Skip to content
ransomwarecredential-theftCritical Infrastructure

Rhysida ransomware claims Berlin state government six weeks before German federal elections

3 min read
Share

The Rhysida ransomware group claimed a breach of Berlin's state administrative network on August 28, 2026, six weeks before German federal elections. The group says it exfiltrated 5.79 terabytes of data and is demanding 30 bitcoin (approximately $2.3 million) with a one-week deadline before auctioning the data publicly. Berlin's state government has confirmed the extortion attempt and says it will not pay.

What was taken, and why the credential files are the real problem

Rhysida's claimed haul includes 80,000 administrative fine proceedings, 46,500 contracts, and 12,076 individuals' personal records. Those are damaging but relatively contained. The element that should concern Berlin's IT security team is the approximately 6,000 files described as containing login credentials. Credential files enable follow-on access into connected systems and partner networks that the initial attackers may not have reached. Rotating exposed credentials is a time-sensitive task.

The timeline matters

Forensic analysis has pinned the exfiltration window to August 7 through August 12. The Senate Department for Mobility, Transport, Climate Protection and Environment first reported anomalous outflows on August 7; the network segment was cut off on August 14. Rhysida posted the claim on August 28, two weeks after the connection was severed. The gap between exfiltration and public claim is typical for Rhysida: the group uses it to negotiate quietly before going public.

Pre-election timing is not a coincidence

Rhysida's one-week auction deadline lands the potential data release in the final stretch before German federal elections. Leaked administrative proceedings, contracts, and personal records from Berlin's state government would generate significant press coverage. Whether Rhysida explicitly timed the claim to maximize political impact or whether this is opportunistic overlap is unresolved, but defenders managing government environments in active election periods should treat ransomware extortion as a potential influence operation vector.

Rhysida as a threat actor

Rhysida has been active since mid-2023 and has targeted hospitals, government agencies, and educational institutions across Europe and North America. The group operates as ransomware-as-a-service. CISA and FBI issued a joint advisory on Rhysida in November 2023 documenting its TTPs. The Berlin claim is the first major European government target in 2026 that has been publicly confirmed.

The lesson is not about Rhysida specifically

The operationally transferable lesson here is not Rhysida-specific: any ransomware group that obtains credential files from a government network should be treated as having potentially exposed every system those credentials touched. The response is not a single password reset but a systematic credential inventory and revocation exercise scoped to the August 7-12 exfiltration window.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization is managing ransomware response or government network security.

Related articles