Berlin Confirms Rhysida Data Theft After Leak Claim

Berlin’s city administration has confirmed data theft after the Rhysida ransomware gang listed the city on its leak site and tried to extort it. The public confirmation turns the incident from a ransom claim into an acknowledged exfiltration event, but officials have not said what systems or records were taken. Rhysida’s model is to steal data first and then threaten to publish it if the victim does not pay. That means the harm can continue even if Berlin restores systems, because copied records can still be leaked, sold, or used for fraud and phishing later. For local governments, the lasting exposure is no longer just downtime: resident, employee, or administrative records can outlive the incident inside criminal hands. The unanswered question is scope, and that uncertainty matters because the privacy and fraud fallout depends on which records left the network.

Part of the PlainSec briefing for 2026-08-31

Editions

Sources