What happened
Tagesschau reported that unauthorised access and data removal occurred between August 7 and August 12, 2026, with the incident detected on August 14, 2026. Two Berlin Senate administrations were affected, and the incident disrupted public functions while authorities investigated data theft and isolated systems.
On September 4, 2026, Berlin confirmed that stolen government data had been published and began an intensive forensic review. Reuters reported that the released trove followed an auction associated with 5.79 terabytes of data and a starting price of 30 bitcoin. Berlin said identified individuals would be informed according to risk and applicable legal requirements.
On September 5, 2026, Berlin established a central coordination unit under its Chief Digital Officer to direct review, notification and security-agency coordination. The unit brought together the affected administrations, police, data-protection and information-security authorities to evaluate released material and support affected citizens, businesses and government bodies.
During the night into September 6, 2026, attackers released an additional data package containing credentials. Berlin said the additional package included credentials, but it did not publish the credential types, values or number of affected accounts. Berlin said strengthened safeguards could cause short-term restrictions in specialist applications used by the affected Senate administration. Attribution posture: Berlin reported that Rhysida claimed the attack, but the cited official statements did not publish a final forensic attribution.
Why this matters now
The Sunday disclosure changed the incident from a large public data-release problem into an explicit credential-containment problem. Once access data appears in a released package, identity teams must assume potential reuse across legacy, administrative, service and partner paths until scope and revocation are proved.
Berlin also warned that additional safeguards could temporarily restrict specialist applications. That is the core executive trade-off: reducing the probability of credential reuse may impair public services. Security, operational leadership and legal teams need one prioritised decision process rather than independent technical changes.
For enterprises, the lesson extends beyond government. Extortion incidents can create successive response waves after the initial leak: new archives reveal more sensitive classes, notification populations change, fraud risks rise and controls that appeared complete must be reopened. Leak publication is an event in the incident timeline, not closure.
The decision for security leaders
Assign identity leadership to scope exposed credential classes and contain every plausible reuse path. The work should include human accounts, service identities, embedded secrets, remote access, shared credentials and partner connections.
Assign incident response to reopen containment validation after each new archive release. A previous clean assessment may no longer be sufficient when newly disclosed data changes the credential or sensitive-information scope.
Assign legal, privacy and service owners to coordinate notification and operational restrictions. Control changes should be risk-ranked so that essential services remain available through approved alternatives where possible.
Evidence of closure
- Credential inventory records an approved disposition for every exposed class.
- Identity telemetry shows no unexplained use after containment.
- Notification register identifies verified affected populations and legal decisions.
- Continuity validation confirms approved operation of restricted specialist applications.
The Security.io assessment
The second package is the weekend’s material change because Berlin explicitly identified credentials within the released data and strengthened safeguards in response. This creates a more immediate defensive requirement than the earlier extortion demand or unverified descriptions of archive contents.
The cited weekend statements did not publish malware hashes, filenames, attacker IP addresses, domains or forensic details of initial access. Security.io therefore does not infer a technical entry method or treat the threat actor’s claimed volume as an independently verified inventory of affected records.
This story warrants inclusion because it demonstrates a distinct ransomware decision stage: public release can uncover new risk classes after initial containment. CISOs need an operating model that reopens identity, notification and continuity decisions whenever verified leak contents materially expand the incident scope.
Questions for the morning meeting
- Which credential classes were present in the newly released package?
- Have all potentially exposed identities, secrets and access paths been contained?
- Can critical services tolerate the restrictions introduced during credential response?
- Are notification and fraud-monitoring decisions supported by verified data review?