Berlin has launched an emergency review of data stolen from its administration after ransomware gang Rhysida published what it claims is a 5.79-terabyte haul containing sensitive government information, credentials, and critical infrastructure documents.
The German capital said the leaked files are being analysed “with utmost urgency,” with forensic specialists examining both the affected systems and the material now published online.
An additional task force, led by Berlin Chief Digital Officer Florian Hauer, has been established within the Senate Chancellery to coordinate the response. It brings together the Berlin State Criminal Police Office (LKA), the two affected Senate departments, data protection officials, and other security authorities.
The unit will also ensure that state and federal agencies are informed if security-relevant information is found among the leaked material.
“This hacking attack is an extremely serious crime and an attack on the state of Berlin,” the city said. “In the interest of Berlin’s security, it is important to carefully examine information circulating, for example on social networks, and not to further disseminate reports that cannot currently be verified.”
The breach affected Berlin’s Senate Department for Mobility, Transport, Climate Protection and the Environment and its Senate Department for Urban Development, Construction and Housing. Berlin previously said the data was exfiltrated between 7 and 12 August, before the two departments were disconnected from the state network on 14 August.
Rhysida claims to have obtained 5.79TB of data comprising approximately 1.44 million files. A listing on the ransomware group’s leak site, seen by Resilience Media, claims the cache includes more than 124,000 mapping and geographic files, 77,000 legal and complaints documents, 55,000 financial files and 46,000 contracts.
The group also claims to have obtained thousands of personnel records, identity documents and plaintext credentials. Its listing says the stolen material contains 16,389 email addresses, 11,963 phone numbers, and information relating to more than 12,000 individuals.
Among the more security-sensitive claims, Rhysida says the haul contains vulnerability analyses relating to Berlin’s water supply, as well as information concerning the handling of classified material and documents connected to Bundesrat committees.
Those claims have not been independently verified, and Berlin has not confirmed that the specific documents described by Rhysida are genuine.
However, authorities said their analysis of the leaked material is being prioritised according to risk. If investigators identify information affecting “security-critical authorities or institutions,” the relevant Senate departments will contact them immediately.
Berlin said the safety of residents, state employees and government partners remains its priority, adding that individuals found to have been affected by the leak will be contacted in accordance with German and European data protection rules.
Governing Mayor Kai Wegner described the incident as a “very serious crime” against Berlin and said authorities were working to establish what information had been exposed.
“We will inform, advise, and support the affected employees and residents of Berlin as quickly as possible,” he said, adding that the city was in close contact with federal security authorities.
Rhysida has previously targeted public-sector organisations, most notably the British Library in October 2023. The group subsequently published data stolen from the library, which said it neither paid a ransom nor engaged with the attackers.
Berlin has similarly said it will not submit to extortion.












