// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / Berlin government
Breach Record

Berlin government

DISCLOSED 2026-09-12 · RANSOMWARE · 1,400,000 RECORDS EXPOSED · RANSOMWARE

The Rhysida ransomware group published nearly 1.4 million files stolen from Berlin after a €2 million ransom demand was not paid. The exposed data includes personal and sensitive government information. The attack targeted the Berlin government.

The record

What we know

Disclosed
2026-09-12
Attack vector
Ransomware
Sector
government
Country
Germany
Records exposed
1,400,000
Data classes exposed
personalsensitive government data
RANSOMWARE
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

The text does not specify how the attackers gained access, so it is unclear whether a positive-security model would have prevented the breach.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other ransomware breaches on file

This page is the permanent ColdRecon entry for the Berlin government disclosure. It updates if new public reporting emerges. All tracked breaches →

Berlin government just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →