CSIDB logo
Incident

Senate Department for Mobility, Transport, Climate Protection and Environment

Incident posture

Attack window
Aug 2026
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 11:51

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

On August 31, Berlin's state government confirmed that data was forensically verified as stolen from the Senate Department for Mobility, Transport, Climate Protection and Environment during a five-day window in early August, marking an escalation from earlier hedged statements about a possible breach. The Rhysida ransomware group had publicly claimed responsibility roughly three days earlier, asserting it exfiltrated approximately 5.79 TB of data across 1.44 million files, including personal records tied to over 12,000 individuals, supplier contracts, passwords, and bank details—figures the government has not independently verified. Data had reportedly been leaving the shared administrative network undetected for roughly a week before the intrusion was discovered, prompting authorities to disconnect two Senate departments from the central network as a containment measure. Berlin's political leadership has firmly rejected the ransom demand, with the Mayor and Interior Senator publicly stating the capital will not negotiate with extortionists, while investigators from state and federal agencies continue piecing together the full scope of the compromise.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On August 31, 2026, Berlin's state government confirmed that data was forensically determined to have been stolen from the Senate Department for Mobility, Transport, Climate Protection and Environment during the Rhysida ransomware incident, ending roughly two weeks of official hedging in which officials acknowledged an attack had occurred but would not commit to the proposition that non-public information had been taken. Forensic analysis pinpointed a confirmed data-exfiltration window of August 7 through August 12, 2026, inside that single Senate department, one of two administrative portfolios that Berlin had severed from its central administrative network, the Landesnetz, on August 14 as a containment measure. The other disconnected department was the Senate Department for Urban Development, Building and Housing. State Secretary for Digital Affairs Florian Hauer stated that data had been leaving the network for roughly a week before the intrusion was discovered, a timeline that explains why the confirmed outflow window predated the August 14 disconnection by approximately seven days. Investigators from the State Criminal Police Office, the public prosecutor's office, and federal security agencies were assigned to the case.

The Rhysida ransomware-as-a-service group publicly claimed responsibility for the intrusion on August 28, 2026, when it posted a Berlin entry on its dark-web leak site and opened what it described as a four-day countdown toward an auction of the stolen material, with a starting price of 30 Bitcoin. According to the gang's own statements, as reported by outlets including The Hacker News and SecurityWeek, the dataset totals 5.79 TB spread across roughly 1.44 million files and includes approximately 46,500 supplier and third-party contracts, more than 11,000 confidential documents, close to 6,000 passwords, tens of thousands of emails and phone numbers, 148 IBAN bank account numbers, and personal records tied to 12,076 individuals. None of those volume or category figures have been independently verified by Berlin's government, which has restricted its public statements to the forensically confirmed exfiltration from the Mobility, Transport, Climate Protection and Environment portfolio during the August 7–12 window. Berlin's government was explicit that the full extent of the incident remains under review.

Berlin's political leadership rejected the extortion demand outright. Mayor Kai Wegner stated publicly that "Berlin will not be blackmailed," and Interior Senator Iris Spranger added that "regardless of the amount demanded or the method of extortion, we will not allow this extortion to take place in the federal capital and in Berlin." Both statements were reported by outlets including the BBC and The Berliner. The refusal is consistent with guidance from Germany's federal cybersecurity agency and with a broader European trend of public-sector bodies declining to negotiate with ransomware operators. Rhysida has been active since mid-2023 and reporting on the Berlin incident placed its victim count at roughly 280 organizations worldwide, concentrated in sectors such as hospitals, universities, school districts, and state and municipal governments.

The confirmed sequence of events places initial unauthorized data movement out of the Senate department at approximately August 7, 2026, followed by detection of the intrusion in mid-August. On August 14, 2026, Berlin disconnected the Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and Environment from the shared Landesnetz administrative network as a containment step. Rhysida's public leak-site entry followed on August 28, with Berlin's leadership rejecting the ransom within the same window. On August 31, the city-state's language shifted from an acknowledgment that an attack had occurred to an explicit confirmation that data exfiltration had taken place and been validated by forensic review. The roughly two-week gap between the last confirmed data outflow on August 12 and the public confirmation on August 31 reflects the standard incident-response timeline for a network of Berlin's size, during which time the attackers had unsupervised access to map connected systems, harvest credentials, and select which departments to target.

The confirmed scope of the incident is narrower than the attacker's public claims. Berlin has validated exfiltration from one Senate portfolio during a specific five-day window in August and has not validated Rhysida's headline figure of 5.79 TB or its claim that 12,076 individuals had personal data exposed. The Senate has stated that personal or otherwise non-public data may be among what was taken but has not published a complete list of affected individuals or data categories, mirroring the "confirmed but not comprehensive" disclosure pattern common in large-scale government breaches. The Senate Department for Mobility, Transport, Climate Protection and Environment is the only department for which exfiltration has been publicly confirmed to date, although the precautionary disconnection of the second Senate portfolio suggests additional review is underway. Berlin is approaching an election cycle, and the pre-election timing has been cited by outlets covering the breach as amplifying the political stakes of the disclosure.

Operational and regulatory consequences were set in motion by the August 31 confirmation. Once a government body formally confirms data theft, it typically triggers breach-notification obligations, regulatory scrutiny, and a documentation trail that outlives the news cycle. Class-action-style complaints or data-protection authority inquiries tied to GDPR notification obligations are anticipated in the weeks following the disclosure. The Senate has not yet published a full breakdown of affected individuals or organizations, and a more complete accounting is expected to follow the initial confirmation once forensic reconstruction is finalized. Rhysida's auction countdown was scheduled to lapse in early September 2026, and based on the group's pattern in past incidents, the listing was expected to either proceed without a sale and lead to publication of the data or be quietly shelved if no buyer emerged. Berlin's confirmation that data was stolen from the Senate Department for Mobility, Transport, Climate Protection and Environment during the August 7–12 window, alongside the precautionary disconnection of a second Senate department and the refusal to engage with the ransom demand, represents the established factual record of the incident as of August 31, 2026.

Sources

Sources available to members: 1 source.

CSIDB