describe the incident as turning on a seven-day gap between detection and isolation, placing first detection on 7 August and disconnection on 14 August [8]. Berlin's own statements describe 7 to 12 August as the period of data outflow and 14 August as the date of precautionary disconnection [1], which is a claim about the attacker's dwell time, not about a week of known-but-untreated compromise. The distinction matters: one version describes a response failure, the other describes ordinary detection latency. Unless the state publishes a forensic timeline establishing when the intrusion was first known internally, the seven-day framing should be treated as unconfirmed.

Two further details are established. Passwords were among the data taken, confirmed at a press conference on 1 September, and home working was suspended for staff in the affected departments as a consequence [5]. Berlin also states there is currently no indication that the state network remains infiltrated, while forensic work continues, including on whether further data left the network [2]. The interior senator has stated that the conduct of the 20 September House of Representatives election is not affected [3][8].

What to take from it

Three things transfer to any government or large enterprise environment in this region.

  • Plan for the publication phase as a distinct operation with its own staffing, not as an appendix to recovery. Restoring services and determining what is in a public dump are different jobs with different skills, and Berlin ran both simultaneously.
  • Know what is on your file shares before someone else reads them. The exposure here is not a hardened application; it is a decade of accumulated working documents, which is exactly the estate that receives least governance attention.
  • Fix the notification path in advance. Risk-based notification against an unindexed corpus is slow by nature, and the regulatory clock does not pause for discovery.

Cyber operations close

For operations teams the transferable lesson is about the shape of the commitment. A refusal to pay is a defensible position and, on the evidence of this case, does not prevent publication — Rhysida's practice of releasing data after a refused deadline is documented in earlier cases, including the British Library [4]. What refusal does is convert an open-ended negotiation into a fixed, public, resource-intensive workstream with a statutory clock attached. Organisations that intend to refuse — which for a public authority is often the only tenable position — should cost that workstream before the incident, not after the deadline expires.

Sources

Every R3KONX article cites its primary material. 12 sources, in order of first citation. Links open the original publication.

  1. Cyberangriff auf das Landesnetz: Informationen fu00fcr Bu00fcrgerinnen und Bu00fcrger Berlin.de u2014 Der Regierende Bu00fcrgermeister, Senatskanzlei · 2026-09-10
  2. Aktuelle Lage nach dem IKT-Vorfall im Landesnetz Berlin Berlin.de u2014 Senatskanzlei press release · 2026-09-02
  3. Hackerangriff auf Landesnetz: Arbeit mit Hochdruck an Lu00f6sungen Berlin.de · 2026-08-19
  4. Rhysida Publishes Berlin Government Data After u20ac2m Extortion Demand Refused Infosecurity Magazine · 2026-09-07
  5. Cyberattacke auf Berlin ku00f6nnte gru00f6u00dfere Folgen haben als bisher gedacht heise online · 2026-09-08
  6. Berlin Ransomware Leak Exposes State Secrets Security Affairs · 2026-09-09
  7. Hackers leak nearly 6TB of sensitive Berlin government data The News International · 2026-09-05
  8. Berlin's Seven-Day Ransomware Isolation Gap Let Rhysida Steal Critical Infrastructure Data Tech Times · 2026-09-01
  9. Rhysida Ransomware Leaks 6TB of Berlin Data Tech Insider · 2026-09-12
  10. Cyber-Angriff trifft zwei Berliner Senatsverwaltungen Behu00f6rden Spiegel · 2026-08-18
  11. Cyberangriff auf Berliner Landesnetz u2013 Ausmau00df unbekannt heise online · 2026-08-17
  12. Berlin government data leak: what is confirmed Scam Checker · 2026-09-06

Researched and written by the R3KONX Analysis Desk from the cited primary material, with AI assistance in research and drafting. Methodological caveat: volumes and file counts in this case originate with the attacker and have not been independently verified; the State of Berlin has published no content inventory. Claims about the nature of specific leaked documents are reported as the assessments of the named individuals making them, not as R3KONX findings. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.