Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election — Threadlinqs Intelligence
As of 2026-08-29, Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election is a high-severity ransomware threat attributed to Rhysida, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-2206 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Rhysida · FINANCIAL
The Rhysida ransomware-as-a-service group claims to have exfiltrated 5.79TB (~1.44 million files) from two Berlin Senate departments and posted the claim to its Tor leak site on August 28, 2026,
Between August 7 and 12, 2026, unauthorized data outflows occurred from Berlin's state government network ("Landesnetz"), a fiber backbone connecting roughly 600 government, police, fire, and hospital sites. The intrusion affected two Senate departments: the Senate Department for Urban Development, Building and Housing (where the initial security gap was located, per Berlin's IT service provider ITDZ) and the Senate Department for Mobility, Transport, Climate Protection and Environment. Forensic indicators reached the Senate Chancellery around August 25-26, 2026; both departments were preemptively disconnected from the state network on August 14, 2026 and remained largely offline (phone-only external communication) until reconnection around August 23, 2026. Berlin publicly disclosed the incident on August 17-18, 2026.
On August 28, 2026, the Rhysida ransomware group posted a "Berlin, Germany" entry to its darknet (Tor) leak site, claiming 5.79 terabytes across approximately 1.44 million files, including personal data on 12,076 individuals (16,389 email addresses, 11,963 phone numbers, 148 IBANs), 5,000+ personnel and administrative-offense files, 46,500 contracts, plaintext credentials for internal systems (GebäudeAtlas, PAYONE, Z_ADMIN), court records, NDA documents, Bundesrat protocols, classified/state-secret material, water-supply vulnerability analyses, and geodata (the largest single file category, ~124,823 files). The group set a roughly seven-day countdown and demanded about 30 BTC (~€2 million). Berlin Governing Mayor Kai Wegner and Interior Senator Iris Spranger issued a joint statement refusing to pay: "The state of Berlin will not submit to extortion." Officials state that election-related systems and data were not affected, despite the timing weeks before the September 20, 2026 Berlin state parliament (Abgeordnetenhaus) election.
Rhysida is a ransomware-as-a-service operation active since at least May 2023, primarily targeting education, healthcare, manufacturing, IT, and government sectors, with prior high-profile victims including the British Library (October 2023) and Chile's army. A joint CISA/FBI/MS-ISAC advisory (AA23-319A, first issued November 2023, periodically updated) documents Rhysida's typical initial-access methods as compromised external VPN accounts lacking MFA, exploitation of the Zerologon vulnerability (CVE-2020-1472) against Active Directory domain controllers, and phishing; Security Affairs cites this advisory as the likely TTP basis for the Berlin intrusion, though the specific initial-access vector used against Berlin has not been publicly confirmed. Germany's Federal Office for Information Security (BSI), the Berlin State Criminal Police Office (LKA), and the Berlin State Prosecutor's Office are investigating; no technical network IOCs (C2 IPs/domains) specific to this intrusion have been published as of this writing.
Target sectors: government administration
Target regions: Europe, germany
Timeline
- Microsoft releases the initial patch for CVE-2020-1472 (Zerologon), later cited by CISA as a common Rhysida entry vector against Active Directory domain controllers.
- Rhysida ransomware-as-a-service operation first observed in the wild, subsequently targeting education, healthcare, manufacturing, IT, and government sectors.
- CISA, FBI, and MS-ISAC publish joint advisory AA23-319A documenting Rhysida IOCs and TTPs, including VPN credential compromise, Zerologon exploitation, and phishing.
- Forensic analysis later identifies unauthorized data outflows beginning from a Berlin Senate department network, continuing through August 12.
- The Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Climate Protection and Environment are preemptively disconnected from Berlin's state network.
- Berlin authorities publicly disclose the cyber incident affecting the two Senate departments.
- Affected departments are reconnected to the Berlin state network as forensic investigation continues.
- The affected Senate administration confirms data exfiltration occurred, following indications received by the Senate Chancellery around August 25.
- Rhysida posts a 'Berlin, Germany' entry to its Tor-based leak site, claiming 5.79TB (~1.44 million files) exfiltrated and demanding roughly 30 BTC (~€2 million) with a countdown timer.
- Berlin Governing Mayor Kai Wegner and Interior Senator Iris Spranger publicly state Berlin will not pay the ransom; BSI, LKA Berlin, and the Berlin State Prosecutor's Office continue investigating.
- Berlin state parliament (Abgeordnetenhaus) election scheduled; officials state election infrastructure and data were not affected by the breach.
Detections & IOCs
As of 2026-09-05, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2020-1472, T1133, T1078, T1566, T1059.001, T1053.005, T1070.004, T1112, T1003.003, T1021.001, T1021.002