The numbers here are bigger than most breaches you will read about this year
Between August 7 and 12, 2026, the Rhysida ransomware gang pulled 5.79 terabytes of data out of Berlin's state government network, spanning roughly 1.44 million files. The haul, according to Rhysida's own claims, breaks down into specifics that read like an inventory of everything a city government should never lose in one event: 124,823 geodata and mapping files, 77,939 legal and complaints files, 55,553 financial records, 46,522 contracts, 27,299 HR files, personal information on more than 12,000 individuals, 148 IBANs, passport and ID scans, water supply vulnerability assessments, and plaintext credentials from multiple internal systems. Any one of those categories on its own would justify a formal breach notification. Having all of them in a single exfiltration event is the kind of scale that turns a routine incident response into a months-long cross-agency remediation program with regulators watching every step.
That last category deserves the most attention from any technology leader reading this. Plaintext credentials turn a records-exposure story into a live credential-compromise event across whatever systems those logins touch, and rotating them at scale across a government's worth of internal tools is a project measured in weeks, not a weekend fire drill. Berlin's Senate Department for Mobility, Transport, Climate Protection and the Environment saw additional exposure beyond the initial intrusion, which tells us the attackers had time to move laterally before anyone cut the connection. That lateral movement window is the part every incident responder should study, because it is where a bad breach becomes a much worse one.
A two-day gap between discovery and disconnection did real damage
The breach was discovered in mid-August, but affected departments stayed connected to the broader state network until August 14, roughly two days after the exfiltration window closed and detection began. That gap is where the second ministry's data likely entered the attacker's haul. In an incident like this, every hour between discovery and isolation is an hour the attacker can spend finding what else is reachable, and Berlin's case suggests that window was long enough to matter.
For enterprise leaders, the operational lesson is blunt: your incident response plan needs a pre-authorized kill switch, not a committee meeting. If cutting network access requires sign-off from multiple department heads who are not immediately reachable, you have already built the delay that turns a contained incident into a sprawling one. Berlin's experience is a live case study for why isolation authority needs to sit with whoever is on call, not whoever normally owns the budget line.
Refusing to pay, in public, before the clock ran out
Berlin's governing mayor, Kai Wegner, called the situation what it was: "The state of Berlin is being blackmailed." He confirmed the city would not pay the 30 bitcoin ransom, roughly 2.3 million dollars at the time, and that multiple agencies were investigating the intrusion in parallel. Interior Senator Iris Spranger separately addressed public anxiety about election infrastructure, stating that security officers found no evidence the election environment itself was compromised. Both officials chose to answer publicly and specifically rather than routing every question through a generic holding statement, which is a communications posture most breached companies never attempt.
The decision to refuse publicly, ahead of the deadline, is a different posture than most private-sector breaches take. Most companies negotiate quietly through a specialized incident response firm and rarely confirm whether a payment happened either way. Berlin's choice to state its position before the countdown expired removes any ambiguity for Rhysida and for the public, at the cost of inviting a data dump as retaliation. That works for a government that answers to voters and can absorb the political fallout of a leak. A company that answers to customers with contracts and SLAs riding on data integrity faces a harder calculation, which is exactly why every board should rehearse this conversation before an actual deadline is ticking and the answer has to happen under pressure rather than in a calm planning session.
Rhysida's pattern is now predictable, and that is useful
Rhysida has been operating since May 2023 and has already hit the British Library, the Chilean Army, multiple healthcare organizations, and Slovenia's Holding Slovenske Elektrarne. The group's approach is consistent: broad exfiltration first, encryption second, a public leak-site listing with a countdown, and an opening bid pitched to generate press coverage as much as payment. That consistency is a gift to defenders, because it means threat intelligence teams can model Rhysida's dwell time and typical target profile with reasonable confidence.
If your organization runs a public-sector adjacent business, a healthcare-linked vendor relationship, or an energy sector contract, Rhysida's victim list should already be in your threat model. Groups that have proven a repeatable playbook against government-grade defenses are not going to stop rotating targets, and mid-market companies with weaker segmentation than a national capital are a softer next stop. Feed Rhysida's known tactics, techniques, and procedures into your detection rules now, while the group is actively operating, rather than after your own name shows up on that leak site.
The roadmap implication
Berlin's breach is a reminder that data volume and data sensitivity are two different risk axes, and this incident scores high on both. Nearly six terabytes of government records, including plaintext credentials and passport scans, is the kind of exposure that triggers regulatory scrutiny, public trust erosion, and a multi-month remediation project all at once, and the bill for that remediation will land regardless of whether the ransom itself ever gets paid.
For your own roadmap, the actionable items are concrete: eliminate plaintext credential storage anywhere in your environment this quarter, pre-authorize network isolation without requiring cross-department sign-off, and rehearse a public disclosure decision before you are staring at a countdown timer. Berlin had the political cover to say no in public. Make sure your organization has thought through what it would say, and when, before that decision gets made for you under pressure.



