RackTop Systems
Threat Brief

Berlin will not pay. It still has to know what left.

Berlin refused a 30-bitcoin ransom after a data theft from one Senate department. The most detailed inventory of what left is still the attacker’s leak-site listing.

RackTop SystemsSeptember 2, 20266 min read

Key takeaways

  • According to public reporting from BleepingComputer and SecurityWeek, Berlin discovered an intrusion on August 14, 2026 affecting the Senate Department for Mobility, Transport, Climate Protection and the Environment, and disconnected the affected systems from the state network the same day. Reporting places the data exfiltration between August 7 and 12, 2026.
  • Governing Mayor Kai Wegner and Interior Senator Iris Spranger said publicly that the state of Berlin would not submit to extortion, after a demand of 30 bitcoin, worth roughly two million euros at the time, according to BleepingComputer, SecurityWeek, and Help Net Security.
  • The Rhysida ransomware group listed Berlin on its leak site on August 28, 2026, allegedly claiming more than 5.7 terabytes across roughly 1.44 million files, itemized down to counts of affected individuals, email addresses, phone numbers, and bank account numbers. Every one of those figures is the group’s own claim and has not been confirmed by the city.
  • Refusing to pay does not shrink the notification obligation. It makes independent scoping the only route to it, and independent scoping needs a per-operation record of which files were read, evidence that has to exist before the intrusion rather than after it.

Berlin discovered an intrusion into its state administration on August 14, 2026 and disconnected the affected systems from the state network the same day, according to public reporting from BleepingComputer and SecurityWeek. The intrusion reached the Senate Department for Mobility, Transport, Climate Protection and the Environment. Reporting places the data exfiltration between August 7 and 12, several days before anyone noticed.

On August 28, 2026, the Rhysida ransomware group listed Berlin on its Tor leak site. Governing Mayor Kai Wegner and Interior Senator Iris Spranger answered with a joint statement that the state of Berlin would not submit to extortion. The demand, according to BleepingComputer, SecurityWeek, and Help Net Security, was 30 bitcoin, worth roughly two million euros at the time. Spranger also said data connected to the upcoming state election was not affected.

The attacker published the more specific inventory

Rhysida’s listing is itemized. According to reporting from BleepingComputer, SecurityWeek, and Security Affairs, the group allegedly claims more than 5.7 terabytes across roughly 1.44 million files, and breaks that down into counts of affected individuals, email addresses, phone numbers, and bank account numbers, alongside categories such as personnel files, payroll records, contracts, legal documents, and nondisclosure agreements. All of it is the group’s own claim, unverified by the city, and leak-site inventories are marketing as much as they are manifests.

Berlin, correctly, has said little. State criminal police, federal security agencies, and prosecutors are investigating, and an authority in the middle of that does not narrate findings in public. Notice the shape of the asymmetry anyway. The most granular public description of what left a government department is the description written by the people who took it.

That matters because the obligation does not wait. Under Article 33 of the GDPR, a controller still owes the supervisory authority a characterization of the categories and approximate number of data subjects affected. A counter-inventory has to come from somewhere. Right now the only detailed inventory in circulation belongs to the adversary, and no organization wants its regulatory filing to be a paraphrase of an extortion post.

Refusing to pay is the right call and the harder one

Not paying is the defensible decision, and Berlin stated it without hedging. It is worth being precise about what payment would and would not have bought. A payment buys a promise of deletion from a party whose business model is breaking promises. It does not retract copies, and it produces no evidence: paying tells you nothing more accurate about what was taken than not paying does.

So the choice was never really between paying and scoping. Scoping is required either way. What refusing does is remove the temptation to treat the extortion listing as an answer, which leaves the organization holding the question it always had: which files did this actually touch?

The exfiltration window is where that question was decided. Reporting describes roughly five days of data movement before discovery. Five days of bulk reads across a department’s file estate is not a quiet event at the data layer. It is a very loud one, provided something in the data path was counting.

Scope becomes a query when the data layer keeps the record

The controls that change this outcome sit below the application and beside the file. Detection of bulk reads and mass change on live production data turns a multi-day extraction into an alert on the first day, because one identity walking an entire share is a behavioral outlier no matter how valid its credentials are. Attribute-based access control (ABAC) enforced per file and per operation bounds what a single compromised account can reach, so a foothold in one department is not a foothold in its whole archive. An immutable, per-operation audit record makes the notification question answerable from your own evidence: not an estimate, and not the attacker’s manifest, but a list. RackTop BrickStor SP enforces all of this inline across SMB, NFS, S3, and Web Drive, which is where public-sector unstructured data actually lives.

Backups and cyber vaults matter, and they are not this. They restore copies after the fact. They do not observe a read, so they cannot tell you what was taken, and in an incident that public reporting describes as theft rather than encryption, restoration was never the open question.

Berlin’s handling looks sound in the parts that are visible: same-day disconnection, law enforcement and federal agencies engaged, a clear public refusal, and a specific statement about election data. This could be nearly any mid-sized public agency, and the lesson is not about one department’s posture. It is that the record you need to answer "what left" has to already exist on the day the extortion note arrives.

Frequently asked questions

From your own evidence, which means that evidence has to have been collected before the intrusion. The record that answers the question directly is a per-operation audit trail of reads on the data itself, naming the identity, the object, and the timestamp for every file operation. Refusing to pay does not change the notification obligation. It only removes the option of quietly treating the attacker’s file list as an inventory.GHOST immutable audit
No, and the doubt cuts both ways. Leak-site listings are a negotiation instrument, so volumes and record counts are routinely inflated, occasionally understated, and sometimes assembled from an earlier breach entirely. Every figure in an extortion post is an unverified claim from an interested party. The practical difficulty is that a victim with no read-level record of its own has no basis for a different number, so the attacker’s figure becomes the one regulators and reporters work from.
Because they record the wrong layer. Network telemetry shows that bytes left and how many, but encrypted or tunnelled traffic does not name the objects inside it. Application and authentication logs show that a session existed, and they often age out before an investigation reaches them. Neither can enumerate the files a session opened. That enumeration exists only where the read happened, on the storage platform serving SMB, NFS, S3, and Web Drive.File activity telemetry for the SOC
Article 33 of the GDPR requires a controller to describe the nature of the breach including, where possible, the categories and approximate number of data subjects and records concerned, together with likely consequences and the measures taken or proposed. The phrase "where possible" is doing real work there: the regulation accommodates uncertainty. An organization that can characterize the affected records from its own audit trail is still in a materially stronger position than one estimating from an extortion post.

See data-layer defense in action

A 30-minute demo shows Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your environment.

Berlin Data Breach: Proving What Actually Left | RackTop