Europe
Ransomware Remains a Data-Theft Investigation
On 28 August, the Rhysida ransomware group posted a leak-site entry titled “Berlin, Germany”, claiming 5.79TB of data across roughly 1.44 million files, including approximately 46,500 contracts, emails, phone numbers, credential files and material described as classified. The group opened bidding at 30 bitcoin with a one-week countdown. Berlin’s Governing Mayor stated publicly that the city would not pay.
On 31 August, Berlin officials confirmed that data theft had been forensically verified, with a confirmed exfiltration window of 7–12 August inside the Senate Department for Mobility, Transport, Climate Protection and Environment, one of the departments disconnected from the Landesnetz, the state backbone network.
The operationally significant number is not 5.79TB. It is the gap. Reporting indicates suspicious data movement was first detected around 7 August, and that affected departments were not disconnected from the Landesnetz until 14 August. Berlin’s State Secretary for Digital Affairs is reported as saying data had been leaving for roughly a week before the intrusion was discovered.
There is a second gap worth noting, and it is the one that logging directly addresses. Berlin has validated exfiltration from one Senate portfolio during a five-day window. It has not validated Rhysida’s headline 5.79TB figure, nor the claim regarding personal data belonging to 12,076 individuals.
When an organisation cannot independently reconstruct what left the environment, the attacker’s claim becomes the working assumption, for the media, for the regulator, and for every affected citizen.
The incident reinforces the evolution we covered in Issue 13. Ransomware is not an encryption investigation. It is an investigation into:
Access → Privilege → Movement → Collection → Exfiltration → Disruption.