Berlin confirms second Rhysida data dump overnight
A 6 September 2026 Land Berlin press release says attackers published a further data package overnight, including access credentials. The Senate department for urban development, building and housing tightened controls that may briefly disrupt specialist procedures. Berlin has not published a full inventory of either dump.

The Presse- und Informationsamt des Landes Berlin issued a press release dated 6 September 2026 on a further attacker publication after the cyberattack on Landesnetz Berlin. Overnight Saturday into Sunday, 6 September 2026, the attackers published another data package.
This is an official Land Berlin press release. It is not a BSI technical advisory, not a court indictment, and not a complete public inventory of what was stolen.
The new package includes access credentials (Zugangsdaten) among other material. That is the line most first-dump headlines skipped. On Sunday the Senatsverwaltung für Stadtentwicklung, Bauen und Wohnen reviewed the measures already taken after the first publication and tightened some of them. Those extra controls may cause short-term restrictions on specialist procedures (Fachverfahren), and users are being informed.
The first publication was around 4 September, after Berlin refused to pay. BleepingComputer (Bill Toulas) reported that Rhysida claimed about 5.79 TB, or about 1.44 million files, from the administrative network, and that Mayor Kai Wegner said the city would not pay. Secondary coverage put the auction floor around 30 bitcoin. Those size and ransom figures remain the attackers' claims, and Berlin has not confirmed them.
Berlin has not published a complete public inventory of either dump. Treat 5.79 TB as Rhysida's claim unless the Land later measures it.
A second dump that includes credentials is the same class of public-sector incident as the Aesto Health notice covering 9.5 million records, the Thomson Reuters C-Track court-records breach, and the Manchester Airports Group 8.7 million customer-data incident. It is not the same instrument as a vendor CVE with a CISA KEV due date.
If you hold accounts, VPN tokens, or vendor logins that touch Berlin housing, building, or urban-development systems, rotate those credentials today, expect Fachverfahren downtime this week, and do not treat the 5.79 TB figure as a confirmed inventory.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free