discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Berlin Confirms Data Theft After Rhysida Ransomware Attack Claims

Berlin confirms data theft after Rhysida ransomware attack claims. City administration will not pay the attacker and is investigating the incident.

By Bill Toulas·Aug 31·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Berlin Confirms Data Theft After Rhysida Ransomware Attack Claims
Image: bleepingcomputer.com

Berlin's city administration confirms a data theft incident after Rhysida ransomware claimed it. The threat actor is demanding payment to prevent the release of exfiltrated data.

Why it matters

This confirms a ransomware attack on Berlin's city administration, highlighting the vulnerability of public sector entities to cyber threats.

A bad guy used a computer trick called ransomware to get into Berlin's city computer system. They took lots of information, like names and money details, and said they would give it back only if Berlin gave them money. Berlin said they won't give the money and are looking into it.

Analysis

{"heading_1":"Details of the Attack","subheading_1":"Data Exfiltration","content_1":"Rhysida ransomware claims to have exfiltrated 5.79 TB of data, including 1.44 million files. The data includes government, legal, financial, and personal information.","subheading_2":"Types of Information Exfiltrated","content_2":"The attacker claims to have exfiltrated information related to government, legal, financial, contractual, HR, infrastructure, health, and mapping records. They also claim to have exfiltrated plaintext credentials, database accounts, payment-system data, and other sensitive information.","subheading_3":"Victim's Response","content_3":"The Berlin Mayor, Kai Wergner, stated that the city will not pay the attacker and that the State Criminal Police Office, the public prosecutor's office, and federal security agencies are now investigating the incident."}

Key points

  • Berlin's city administration confirmed a data theft incident after Rhysida ransomware claimed it.
  • The threat actor claims to have exfiltrated 5.79 TB of data, including 1.44 million files.
  • The data includes government, legal, financial, and personal information.
The Upside

If Berlin can prevent the ransomware from getting into their system in the future, they won't have to pay the bad guy.

The Downside

If the bad guy gets more information or threatens to release it, Berlin might have to pay to keep the information private.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybersecurityransomwareberlingovernment

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Aug 31, 2026

Source

bleepingcomputer.com

Share

Topics

securitycybersecurityransomwareberlingovernment

Related

More from this desk

Aug 31·bleepingcomputer.com

Cronos blockchain restarts after $74 million Tectonic exploit

Cronos blockchain network resumes trading after Tectonic exploit

Aug 31·bleepingcomputer.com

Microsoft Warns of TerminalFix Attacks Using Reverse Tunnels

Microsoft alerts about a new variant of ClickFix attacks that use fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands in Windows Terminal. The attacks lead to a multi-stage intrusion chain resulting in a reverse tunnel into the vict…

Aug 31·schneier.com

Is Someone Hacking DoD Refrigerators?

DoD refrigerators affected in multiple bases. Pentagon officials declined to comment.

Aug 31·bleepingcomputer.com

Microsoft Exchange Online Outage Causes Email Failures, Authentication Issues

Microsoft investigating widespread service issue affecting Exchange Online users. Authentication, email delays, and failures reported.