Actor Profile

Rhysida is a ransomware-as-a-service (RaaS) operation active since mid-2023, conducting double-extortion attacks against high-value targets. The group exfiltrates sensitive data before deploying ransomware, then threatens public disclosure to pressure victims into payment. Rhysida has demonstrated a pattern of targeting public-sector entities and critical infrastructure, leveraging regulatory frameworks like GDPR to amplify extortion pressure. The group operates a data leak site where they auction or publish stolen data from non-paying victims.

TTPs (Tactics, Techniques, Procedures)

Initial access vector in the Berlin attack remains undisclosed, though Microsoft previously observed Rhysida operators using malicious Microsoft Teams installers to gain entry. Post-compromise activity included extensive data exfiltration (5.79 TB across 1.44 million files) between August 7-12, 2026, targeting government networks and the Senate Department for Mobility, Transport, Climate Protection and the Environment. The threat actor harvested plaintext credentials, database accounts, password vaults, and credentials of senior officials, indicating credential dumping and privilege escalation. Affected systems were isolated from the state network on August 14. TTPs align with T1566 (Phishing), T1078 (Valid Accounts), T1003 (OS Credential Dumping), T1005 (Data from Local System), T1486 (Data Encrypted for Impact), and T1567 (Exfiltration Over Web Service).

Targets & Patterns

Rhysida targets high-impact sectors including healthcare organizations, state and local governments, educational institutions, and critical infrastructure operators. The Berlin attack exemplifies their focus on public-sector entities with sensitive data holdings and regulatory compliance obligations. Target selection appears driven by the potential for significant operational disruption and the presence of data subject to strict privacy regulations (GDPR in Europe), which increases victim pressure to negotiate. The group's theft of critical infrastructure assessments (Berlin water supply security) and classified government materials demonstrates intent to maximize leverage through data sensitivity rather than ransom amount alone. The four-day payment deadline and explicit GDPR violation threats indicate a calculated approach to victim psychology and legal exposure.

Historical Context

Rhysida emerged in mid-2023 and has maintained consistent operations targeting public and critical sectors. Microsoft disrupted a previous Rhysida campaign that leveraged trojanized Microsoft Teams installers for initial access, demonstrating the group's willingness to abuse trusted collaboration platforms. The Berlin incident represents one of the most significant public-sector breaches attributed to Rhysida, with 5.79 TB of exfiltrated data marking it as a large-scale compromise. The group's continued use of double-extortion tactics and data leak site operations aligns with broader ransomware ecosystem trends since 2020, where data theft has become standard practice to maintain leverage even when backup recovery is possible.

Defensive Recommendations

  • Implement robust credential hygiene: eliminate plaintext password storage, enforce password vaults with MFA, and rotate credentials for privileged accounts (addresses observed credential theft)
  • Deploy network segmentation to isolate sensitive departmental systems from broader administrative networks, limiting lateral movement and data exfiltration scope (T1005, T1567)
  • Monitor for anomalous data transfer volumes and durations, particularly outbound traffic to cloud storage or file-sharing services over multi-day periods (5.79 TB exfiltrated Aug 7-12)
  • Harden collaboration platforms (Teams, Slack) against malicious installers: enforce application allowlisting, verify digital signatures, and restrict installation privileges (T1566)
  • Conduct regular security assessments of password vault implementations and database credential storage to detect plaintext or weakly encrypted secrets before threat actors do (T1003)

---

# Geopolitical Context

Geopolitical Context

The Rhysida ransomware attack on Berlin's municipal administration represents a significant cyber incident targeting critical governance infrastructure in Germany's capital and largest city. The breach, discovered in mid-August 2026, reportedly compromised 5.79 TB of sensitive government data including personnel records, financial information, and critical infrastructure assessments. The attackers' claimed exfiltration of classified government material, Bundesrat committee records, and water supply security assessments elevates this beyond a routine ransomware incident to a matter of potential national security concern. Berlin's refusal to pay the ransom aligns with German federal policy discouraging ransom payments to criminal actors. The involvement of federal security agencies alongside state-level law enforcement suggests recognition of broader implications beyond municipal governance disruption. The timing—weeks before a Berlin House of Representatives election—adds political sensitivity, though officials report no evidence of electoral system compromise.

State Actor Alignment

Rhysida operates as a financially-motivated cybercriminal ransomware-as-a-service (RaaS) operation with no confirmed state sponsorship. However, the group's targeting pattern—which includes healthcare, education, state governments, and critical infrastructure across multiple jurisdictions since mid-2023—has drawn attention from Western law enforcement and intelligence agencies. The group's operational security and technical capabilities suggest a moderately sophisticated threat actor, though attribution to any specific state remains unconfirmed. Germany's response, involving the State Criminal Police Office (Landeskriminalamt), federal prosecutors, and unnamed federal security agencies, indicates a coordinated national-level investigation. The incident occurs within a broader context of increased ransomware activity targeting European governmental entities, prompting enhanced EU-level coordination on cyber resilience under the NIS2 Directive framework.

Business Impacty pro region

The Berlin breach underscores persistent vulnerabilities in European municipal and regional government IT infrastructure, despite ongoing digitalization and cybersecurity investment initiatives. Germany's federal structure—where individual Länder and municipalities maintain substantial administrative autonomy and separate IT systems—creates a fragmented attack surface that complicates unified defense postures. The reported theft of critical infrastructure assessments related to Berlin's water supply raises concerns about potential cascading risks if such information is weaponized by other threat actors or shared across criminal forums. For the broader European Union, this incident reinforces the urgency of implementing NIS2 Directive requirements and the proposed Cyber Resilience Act, particularly regarding public-sector digital security standards. The attackers' explicit invocation of GDPR violations as an extortion lever demonstrates how regulatory frameworks designed to protect citizens can be cynically exploited to amplify pressure on victim organizations. Other European capitals with similar administrative structures may reassess their own exposure to comparable attacks.

Forecast

If Berlin maintains its no-payment stance, Rhysida is likely to publish at least portions of the stolen data on their leak site within days, consistent with the group's established operational pattern. This may trigger GDPR breach notification obligations affecting hundreds of thousands of individuals and potentially expose sensitive government operations to public scrutiny. If the published data includes actionable intelligence on critical infrastructure or classified government communications, secondary exploitation by other threat actors or hostile intelligence services becomes possible, though the extent would depend on the actual sensitivity of compromised materials. German federal authorities may use this incident to accelerate legislative or budgetary measures strengthening municipal cybersecurity requirements, particularly for cities administering critical services. If forensic investigation reveals the initial access vector, expect targeted advisories to other German municipalities regarding specific vulnerabilities or attack patterns. The incident may also influence ongoing EU-level discussions regarding mandatory cyber insurance, incident reporting timelines, and cross-border law enforcement cooperation against ransomware operations. If Rhysida continues targeting European governmental entities with apparent impunity, pressure for more aggressive disruption operations—similar to those previously conducted against other ransomware groups—may intensify among Western law enforcement coalitions.