CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Berlin Landesnetz compromise (August 2026)

incident · incident:berlin-landesnetz-compromise-2026-08

Compromise of the Landesnetz, the shared network of the Berlin state administration, established by forensic investigation and confirmed by the Senate Chancellery on 2026-08-17; two Senate departments were isolated from the network from 2026-08-14 and reconnected on 2026-08-23, blocking housing-benefit disbursement to more than 50,000 entitled households and other district-level citizen services. The Landeskriminalamt, the Berlin public prosecutor and the BSI are involved. Investigative journalism (Der Tagesspiegel, 2026-08-28) first named a phishing-email click as the access vector and reported an extortion demand of 30 Bitcoin from a group media reporting attributes to Rhysida; Germany's BSI (BITS-2026-287419-1032, 2026-09-04, confirmed via Mastodon the same day) has since officially confirmed the TerminalFix campaign as the specific access vector and Rhysida (tracked by BSI as Vice Spider) as the responsible actor, though Berlin's Senate administration itself still declines to confirm either.

Aliases: Hackerangriff auf das Berliner Landesnetz, IKT-Vorfall im Landesnetz Berlin, Berlin state network cyberattack

Coverage
1
first 2026-08-23 → last 2026-09-10
Latest activity
2026-09-10
Berlin confirms extortion after a phishing click reaches the shared state network; media reports name Rhysida
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector · regions: dach
Sources cited
14
8 hosts

Defender insights

What each entry about Berlin Landesnetz compromise (August 2026) tells a defender to do, newest first.

2026-08-30HIGHBerlin confirms extortion after a phishing click reaches the shared state network; media reports name Rhysida

Latest update · triage

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed to

part of

Story timeline

  1. 2026-08-30Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida
    active-threatsBerlin confirms extortion after a phishing click reaches the shared state network; media reports name Rhysida
ATT&CK techniques (3 across 3 tactics)

3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessPhishing
  • ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
  • ImpactFinancial Theft

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector · ATT&CK page ↗

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector · ATT&CK page ↗

Entries about Berlin Landesnetz compromise (August 2026) (1)

2026-08-30 · view entry permalink →

HIGHupdatedNATOB1

Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida

Germany's Berlin state administration is the target of a live extortion attempt following a compromise of its Landesnetz, the shared network serving every Senate department and state agency; Der Tagesspiegel and rbb24 both independently date the two affected departments' disconnection from the network, as a containment measure, to 2026-08-14 (translated from German) (Der Tagesspiegel, 2026-08-28; rbb24, 2026-08-29); Berliner Zeitung independently dates the attack becoming publicly known to the same day, stating the departments were disconnected shortly after the incident became known without giving a separate explicit date for the disconnection itself (translated from German) (Berliner Zeitung, 2026-08-28). Contradiction: Security Affairs instead states "Berlin first disclosed the compromise on August 17, isolating" the same two departments, dating both the public disclosure and the network isolation itself three days later than the German-language reporting (Security Affairs, 2026-08-29). This entry follows the 2026-08-14 date as the better-corroborated account (two independent German-language outlets against one English-language aggregator) without resolving the discrepancy. Investigative reporting, not an official technical disclosure, is the first to name a mechanism: the attackers apparently gained access to the Landesnetz through an employee's click on a phishing email (translated from German) (Der Tagesspiegel, 2026-08-28). Forensic investigators found the actual data exfiltration ran between 2026-08-07 and 2026-08-12 (Security Affairs, 2026-08-29), several days before the two affected departments were disconnected.

Der Spiegel reported, citing security-industry sources, that the ransomware group Rhysida is behind the attack (heise online, 2026-08-29), an attribution Berlin's Senate administration has declined to confirm, citing investigative-tactical reasons (heise online, 2026-08-29). Rhysida's own dark-web leak site independently posted an entry titled "Berlin, Germany" on 2026-08-28 claiming 5.79 terabytes of data across roughly 1.44 million files, including personal data on 12,076 individuals, more than 5,000 personnel files, plaintext credentials for internal systems, disciplinary and court records, Bundesrat committee protocols, and vulnerability analyses concerning Berlin's water supply (Security Affairs, 2026-08-29). Rhysida demanded 30 Bitcoin, about EUR 2 million (translated from German) (heise online, 2026-08-29), with a one-week ultimatum running from 2026-08-28 (translated from German) (Der Tagesspiegel, 2026-08-28); Berlin's Governing Mayor Kai Wegner and Interior Senator Iris Spranger jointly confirmed the extortion attempt and publicly refused to pay, stating the state of Berlin will not submit to extortion (Security Affairs, 2026-08-29). Whether the affected systems were also encrypted, not only exfiltrated, is disputed: one outlet attributes to unnamed "experts" the claim that the Rhysida ransomware was the tool used to both encrypt the systems and steal the data (translated from German) (BornCity, 2026-08-29), while every other cited source describes only data theft and extortion without confirming encryption; this entry does not assert that encryption occurred.

CrowdStrike is conducting a forensic investigation across every Senate department and state agency network-wide, an effort Tagesspiegel's sources expect to take several more days (Der Tagesspiegel, 2026-08-28). The department networks disconnected on 2026-08-14 were reconnected on 2026-08-23, but staff report continuing operational degradation days later, with many now working over private internet connections because the corporate network remains impaired; the same reporting flags that workaround as a new, self-inflicted security exposure (Der Tagesspiegel, 2026-08-28). Rhysida has run this extortion pattern against public-sector targets before, including an earlier 2026 claim against the city of Stuttgart (translated from German) (heise online, 2026-08-29); per the joint CISA/FBI/Multi-State ISAC advisory on the group, current as of its 2025-04-30 update, its initial-access techniques include compromising internal VPN access points using valid credentials at organizations lacking multi-factor authentication, and separately deploying Gootloader malware (CISA, 2025-04-30).

Triage: the confirmed mechanism, a user-driven phishing-email click followed by multi-day bulk data exfiltration, surfaces at the point of delivery in mail-flow and attachment-sandboxing logs, and in network-egress and data-loss-prevention telemetry as a sustained high-volume outbound transfer from a single department's network segment; neither cited source states what executed after the click, so no process-level discriminator is offered here.

The attackers apparently gained access to the Landesnetz through an employee's click on a phishing email.

Der Tagesspiegel 2026-08-28

“The state of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin's interior senator, Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack on their Tor data leak site.

The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Security Affairs 2026-08-29

Experts identified the ransomware Rhysida as the tool with which the systems were encrypted and the data stolen.

BornCity 2026-08-29

All files have been uploaded to the publicly accessible area, have fun browsing, data hunters!

Rhysida leak-site posting, via heise online

Based on what I can see here now, they have put the complete dataset online for everyone to view

Joachim Selzer, Chaos Computer Club spokesperson, via heise online (dpa)

Among the data that is viewable is, for example, the application for a new phone, including the signature of the administrative employee.

heise online (dpa)

the ministry points only to the existing constitutional framework.

heise online, citing the Federal Interior Ministry's (BMI) written reply

Until now, the BSI has only been constitutionally permitted to assist the states in defending against serious cyberattacks after an explicit request for administrative assistance. In addition, lengthy bilateral agreements had to be concluded, and these still do not exist with all 16 federal states today.

heise online 2026-08-29

In addition, data containing information on critical infrastructure, companies and organizations can, depending on the sensitivity of the data, also increase the threat level. (translated from German)

BSI spokesperson, via heise online

According to Der Tagesspiegel, the data reportedly also includes information on heating plants, fuel depots, backup-power facilities, substations, prisons, waterworks, as well as armaments companies and the Bundeswehr. (translated from German)

heise online, citing Der Tagesspiegel

The state of Berlin acted grossly negligently and deliberately failed to comply with classified-information protection requirements. (translated from German)

Manuel Atug (IT-security expert), via heise online (dpa)

That TerminalFix is the attack vector used by the Rhysida cybergang has been confirmed by the BSI in a Mastodon post. (translated from German)

This makes it clear: the Senate administrations for construction and transport were attacked via TerminalFix. (translated from German)

heise online (Nico Ernst) 2026-09-07

The Rhysida ransomware and leak site is attributed to the financially motivated group Vice Spider (aka Vice Society, WhiteNefas, White Hekate, DEV-0832, Vanilla Tempest). (translated from German)

BSI (Bundesamt für Sicherheit in der Informationstechnik), BITS-2026-287419-1032, v1.0 2026-09-04

This data leak is of grave scope and endangers our national security.

Roderich Kiesewetter (CDU defense-policy spokesperson), via Süddeutsche Zeitung, relayed by heise online

In an internal letter, he cites concerns, according to rbb, about near-unlimited data access, possible disruption to specialised administrative applications, and remaining monitoring risks for staff.

heise online, citing rbb24, on the Lichtenberg district's refusal to deploy CrowdStrike Falcon Agent

Berlin's data protection commissioner Meike Kamp and the security agencies advise those potentially affected to exercise increased vigilance. They recommend changing passwords, closely monitoring account activity, and increased scepticism toward phishing emails.

heise online, citing Berlin's Data Protection Commissioner Meike Kamp
Updaterun 2026-09-05T0409Z-intelupdated_atsourcesevidencebody

Rhysida's one-week ultimatum expired on 2026-09-04 at roughly 15:35 local time; the Berlin Senate had publicly committed not to pay, and about an hour after the deadline the group published the full stolen dataset on its darknet leak site, replacing the prior partial "auction" listing (heise online, 2026-09-04). Chaos Computer Club spokesperson Joachim Selzer confirmed the complete dataset (including personnel files and documents Selzer describes seeing directly, such as employment references) is now publicly accessible to anyone. Whether the dataset actually contains the drinking-water vulnerability analyses and administration credentials the group had earlier claimed remains unverified by any party this entry cites: Left-party parliamentary faction leader Tobias Schulze stated the Senate now has the opportunity to check whether the prior assumptions about the leaked data are accurate, and should notify affected individuals and organizations as quickly as possible once it does. No further technical root-cause detail beyond the phishing vector has been disclosed by the Senate.

Updaterun 2026-09-06T0409Z-intelupdated_atsourcesevidencebody

A structural consequence of this incident has now surfaced at the federal level. Asked in a Bundestag inquiry whether, given ongoing severe attacks on states and municipalities, the government would bring forward a constitutional amendment planned earlier by the previous coalition to make the BSI a true central authority for cyber incidents, the Federal Interior Ministry pointed only to the existing constitutional framework (heise online, 2026-09-03). Under that framework, the BSI may assist a state in defending against a serious cyberattack only after that state explicitly requests administrative assistance, and durable bilateral cooperation agreements (a precondition the ministry itself confirms do not yet exist with all 16 federal states) still gate faster support; in practice the BSI has repeatedly had to help first and formalise the legal basis afterward (heise online, 2026-09-03). The ministry points instead to its 14 existing cooperation agreements, its NIS2-transposition-driven expansion of BSI's powers, and increased staffing and budget as sufficient. Green-faction deputy chair Konstantin von Notz, who filed the inquiry, called the reversal "devastating for Germany's IT security" (translated from German) given the still-unfolding fallout from this exact incident. The tension is directly transferable to any federated cyber-incident-response model, including Switzerland's own federal/cantonal/communal cooperation structure with BACS: a central technical authority's ability to help is gated by a request-and-agreement process rather than by its own capacity to act.

Separately, on the incident itself, the Chaos Computer Club's Joachim Selzer identified specific record types now visible in the fully-published leak beyond the personnel-and-employment-reference material already recorded here: an internal request form for a new mobile phone bearing the requesting employee's handwritten signature, which Selzer noted gives a criminal a usable signature sample (heise online, 2026-09-04).

Updaterun 2026-09-07T0411Z-intelupdated_atsourcesevidencebody

Follow-up reporting establishes for the first time that the scope of the published leak extends well beyond the personal data first identified. Citing Der Tagesspiegel, heise reports the dataset also includes information on district-heating and power plants, fuel depots, backup-power installations, electrical substations, prisons, waterworks, and armaments companies and the Bundeswehr (translated from German) (heise online, 2026-09-06), a materially broader critical-infrastructure and defense-industrial exposure than the water-supply-vulnerability material Rhysida itself had claimed at disclosure.

Germany's BSI issued a public warning on 2026-09-05 of an elevated threat level stemming from the leak. The agency states data containing information on critical infrastructure, companies and organizations can, depending on its sensitivity, also increase the threat level (translated from German) (heise online, 2026-09-05), and separately warns of heightened targeted-phishing risk against anyone who had contact with affected individuals or institutions (heise online, 2026-09-05). BSI additionally flags a hack-and-leak risk specific to the political calendar: Berlin holds a state-parliament election on 20 September 2026, and stolen documents can be released or recontextualized at a moment favorable to an attacker (heise online, 2026-09-05). BSI assesses the underlying intrusion itself as financially rather than politically motivated (heise online, 2026-09-05), an assessment attributed to BSI, distinct from opposition politicians' own separately reported alarm about the incident's severity.

Berlin's government responded on 2026-09-06 by establishing a dedicated coordination unit ("Steuerungseinheit") in which BSI, the Federal Criminal Police Office (BKA) and the domestic intelligence service (BfV) jointly review and assess the leaked material, and by starting a risk-based notification process to contact affected citizens, employees and companies by letter or email (heise online, 2026-09-06). Independent IT-security expert Manuel Atug separately stated that the state of Berlin acted grossly negligently and deliberately failed to comply with classified-information protection requirements (translated from German), adding that he had already flagged the same security gaps to Berlin's parliamentary interior committee in 2023 and 2025 (heise online, 2026-09-06). Contradiction: the heise 2026-09-06 timeline separately dates full network reconnection to 2026-08-24, one day later than the 2026-08-23 date this entry's main analysis attributes to Der Tagesspiegel; both dates are carried without resolving the one-day gap.

The same 2026-09-06 report adds a fourth account of the date sequence: its own retrospective timeline states the two affected Senate departments were isolated from the Landesnetz on 2026-08-14 (matching Der Tagesspiegel and Berliner Zeitung's dating of the isolation, not Security Affairs' 2026-08-17) and separately states the Senate chancellery's public press statement disclosing the "ICT incident" followed on 2026-08-17 (translated from German) (heise online, 2026-09-06). This distinguishes network isolation (2026-08-14, now three independent accounts) from the Senate's own formal press disclosure (2026-08-17) as two separate events, but Security Affairs' claim that the isolation itself happened on 2026-08-17 remains an unresolved discrepancy with the German-language reporting, not one this update can settle.

Updaterun 2026-09-08T0411Z-intelupdated_atentitiestechniquessourcesevidencesourcing_noteconfidenceclassificationbody

Germany's BSI published an advisory on 2026-09-04 describing the compromise of an anonymized "state institution" whose technique matches the multi-stage TerminalFix campaign Microsoft documented on 2026-08-28, the advisory itself never names Berlin (BSI, BITS-2026-287419-1032, 2026-09-04). The same day, BSI posted on its official Mastodon account that it was intensively involved in handling the Berlin incident and separately linked to its detailed TerminalFix security notice; heise reports that juxtaposition as confirmation that TerminalFix is specifically the attack vector the Rhysida operators used against Berlin's two affected Senate administrations (heise online, citing BSI, 2026-09-07), the first technical confirmation, reported by heise, of both the access vector and the attribution this entry had previously carried only from investigative journalism. BSI attributes the Rhysida ransomware and leak site to a financially motivated group it tracks as Vice Spider, cross-referenced against the aliases Vice Society, WhiteNefas, White Hekate, DEV-0832 and Vanilla Tempest, active since at least mid-2021 and using the Rhysida ransomware and leak site almost exclusively since June 2023 (BSI, BITS-2026-287419-1032, 2026-09-04). BSI's advisory adds a detail beyond what Microsoft's original write-up described: reporting organizations told BSI that TerminalFix operators have staged exfiltration into attacker-controlled cloud storage, for example Azure, using the cloud provider's own transfer tooling such as azcopy (BSI, BITS-2026-287419-1032, 2026-09-04). BSI further states that incident reports place a malware family it names LoremIpsumLoader (also known as AxolotLoader) within the campaign, and attributes that loader to the same group responsible for Rhysida (BSI, BITS-2026-287419-1032, 2026-09-04). BSI assesses the campaign as opportunistic, purely financially motivated cybercrime with no established link to a state or politically motivated actor, and states Rhysida shows no particular regional focus on Germany, concentrating instead on education and healthcare, with public administration a more distant top-five target sector (BSI, BITS-2026-287419-1032, 2026-09-04).

Updaterun 2026-09-10T0410Z-intelsourcesevidencebody

CDU defense-policy spokesperson Roderich Kiesewetter told Süddeutsche Zeitung "this data leak is of grave scope and endangers our national security" (translated from German), naming civil-defense and total-defense emergency plans and barracks documents as part of the published dataset alongside the critical-infrastructure material already recorded here; Germany's Bundeswehr Operative Führungskommando and the Nationales Cyberabwehrzentrum have joined BSI in reviewing the security fallout (heise online, citing Süddeutsche Zeitung, 2026-09-07). Separately, the Berlin district of Lichtenberg has refused to deploy CrowdStrike's Falcon Agent on its own servers: "in an internal letter, he cites concerns, according to rbb, about near-unlimited data access, possible disruption to specialised administrative applications, and remaining monitoring risks for staff" (translated from German), while the district states it has found no evidence of intrusion on its own systems and is demanding the Senate assume full responsibility and cost for the response (heise online, citing rbb24, 2026-09-07). Berlin's data protection commissioner Meike Kamp has now issued concrete guidance for potentially affected individuals: "change passwords, closely monitor account activity, and increased scepticism toward phishing emails" (translated from German) (heise online, citing Meike Kamp, 2026-09-07).

incident30 Aug 04:35Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • heise.de7 (50%)
  • berliner-zeitung.de1 (7%)
  • borncity.com1 (7%)
  • bsi.bund.de1 (7%)
  • cisa.gov1 (7%)
  • rbb24.de1 (7%)
  • securityaffairs.com1 (7%)
  • tagesspiegel.de1 (7%)
All cited sources (14)