A German federal- and state-funded memorial foundation is rebuilding its entire IT from scratch after ransomware — all seven sites offline, data assumed exfiltrated, no actor named
The Stiftung Brandenburgische Gedenkstätten — a public-law foundation funded by the Brandenburg state ministry for science and culture and by the federal government's commissioner for culture and media, operating seven memorial sites including the former Sachsenhausen and Ravensbrück concentration camps — published press release Nr. 42/2026 on 2026-08-11 stating that it "ist Opfer eines sogenannten Ransomware-Angriffs geworden" ("has become the victim of a so-called ransomware attack") (Stiftung Brandenburgische Gedenkstätten, 2026-08-11). The attack was detected on 5 August; attackers reached the internal IT systems, encrypted parts of the systems and data with dedicated software, and left a ransom note demanding payment for decryption. The foundation states that "Nach aktuellem Stand muss davon ausgegangen werden, dass Daten von den Angreifern heruntergeladen wurden" — on current assessment it must be assumed that data was downloaded by the attackers before encryption. Its director describes the entire IT system as currently non-functional. heise online corroborates the disclosure independently (heise online, 2026-08-11).
All seven memorial-site locations and the central business office are affected. The foundation's IT department disconnected every internet and network connection immediately, and the foundation reported the incident to the Zentrale Ansprechstelle Cybercrime at the Brandenburg state police and filed a breach notification with the Brandenburg data-protection authority within the statutory window. Physical visits to the memorials continue; booking delays for educational programmes are expected. No source names a threat actor or ransomware family, no leak-site listing had surfaced as of this run, and neither the foundation nor heise states how the attackers got in.
The transferable part is the recovery decision, not the victim. The foundation is rebuilding its IT systems from scratch rather than restoring from backups, explicitly to deny the attacker a route back in, and is doing so with an external incident-response provider recommended by the BSI (Stiftung Brandenburgische Gedenkstätten, 2026-08-11). The foundation expects the systems to be available again in a few days ("in einigen Tagen"), with delays to educational-programme bookings until then. For a small public body the rebuild is still the more expensive of the two options — it trades a longer outage for the certainty that restored infrastructure is not carrying the intruder's persistence — and it is the correct default when data theft is assumed and the dwell time is unknown, because a backup taken during an undetected intrusion restores the foothold along with the files.
Triage: with no actor, family or vector disclosed, there is nothing here to match an alert against — the entry is a sector-pattern and recovery-posture record, and any attempt to bind it to a specific intrusion set would be invention.
Die Stiftung Brandenburgische Gedenkstätten ist Opfer eines sogenannten Ransomware-Angriffs geworden.
Nach aktuellem Stand muss davon ausgegangen werden, dass Daten von den Angreifern heruntergeladen wurden.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Impact TA0040
T1486Data Encrypted for Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.