Berlin's state government has confirmed that data left part of its administrative network during an August cyberattack and that the city is now facing an extortion attempt. Governing Mayor Kai Wegner says Berlin will not meet the attackers' demands. The investigation is still determining exactly what was taken. Officials say personal data or other non-public material may be involved, but they have not confirmed a victim count, a data volume or the identity of the attacker.
That distinction matters. Berlin has confirmed the incident, exfiltration and attempted blackmail. Claims about Rhysida, a 30-bitcoin demand, 5.79 terabytes of data, roughly 1.44 million files and information about 12,076 people come from reporting and an extortion-site listing—not from Berlin's official findings.
What Berlin has confirmed
The Senate Chancellery says forensic work found additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and the Environment. Officials place that activity between 7 and 12 August 2026, before the affected department and the Senate Department for Urban Development, Building and Housing were disconnected from the state network on 14 August.
The content and scope remain under review. Berlin says it cannot exclude personal or otherwise non-public data from the material taken. The state data-protection commissioner and Germany's Federal Office for Information Security are being kept informed, while the ICT emergency team, forensic investigation and scanning of the state network remain active.
Officials separately say that, based on current knowledge, no data left systems relevant to the September election for the Berlin House of Representatives. That is a scoped statement about the election environment, not a conclusion that the wider incident had no sensitive-data impact.
What remains reported or alleged
Media reporting has linked the incident to Rhysida and described a demand for 30 bitcoin. A listing attributed to the group claims 5.79 terabytes of data and about 1.44 million files. Berlin has not publicly validated those figures or the attribution. Extortion listings are adversary claims and can be incomplete, exaggerated or deliberately misleading.
A responsible response therefore avoids two opposite errors: minimizing a confirmed data loss because the final count is unknown, or presenting every figure posted by a criminal group as established fact. The safe baseline is that data exfiltration occurred and the government is being blackmailed; the detailed scope is still unknown.
The recovery channel is part of the incident boundary
When an organization is still scanning a compromised network, its normal email, chat, identity and ticketing systems cannot automatically be treated as trusted. Sending a new administrator password or recovery key through the same environment can let an intruder observe the cleanup and regain access.
- Declare a known-clean coordination channel. Name the approved devices, accounts and contacts before distributing replacement secrets.
- Verify recipients out of band. A familiar display name or an urgent message inside the affected environment is not sufficient identity proof.
- Rotate in dependency order. Start with identities that can reset other accounts, mint tokens or access backups.
- Revoke sessions and keys. A password change alone does not invalidate every token, certificate or API key.
- Minimize persistent copies. Do not leave emergency credentials in chat history, tickets, shared documents or forensic notes.
- Record custody, not plaintext. Audit who authorized and received a secret without copying the value into the incident log.
Where Secretus fits
Secretus can help an authorized response team hand off a temporary recovery password, replacement API key or break-glass value without placing plaintext in a persistent email or chat transcript. A one-time link and short expiry reduce the lifetime of the human-facing copy; Team Split can require multiple approved holders for a critical recovery secret.
It does not make a compromised endpoint safe and does not verify a recipient's identity. Establish a clean device and an independently verified contact first. Open the value only where it can be used safely, rotate it again if exposure is suspected, and avoid putting the link and its surrounding operational context in the same compromised channel.
What remains unknown
Berlin has not published the initial access path, the complete affected-data inventory, the number of people involved or a confirmed attribution. It has also not confirmed the ransom amount or the volume claimed on the leak site. Those gaps should remain visible as the investigation evolves.
