What Rhysida Actually Took

Rhysida says it took 5.79 terabytes of data from Berlin's city-state administrative network, structured across roughly 1.44 million files. The ransomware group, active since 2023 and believed to operate out of Russia or Eastern Europe, posted its claim to a dark-web leak site on August 28, 2026. The same group has previously claimed the British Library and the Chilean Army among its victims, so this is not a first-time operator testing tactics on a major government target.

The file count breaks down into contracts, emails, phone numbers, passwords, classified material, and payroll and administrative-offense records touching more than 5,000 personnel files each. Rhysida also claims SQL database dumps spanning 2020 through 2026 and 3,226 signed non-disclosure agreements. Personal data tied to roughly 12,076 individuals is reportedly inside the haul, which is the number that will drive breach-notification obligations regardless of what else is in the archive.

The Water Supply Detail Changes the Risk Calculus

Buried inside that file list are vulnerability assessments of Berlin's water supply, and that single category matters more than the terabyte figure. Personnel records and payroll data are the standard contents of a municipal breach; a documented map of weak points in a capital city's water infrastructure is not. Whoever holds that assessment now has a head start on identifying where a follow-on attack against physical infrastructure would do the most damage, whether that attacker is Rhysida itself, a buyer at its threatened auction, or an unrelated actor who never touches the leak site at all.

This distinction gets lost when a breach is summarized only by its size. A typical ransomware disclosure produces embarrassment, notification costs, and possibly fraud downstream. A disclosure that includes infrastructure vulnerability data produces a target list. TheHackerNews and other outlets that reported the leak have treated the water-supply detail as one line among many; for anyone responsible for critical-infrastructure security, it should be the headline.

Refusing to Pay Solves One Problem, Not the Other

Berlin's mayor Kai Wegner and interior senator Iris Spranger issued a joint statement that the city-state will not submit to extortion, and that position is defensible on its own terms. Rhysida demanded 30 Bitcoin, worth around 2 million euros at the time of the demand, with a roughly seven-day deadline before the data goes to auction. Paying a ransom funds the next attack and offers no binding guarantee that stolen copies are deleted rather than quietly resold.

What refusal does not do is put the data back. Once a file set has been exfiltrated and posted to a leak site, the decision to pay or not pay only affects whether Rhysida publishes the full archive or keeps extorting privately; the copies already made are outside Berlin's control either way. Officials have said systems and data for the September 20 election are unaffected, which addresses the most urgent question but says nothing about whatever access the attackers held on the administrative network before the intrusion was detected.

What NIS2 Actually Requires From Here

For operators inside the EU's NIS2 regime, a no-ransom stance is a policy choice, not a compliance answer. NIS2 puts duty-of-care obligations on essential and important entities that cover risk management, incident reporting timelines, and supply-chain security, and a municipal water utility sits squarely inside the categories the directive was written to protect, the kind of standard the UK's National Cyber Security Centre pushes operators toward even outside the EU regime. The question NIS2 asks is not whether Berlin paid the ransom; it is whether the vulnerability data Rhysida now holds should have been reachable from the same network as payroll files and contract archives in the first place.

The categories Rhysida claims to hold illustrate the range of exposure in one incident:

Data categoryReported scale
Contracts46,500
Personnel filesover 5,000
Administrative-offense filesover 5,000
Non-disclosure agreements3,226
Individuals with personal data exposedapproximately 12,076

Segmentation between administrative records and operational-technology or critical-infrastructure assessment data is exactly the kind of control NIS2 expects to see documented, tested, and reported on, not assumed. An organization that can show it segmented that data, even if the segmentation failed, is in a different position than one that never separated it at all.

Why We Do This

We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.

Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.

If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.