zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Data Breach in Berlin Weeks Ahead of Election

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Data Breach in Berlin Weeks Ahead of Election

Product Serial: F-2026-09-18

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on the data breach of Berlin State in Germany mere weeks before an important election.

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On August 28, 2026, threat actor “Rhysida” advertised the sale of 5.79 TB of data allegedly exfiltrated from the city government of Berlin, Germany. The breach was confirmed by the government of Berlin on August 14, 2026, while the attack itself very likely occurred between August 7–12, 2026.
  • Rhysida claims the data includes violations of the General Data Protection Regulation (GDPR), the European Union (EU)’s comprehensive data law that governs the safekeeping of the personal data of EU citizens or residents held digitally by organizations. The threat actor very likely used alleged GDPR violations as leverage to persuade Berlin to pay the ransom.
  • Berlin’s subsequent refusal to pay is consistent with guidance from the German federal cybersecurity agency; it likely reflects a government priority to show resolve against cybercrime in the lead-up Berlin State elections to be held on September 20, 2026, for both a new state parliament and local district councils.
  • ZeroFox assesses that, as further elections across Europe draw near over the next six to 12 months, threat actors will almost certainly seek to influence outcomes by conducting timed operations likely intended to sow distrust in government institutions.

Tags: tlp:clear,  data breach,  threat actor