Get a free audit

Field Notes / Breach Analysis

Berlin Watched the Data Leave on 7 August. It Stayed Plugged Into the State Network Until the 14th.

Rhysida pulled 5.79 terabytes and 1,439,893 files out of the Berliner Landesnetz, including CBRN threat planning and nearly 6,000 files of credentials. Detection worked. Disconnection took seven days. Here is what that gap cost, and how to make yours minutes.

Author
Red Team Partners
Read
12 MIN READ
Filed
07 Sep 2026
An operator tracing network segmentation, the control that decides how far an intruder travels once the alarm has already gone off.

01 The seven-day gap

he Senate Department for Mobility, Transport, Climate Protection and Environment recorded a data outflow on 7 August. The Senate Department for Urban Development, Building and Housing was affected too. Both stayed connected to the central Landesnetz until 14 August, when they were isolated and staff found themselves with no internet, no email and no remote access Born’s IT-Blog 2026 . They were reconnected on 23 August alongside the other Senate departments The Hacker News 2026 .

Seven days is not negligence. It is the honest cost of a decision in a large interconnected government estate. Disconnecting a Senate department stops building permits, transport administration and public services. Someone has to weigh the damage of the intrusion against the damage of the cure, and that person needs facts nobody has yet on day one. So the meetings happen. Meanwhile the attacker copies files at line rate.

This is the part of an attack that almost nobody tests. Firms rehearse detection endlessly. They buy the SIEM, tune the alerts, run the tabletop where the answer is "we would have seen it". Berlin did see it. The question that actually decided the outcome was different: how long between seeing it and being able to act on it, in a network where acting hurts.

02 What 5.79 terabytes of a government looks like

Rhysida posted its claim on 28 August and set a one-week deadline against a demand of 30 bitcoin, roughly 2 million euros The Hacker News 2026 . Berlin’s Governing Mayor Kai Wegner said the state was being blackmailed and would not meet the demand. The deadline expired on Friday 5 September and the files went up.

What Rhysida publishedWhy it keeps mattering after the news cycle
CBRN threat planning documents (AG CBRN-Rahmenplanung)Response assumptions for chemical, biological, radiological and nuclear scenarios, now readable by the people planning them
Federal emergency communication channelsHow government reaches itself in a crisis, which is exactly what an adversary wants to disrupt or impersonate
Roughly 6,000 files containing login credentialsA second intrusion, pre-packaged, against Berlin and anyone who shares those credentials
46,500 contracts and 80,000 administrative fine proceedingsSupplier relationships, prices and legal exposure, useful for extortion and for targeting the suppliers next
Personal data of 12,076 individuals, including home addresses and birth certificatesCivil servants become targets in their own homes and in their own inboxes

Investigative journalist Lars Winkelsdorf called the leak "of a magnitude that threatens the state", pointing at criminal investigation material and national defence planning inside the dump Euronews 2026 . Strip the political weight and the structure is familiar to any enterprise. A shared network held material from many functions. One function was compromised. The attacker took everything reachable from there.

EXFILTRATION WINDOW An administrator receiving a threat detection alert in a server room, hours before anyone decides what to do about it.
7 to 12 August: five days of transfer. 14 August: isolation. The alert arrived first and changed nothing for a week.

Note the credential files in particular. Nearly 6,000 of them. Germany’s Federal Office for Information Security warned the public about follow-on phishing built on the leaked material, which is the predictable second act. A breach that publishes credentials does not end when the incident is closed. It ends when every credential in that dump has been rotated, and almost nobody finishes that job.

03 The way in Rhysida usually takes

Berlin has not disclosed an initial access vector, and no official statement names one. Speculating about this specific intrusion would be dishonest. What is documented, and what you can act on today, is how Rhysida gets in generally. CISA, the FBI and MS-ISAC published it in a joint advisory in November 2023 CISA AA23-319A .

  • Valid credentials against internet-facing VPN endpoints at organisations that do not enforce multi-factor authentication by default. This is the group’s signature route.
  • Zerologon, CVE-2020-1472, a domain controller privilege escalation patched in August 2020 and still unpatched in enough estates to be worth an attacker’s time six years later.
  • Phishing, the entry that needs no vulnerability at all.

Every one of those three is testable from outside your perimeter this month. You can enumerate your own external authentication endpoints and check which ones accept a password alone. You can test whether a valid credential without a second factor produces a session. You can measure your click rate with a realistic phishing simulation instead of guessing at it. None of this requires waiting for a breach to teach you the answer.

The uncomfortable part is that MFA gaps rarely live where the policy says they do. The policy says MFA is mandatory. The reality is a legacy VPN concentrator kept alive for one supplier, a service account exempted during a migration in 2023, an emergency break-glass login that nobody removed. We find at least one of those in most estates we test, and the client is always surprised, because the policy document is genuinely correct.

04 Refusing to pay is correct. It is not containment.

Berlin refused the ransom and it was the right call. Paying funds the next campaign and buys a promise from people whose business model is breaking promises. Refusing also removes the fantasy that a payment makes the data unpublished, which it never does. The state criminal police, the public prosecutor, Berlin’s data protection commissioner and the BSI were all involved Anadolu Agency 2026 .

What refusal does not do is reduce the loss. By 28 August, when the demand appeared, the outcome was already fixed. The decision that mattered was taken on 7 August, and it was taken by not being ready to take it. Ransomware negotiation is the visible end of an incident. The invisible end, the part that determines the size of the number on the leak site, happened two weeks earlier in an architecture review nobody ran.

There is a timing detail worth naming. The attack landed three weeks before a Berlin state election. Attackers read calendars. A period when an administration is least able to absorb disruption is exactly when disruption is worth the most to them. If your organisation has a season where cutting a system off the network is politically impossible, an attacker can work that out from your public filings, and will.

05 What to fix this quarter

This maps onto the frameworks your board already answers to. ISO 27001 Annex A asks for network segregation and for access control on remote access. NIST CSF puts Respond and Recover beside Detect for exactly the reason Berlin demonstrates. NIS2 obliges essential and important entities across the EU to manage incidents, not merely notice them, and it puts management personally on the hook for it. For a regulated firm, an intrusion that publishes credential material and personal data is a reportable event and a resilience gap you are expected to have tested for.

Remediation Log
  • Multi-factor authentication enforced on every internet-facing authentication endpoint, with the exemption list printed, owned and dated
  • Network segmented so one department, subsidiary or supplier connection cannot reach the whole backbone, and the segmentation proven by testing rather than by diagram
  • An isolation decision pre-authorised: who can cut a business unit off the network, at what evidence threshold, without waiting for a committee
  • The disconnection rehearsed at least once against a real segment, with the business impact measured so the decision is cheap to make under pressure
  • Egress monitoring that alerts on volume and destination, not only on known-bad signatures, because 5.79 terabytes leaving is itself the indicator
  • A credential rotation plan that assumes your secrets are already in someone else’s archive, with service accounts and break-glass logins included

Berlin saw the attack on day one and still lost 5.79 terabytes, because seeing is not stopping. The distance between those two verbs is measured in segmentation, in pre-authorised decisions and in whether anyone has ever rehearsed pulling the cable. We test that distance directly. You get the path an intruder takes through your estate, the point where segmentation actually holds, and how long your team needs to cut it. Enterprise-grade. Not enterprise-priced. Start with your Threat Map.

References

Sources

  1. The Hacker News. Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network. August 2026. thehackernews.com
  2. Euronews. Berlin cyberattack: hackers leak highly sensitive data across dark web. 5 September 2026. euronews.com
  3. Anadolu Agency. Cyberattack hits Berlin state ministries. August 2026. aa.com.tr
  4. Born’s IT- und Windows-Blog. Cyberangriff auf Berliner Landesnetz, Senatsverwaltungen offline. 17 August 2026. borncity.com
  5. CISA, FBI and MS-ISAC. #StopRansomware: Rhysida Ransomware (AA23-319A). 15 November 2023. cisa.gov