Flash Report: Data Breach in Berlin Weeks Ahead of Election
by ZeroFox Intelligence
Key Findings
- On August 28, 2026, threat actor “Rhysida” advertised the sale of 5.79 TB of data allegedly exfiltrated from the city government of Berlin, Germany. The breach was confirmed by the government of Berlin on August 14, 2026, while the attack itself very likely occurred between August 7–12, 2026.
- Rhysida claims the data includes violations of the General Data Protection Regulation (GDPR), the European Union (EU)’s comprehensive data law that governs the safekeeping of the personal data of EU citizens or residents held digitally by organizations. The threat actor very likely used alleged GDPR violations as leverage to persuade Berlin to pay the ransom.
- Berlin’s subsequent refusal to pay is consistent with guidance from the German federal cybersecurity agency; it likely reflects a government priority to show resolve against cybercrime in the lead-up Berlin State elections to be held on September 20, 2026, for both a new state parliament and local district councils.
- ZeroFox assesses that, as further elections across Europe draw near over the next six to 12 months, threat actors will almost certainly seek to influence outcomes by conducting timed operations likely intended to sow distrust in government institutions.
Details
On August 28, 2026, threat actor Rhysida advertised the sale of 5.79 TB of data exfiltrated from the city government of Berlin, Germany. The offering was posted on Rhysida’s dark web leak site for 30 Bitcoin (roughly USD 75,000 at the time of writing). The threat actor also reportedly targeted data from the German Senate’s Department for Mobility, Transport, Climate Protection and the Environment.1
The breach was confirmed by the government of Berlin on August 14, 2026; the attack itself very likely occurred between August 7–12, 2026, according to the Berlin State government.2 Rhysida claims the data exfiltrated includes:
- Government, legal, financial, contractual, HR, infrastructure, health, and mapping records
- Thousands of names, email addresses, and phone numbers, as well as 148 international bank account numbers
- Plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials
- Personnel files, payroll information, administrative-offense records, email archives, SQL database dumps, identity documents, and banking information
- Documents related to disciplinary proceedings and other named cases
- Allegedly classified or sensitive government material, including Bundesrat committee records and information about handling classified documents
- Critical-infrastructure security assessments concerning Berlin’s water supply
- More than 3,200 documents marked as nondisclosure agreements3
Rhysida further claims the data includes violations of the GDPR, the EU’s comprehensive data law that governs the safekeeping of the personal data of EU citizens or residents held digitally by organizations.4 The threat actor very likely used alleged GDPR violations as leverage to persuade Berlin to pay the ransom. However, the government of the German capital refused to pay,5 almost certainly leading to the subsequent sale advertisement.
Berlin’s refusal to pay is consistent with guidance from the German federal cybersecurity agency6 and comes less than a month before the Berlin State elections on September 20, 2026, when both a new state parliament and local district councils will be elected to serve five-year terms.7 Berlin’s refusal to pay the ransom was very likely influenced by the upcoming elections, highlighting that governments are likely to show resolve against cybercrime in the lead-up to important elections.
Rhysida’s timing is unlikely to be a coincidence. There is a roughly even chance the threat actor timed this operation, and the subsequent leak of data, to influence the Berlin State elections. ZeroFox assesses that, as further elections draw near across Europe over the next six to 12 months, threat actors will almost certainly seek to influence outcomes by conducting timed operations likely intended to sow distrust in government institutions.
ZeroFox Intelligence Probability Scale
All ZeroFox intelligence products leverage probabilistic assessment language in analytic judgments. Qualitative statements used in these judgments refer to associated probability ranges, which state the likelihood of occurrence of an event or development. Ranges are used to avoid a false impression of accuracy. This scale is a standard that aligns with how readers should interpret such terms.
- hXXps://www.bleepingcomputer[.]com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/
- Ibid.
- Ibid.
- hXXps://securityaffairs[.]com/198064/cyber-crime/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote.html
- Ibid.
- hXXps://tech-insider[.]org/berlin-confirms-data-theft-rhysida-ransomware-2026/
- hXXps://www.rbb24[.]de/politik/berlin-wahl-2026/beitraege/faq-englisch-berlin-elections-state-parliament-district-councils.html