Bremen – September 14, 2026 -- Ransomware group Rhysida published 5.79 terabytes of stolen data -- 1.44 million files -- from Berlin's state administration network BeLa on the darknet on September 4, after the city refused to pay a ransom of roughly €2 million. IT security consultancy team neusta and crisis communications specialist NetFed are citing the breach as a warning case for organizations of any size.
Attackers infiltrated two Berlin Senate administrations between August 7 and 12, 2026, copying data undetected for days before the intrusion into the BeLa network was discovered on August 14. The leaked dataset includes personal information on more than 12,000 individuals and emergency plans tied to critical infrastructure.
Weak Network Segmentation and Plaintext Credentials Enabled the Breach
team neusta identified three technical failures in the case: access credentials stored in plaintext within Office files, data exfiltration that went unnoticed for several days, and insufficient network segmentation that allowed access to sensitive records held by a separate administration.
50,000 Households Could Not File Housing Benefit Claims for Over a Week
The disruption had direct consequences for citizens. For more than a week, roughly 50,000 households were unable to apply for Wohngeld (housing benefit), and both affected administrations were at times reachable only by phone.
First Public Statement Came Four Days After Network Disconnection
Crisis communication lagged the technical response. Berlin's first press release followed four days after the network was disconnected and relied on vague language citing "investigative reasons." An early assurance from Governing Mayor Kai Wegner that no sensitive data had been affected had to be corrected days later, and no central channel existed for citizens or media to track the situation.
Tascha Schnitzler, Business Development Public Sector at team neusta, said cyberattacks on German organizations are "no longer an exception but everyday reality," adding that the topic still is not treated with the seriousness it deserves. She linked the incident to eroding public trust in government, pointing to voter turnout and sentiment in recent Saxony-Anhalt elections as evidence of how fragile that trust already is.
Leaked Organizational Documents Could Sharpen Future Phishing Attacks
Analysts at team neusta warn that individually harmless documents -- organizational charts, phone numbers, vendor contracts, credentials, emergency procedures -- combine into a detailed operational profile of an organization once aggregated. Such material could make phishing emails referencing real names, real processes and actual service providers far harder to detect, a risk extending to any company working with the affected agencies. Unverified reports suggest the leaked dataset may also include documents related to civil-military cooperation, which security professionals say could be of interest to state actors preparing hybrid operations; this has not been confirmed.
team neusta Calls Data Publication a Trust Crisis, Not Just a Security Incident
André Conin, Key Account AI at team neusta, said the deciding question is no longer whether an attack can be prevented, but whether an organization is prepared when one occurs. "Systems can be restored, lost trust much less so," Conin said, arguing that technical security, incident response and crisis communication must be integrated.
NetFed: 1.44 Million Files Form a Dataset, Not a Random Document Pile
Thorsten Greiten, managing director of NetFed, said a password can be reset by Monday, but a water utility cannot. He noted the security barrier must be established before data exfiltration occurs, not after, when it is too late for delisting requests or takedown notices to restore confidentiality.
Five-Point Framework Targets Both Technical and Communication Gaps
team neusta and NetFed outlined five measures applicable to organizations of any size: a documented and rehearsed incident-response plan defining internal and external communication roles; a legally vetted "dark site" with crisis communication templates activatable within minutes; quarterly security audits and penetration tests rather than one-off checks; a backup strategy following the 3-2-1 rule; and continuous employee training with phishing simulations in a culture that does not penalize reporting suspicions.