Security1 distinct publisher3 min readPublished
The Senate says it will not pay and has now dated a second outflow to August 7 through 12. Twenty-two days after that outflow was first reported, it has published nothing for the people whose records went.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Two of the dates sit on top of each other. Berlin's forensic work puts the second outflow between August 7 and August 12, 2026 [2]. The affected department reported an outflow on August 7 and was not cut off from the state network until August 14 [4]. The entire dated exfiltration therefore ran and finished inside the interval between the first report and the disconnection [4]. Scope and content are still under examination, and the Senate Chancellery says personal and other non-public data cannot be excluded from what was taken [3].
Since Berlin has published no volume figure, the arithmetic available to a resident is the attackers'. The leak-site post claims 5.79 terabytes across roughly 1.44 million files, an average of about 4 MB per file [11][1]. Its eleven categories cover about a quarter of that file count, some 360,000 files, which leaves on the order of 1.08 million files the post never describes [11][2]. The largest itemized category, 124,823 maps and geodata files, is around a third of the itemized quarter and under nine percent of the whole claim [11][3]. The entry names the victim only as Berlin, Germany, rather than the Senate or any department, and carries no ransom figure [11].
Keep the attribution layers separate. The Senate Chancellery names no group and says state criminal police, the public prosecutor and federal security authorities are investigating [8]. Der Spiegel named Rhysida on August 28, citing the group's darknet leak site and security sources involved in the response [9]. The Hacker News separately confirmed through a monitoring service that an entry titled "Berlin, Germany" landed on that leak site on August 28 [10]. Governing Mayor Kai Wegner, after a special Senate session at the Rotes Rathaus, said the state of Berlin is being blackmailed [7].
The tradecraft on file is familiar. The November 2023 CISA, FBI and MS-ISAC advisory on Rhysida records initial access through valid credentials against external-facing VPN endpoints, notably where multi-factor authentication is not on by default [12][15], through Zerologon (CVE-2020-1472), which Microsoft patched on August 11, 2020, nearly six years before the Berlin window [13][6], and through phishing [14]. The same document's countermeasures are MFA across services, remediation of known exploited vulnerabilities, and segmentation [16]. It also notes reported similarities between the Rhysida operators and Vice Society, tracked by Microsoft as Storm-0832 [17]. The monitoring service counted 280 Rhysida victims as of August 29, nine of them German, including the Stuttgart city administration in May 2026 [18].
Refusing to pay matches the FBI and CISA position, which is that payment neither guarantees recovery nor discourages the next attack [15]. That settles the extortion question but leaves the notification question, which belongs to Berlin alone: 22 days after the department first reported an outflow, the Senate's two releases still carried no guidance for people whose records may be in the data [5][6]. The state data protection commissioner and the BSI are being kept informed on a continuing basis [19], and as of August 29 that commissioner had issued no public statement of her own [19]. Regulators are current while the 12,076 individuals named in the attackers' count [5] are left reading a leak-site post.
Ranked by verification strength, evidence, and original report placement.
Berlin's state government confirmed it is the target of an extortion attempt following the August compromise of the city's state administrative network and said it will not meet the extortionists' demands.
Scope and content are still being examined, and the Senate Chancellery said personal or other non-public data cannot be excluded from what was taken.
"The state of Berlin is being blackmailed," Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus, quoted in the machine-translated English version on Berlin's official city portal.
The same statement disclosed that forensic work found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with the exfiltration dated between August 7 and August 12, 2026.
The department first reported an outflow on August 7, the Senate Chancellery said in response to questions, seven days before it was cut off from the network on August 14.
Berlin has published no figure for how much data left the network; the only itemized account in circulation is the attackers' leak-site post indexed on August 28, which claims 5.79 terabytes of data and personal information on 12,076 individuals.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Official spine, criminal arithmetic
The structural facts are on the record from the people responsible for them: the Senate Chancellery dates the second outflow to August 7-12, names the investigating authorities, and confirms the extortion attempt, and Wegner's blackmail line comes off Berlin's own portal. The federal tradecraft detail traces to a published CISA-FBI-MS-ISAC advisory. The weak joint is the quantity: every number describing what actually left - terabytes, files, 12,076 people - originates with the extortionists, and Der Spiegel's naming of Rhysida is relayed rather than independently matched in what we hold.
Downtime you could feel, a list 280 long
This is not a paper incident. Two departments spent from August 14 to August 23 off the state network, housing benefit applications and payments stopped in the meantime, and the same crew's leak site carried 280 organizations - nine German, with Stuttgart's city administration listed in May 2026 and the Port of Seattle in 2024. What keeps this short of the top of the scale is the other side of the footprint: the count of affected people is asserted by criminals, and no notification to any of them has been published.
The extortionists own the only scoreboard
Modestly overstated, and not by the reporting - by the vacuum it describes. 5.79 terabytes and 12,076 individuals will be the numbers everyone repeats, yet they come from a sales post that labels its victim only "Berlin, Germany," names no ransom, and characterises about 360,000 of the 1.44 million files it claims, leaving roughly a million asserted and undescribed. Berlin's counterweight is thin in the other direction too: on August 19 the message was that no sensitive data had left, and by August 28 personal data could no longer be excluded.
Two parties with reasons to pick a number
Read the numbers against who benefits from them. An extortion crew publishing a haul size is advertising, and inflation costs it nothing; a state government facing an Abgeordnetenhaus election on September 20 has every reason to date, bound and quantify slowly, which is roughly what happened between the August 19 line that no sensitive data had left and the August 28 admission that personal data cannot be excluded. The one voice with no stake in Berlin's outcome is the 2023 federal advisory, whose no-pay guidance happens to align with the choice Wegner announced.
Well-quoted, singly held
We are confident about what was said and when - the dates, the quotes, the advisory contents are all specific and checkable. We are much less confident about what is true of the theft itself, because a single outlet carries the whole account, the attribution comes via Der Spiegel, and the scope Berlin admits is explicitly still under examination.