Sep 09, 2026 · 7 min read
Rhysida Leaks 16,389 Berlin Emails and Plaintext Logins
Berlin's Senate refused 30 Bitcoin from the first day. The countdown ran out on a Friday afternoon and 5.79 terabytes went public: 1,439,893 files covering 12,076 residents, 148 IBANs, and every letter those people ever sent a city agency.
Most of the coverage led with the terabytes. The number that will still matter in 2028 is 5,941, the count of leaked files that contain passwords, and the group's claim that some of those passwords open a building management database. Berlin was right to refuse. It just did not protect anyone, and Euronews reported the dump landing on the dark web minutes after the deadline.
Key Takeaways
- Rhysida published 5.79 terabytes across 1,439,893 files taken from Berlin's state network after the Senate refused a ransom of 30 Bitcoin, roughly 2 million euros.
- The itemised set includes 16,389 email addresses, 11,963 phone numbers, personal data on 12,076 individuals, 148 IBANs and 5,941 files containing passwords.
- Rhysida claims plaintext credentials for internal systems including the GebäudeAtlas building management database, the PAYONE ePayment database and Z_ADMIN accounts.
- A second tranche of login data surfaced on September 7 and Berlin opened a fresh investigation, 13 days before the city's September 20 municipal election.
- Governing Mayor Kai Wegner said "a very serious crime has been committed against the State of Berlin" and the city stood up an extra task force to identify who is affected.
What Did Rhysida Actually Publish?
Rhysida published what it says it took from two Berlin Senate departments between August 7 and August 12, 2026, itemised on a leak site entry titled "Berlin, Germany" that went up on August 28. The inventory is unusually specific for a ransomware listing, and Help Net Security published the breakdown.
- 16,389 email addresses, 11,963 phone numbers and personal data on 12,076 individuals
- 148 IBANs, alongside 55,553 financial files and 46,522 contracts
- 27,299 HR files and 77,939 legal and complaints files
- 124,823 mapping and geodata files, the single largest category
- 5,941 files containing passwords
The departments hit were urban development and housing, and mobility, transport, climate protection and environment. Berlin severed both from the state network on August 14, stalling housing benefit payments and family support until they returned on August 23. A second tranche of login data appeared over the weekend of September 7 and prompted a new investigation.
Why Do Plaintext Credentials Change the Cleanup?
Because a leaked password is not a record you notify someone about, it is a door somebody can still walk through. Rhysida claims working plaintext credentials for the GebäudeAtlas building management database, the PAYONE ePayment database and Z_ADMIN accounts, plus login data belonging to Berlin's leadership, which The Record covered as the second Berlin breach.
A building management credential is the one item on that list whose blast radius is not digital. Those systems drive door controllers, HVAC schedules and lift access across public buildings. If it is live, the exposure outlives the data breach entirely, because you cannot notify a data subject out of a physical access problem.
These are also two clocks that organisations routinely conflate. Notifying data subjects is a legal deadline measured in hours. Rotating credentials scattered across 5,941 password bearing files is an inventory problem measured in months, owned by a different team, and invisible from outside. Berlin's task force is visibly doing the first. The second is where the residual risk sits.
Who Is Rhysida and How Does It Get In?
Rhysida is a ransomware as a service operation that surfaced in May 2023, splits proceeds with affiliates, and has named close to 300 victims across 39 countries. Its documented entry point is boring: the joint CISA, FBI and MS-ISAC #StopRansomware advisory AA23-319A records affiliates authenticating to internal VPN access points with valid stolen credentials, specifically at organisations that had not enabled multifactor authentication by default, plus Zerologon (CVE-2020-1472) and ordinary phishing.
The victim list explains why refusing changed nothing about publication. The British Library, the Chilean Army, Port of Seattle (90,000 people notified) and Sony's Insomniac Games all sat on it, and Insomniac saw 1.67 terabytes published after declining a $2 million demand. Roughly 92 percent of organisations named on Rhysida's leak site end up with their data posted, according to Help Net Security's reporting on the Berlin case.
Berlin is also not Rhysida's first German city administration. Stuttgart's was already on the list, making this a repeat pattern against German municipal targets, and it lands while German firms trace 37% of attacks to foreign actors.
What This Means for Your Inbox
For the 12,076 people in that file, the durable harm is not the password reset. It is that an email address is now permanently bound to a documented interaction with a named agency. The leak contains correspondence with departments and copies of documents residents submitted, so an attacker does not merely learn an address exists. They learn this person wrote to the housing department about a specific matter, with her postal address, date of birth and bank details in the same row.
That is a targeting dataset, and it makes credible spear phishing possible for years. A message citing a real case, a real department and a real date, sent to an address that genuinely corresponded with that department, reads as unremarkable to any filter hunting generic fraud signals. Compare the Manchester Airports breach that hit 8.7 million customers: vastly larger, but thin per person. Berlin's is small and deep, the harder shape to defend.
There is a second effect nobody has priced in. German language phishing at public sector citizens has historically been let down by clumsy translation, which is the tell most people rely on. A dump of genuine agency correspondence hands attackers a style guide for the exact register a Senate department uses. That tell disappears.
What Should an Affected Berlin Resident Do?
Treat the address as burned and change how you verify, not just what you click. The pattern after any government leak of this shape is identical to what followed the Polish healthcare breach affecting 19 million people, where the follow on fraud arrived weeks after the headlines faded.
- Verify out of band. If a message references your case, call the department using a number you looked up on berlin.de yourself. Never a number or link inside the message.
- Watch the account, not the inbox. With 148 IBANs published, the realistic abuse is an unauthorised SEPA direct debit mandate. Under SEPA rules you can reclaim an authorised debit for eight weeks and an unauthorised one for 13 months, so check statements monthly.
- Rotate anything reused. If a password you used with a Berlin online service appears anywhere else, change it there first. Reuse is what turns one leak into five.
- Distrust "confirm your identity" mail about the leak itself. A breach notice asking you to log in and check whether you are affected is the most predictable follow on lure there is.
What Compliance Teams Should Take From This
Refusing to pay is a policy position, not a compliance defence. GDPR Article 33 still requires notification to the supervisory authority within 72 hours of awareness, and Article 34 still requires communication to data subjects without undue delay where the risk to them is high. Berlin's authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, led by Meike Kamp.
Two details belong in your own runbook. Article 34(3)(a) excuses individual notification only where the controller had rendered the data unintelligible, meaning encryption at rest with keys the attacker never held. Exfiltrated plaintext fails that test by definition. And Article 33(4) permits phased notification, which is exactly what a second tranche forces: new material means a new scope assessment, not a closed file. Regulators price the aftermath, as the CNIL's €500,000 fine against a French hospital over 727,000 records showed.
The metric a board should ask about is not the ransom. It is the gap between exfiltration starting on August 7 and the network being severed on August 14. Seven days of undetected outbound transfer turned an intrusion into 1.44 million published files.
Looking Ahead
Berlin's refusal was the correct call: paying would have funded the next attack and, against a group that publishes anyway in the overwhelming majority of cases, bought nothing. But the decision came after the data was already gone. By August 28 the only choice left was who profited.
Watch two things. Whether Berlin says anything concrete about credential rotation, GebäudeAtlas in particular, rather than only notification counts. And whether those 16,389 addresses start appearing in German language lures quoting real case details. The second is the bill for the seven day gap, and it arrives long after the news cycle has moved on.