Rhysida gang claims theft of 5.79TB from Berlin's city government
The ransomware crew says it took 1.44 million files, including water-supply security assessments and plaintext passwords. Berlin's mayor says the city will not pay.

Key points
- Berlin's city administration confirmed on 28 August 2025 that the Rhysida ransomware gang is trying to extort it after listing the city on its leak site.
- The attackers claim they stole 5.79 terabytes of data, roughly 1.44 million files, including credentials belonging to senior officials.
- Mayor Kai Wergner said Berlin will not pay, and German federal and state police are investigating.
- Forensic investigators say data was taken from the Senate Department for Mobility, Transport, Climate Protection and the Environment between about 7 and 12 August 2025.
- Senator Iris Spranger said there is no sign that data for the upcoming Berlin House of Representatives election was touched.
Berlin's city government has confirmed it is the target of an extortion attempt by Rhysida, a ransomware gang that has been hitting hospitals, schools and government bodies since mid-2023. Ransomware is malicious software that scrambles a victim's files, though in recent years the gangs mostly just steal the data and threaten to publish it unless they are paid.
The intrusion was spotted in mid-August. Rhysida went public with its claim on Friday 28 August, posting Berlin on the dark-web site it uses to name victims, as first reported by BleepingComputer.
Mayor Kai Wergner has said flatly that the city will not pay. Germany's State Criminal Police Office, the public prosecutor and federal security agencies are now on the case.
What did the hackers actually take?
Rhysida says it walked away with 5.79 terabytes of files, around 1.44 million documents in total. That is a very large haul, and the gang's own inventory reads like a tour of a city hall's filing cabinets.
The claimed contents include personnel files, payroll, email archives, scanned identity documents, and 148 IBANs (the account numbers used for European bank transfers). The gang also lists plaintext passwords, database logins, payment-system data, and password vaults belonging to senior officials. Plaintext means the passwords were stored as readable text rather than scrambled, which is exactly what a defender does not want to hear.
More worrying for anyone who lives in Berlin: the attackers say the trove contains security assessments for the city's water supply, records from Bundesrat (federal council) committees, and more than 3,200 documents marked as non-disclosure agreements.
| Detail | Figure |
|---|---|
| Data volume claimed | 5.79 TB |
| Files claimed | ~1.44 million |
| IBANs exposed | 148 |
| NDA documents | 3,200+ |
| Attack discovered | mid-August 2025 |
| Public extortion post | 28 August 2025 |
Investigators believe the theft from the Senate Department for Mobility, Transport, Climate Protection and the Environment happened between 7 and 12 August. Those departments were pulled off the state network on 14 August to contain the damage.
Should Berlin residents be worried?
Probably a little, but not about the September election. Senator Iris Spranger said officials have found no evidence that election data was affected, and the systems supporting the Berlin House of Representatives vote are considered secure.
For ordinary residents, the practical risk is the usual one after a big government breach: scam emails, scam phone calls, and fake letters that use real personal details to sound convincing. If your name, address, phone number or bank details sat in a Berlin administrative system, treat any surprise message about tax, fines or benefits with suspicion, and check by calling the office directly.
How did Rhysida get in?
Berlin has not said. Rhysida is not fussy about entry routes. In an earlier campaign disrupted by Microsoft, the gang used booby-trapped Microsoft Teams installers to trick staff into running malware.
The attackers have given Berlin four days to pay before publishing everything, and are pointing to Europe's GDPR privacy rules as extra pressure: leaked personal data means regulatory fines on top of the operational mess. Berlin's answer, so far, is no.


