Berlin Spent Seven Days Plugged Into Its Attackers
Everyone is covering the 5.79TB dump and the election optics. The story that matters is simpler and worse: Berlin detected the breach on August 7 and left Rhysida connected to water-supply and emergency-services infrastructure until August 14. That gap is the failure. The data is the receipt.

TITLE: Berlin Spent Seven Days Plugged Into Its Attackers BODY:
Berlin's Governing Mayor held an emergency Senate session and told reporters the city would not pay. Kai Wegner said the state was being blackmailed. Correct decision. Almost entirely beside the point.
The point is August 7 to August 14.
The Gap Is the Story
Exfiltration was underway from at least August 7, 2026. The affected departments were not disconnected from the Landesnetz—Berlin's backbone linking roughly 600 government, police, fire, and hospital sites—until August 14. Seven days after detecting suspicious data movement, Berlin left Rhysida connected to that backbone.
Translation: Berlin's statement frames this as a response to extortion. The operational record shows Berlin detected the breach and kept the attacker online for a week.
The seven-day gap reflects a structural feature of large interconnected networks: isolating a compromised segment requires either automatic segmentation or manual authorization. One of those was missing. This is not a Russia problem or a ransomware problem. This is a procedures problem.
What moved during those seven days matters. More than 5,000 personnel files, health records, plaintext credentials, passports, ID documents, Bundestag protocols, and KRITIS-relevant material including vulnerability analyses of Berlin's water supply. Hold the water-supply analyses. No service disruption has been reported. The concern is that stolen vulnerability analyses could inform future targeting rather than indicate active disruption. That distinction may matter less in eighteen months when someone reads those files with different intentions.

What the Dwell Time Benchmarks Say
According to Sophos's 2025 Active Adversary Report, median ransomware dwell time stands at four days. Berlin's detection-to-isolation gap ran to seven while the operator knew the attacker was inside.
The industry has compressed dwell time for three years. Berlin ran longer.
The ransom demand was 30 bitcoin, roughly 2 million euros. Berlin refused. Rhysida published everything anyway. The refusal was correct and it changed nothing. The attacker had already extracted maximum leverage during the seven-day window. Paying would have bought the same result: data was gone before the negotiation started.
If your detection-to-isolation gap is measured in days, the ransom negotiation is a formality. The attacker already won.
Rhysida is not novel. Most TTPs during this intrusion are typical for ransomware. Standard playbook, standard credentials abuse, standard lateral movement. Berlin was not outmaneuvered by a sophisticated adversary. It was held by a competent one for seven days because isolation procedures did not move fast enough.
What You Should Actually Do With This
The election timing generates political heat. Interior Senator Iris Spranger confirmed election systems are secure and isolated from the compromised network. Put the optics down.
The question for every operator running municipal water, power, emergency dispatch, or hospital networks in Europe is this: assume your SOC fires an alert Monday morning. When does the network actually go dark on the compromised segment? If the honest answer is "we escalate to leadership and wait for authorization," your isolation time is probably measured in days, not hours.
That is Berlin's problem stated as your problem.
The pattern points to a manual-approval bottleneck or an interdependency so complex that no one had pre-authorized isolation playbooks for a backbone segment shared by 600 sites. Either is fixable. Neither gets fixed after the dump drops.
What to watch: Whether Berlin's post-incident review details the decision chain that produced the seven-day gap—approval process, technical dependency mapping, or both. Whether German federal regulators mandate pre-authorized isolation thresholds for KRITIS-connected networks. Whether the water-supply vulnerability analyses are specific enough to constitute actionable targeting intelligence, which forensic teams reviewing the published data are best positioned to assess first.
- Berlin Ransomware: 7-Day Isolation Gap Aided Rhysida
- Berlin's Seven-Day Ransomware Isolation Gap Let Rhysida Steal Critical Infrastructure Data
- Berlin Confirms Data Theft After Rhysida Ransomware Attack
- Rhysida Ransomware: Attack Methods, IOCs and Defence 2026
- Rhysida Leaks 5.8 TB of Berlin Government Data After €2M Ransom Refusal
- Berlin refuses to be blackmailed after network breach
- Berlin Ransomware: 7-Day Gap Cost 5.79TB
- Berlin Confirms Data Theft in Rhysida Ransomware Attack
- 2026 Berlin State Election
- Rhysida Ransomware Group Claims 5.79 TB Data Theft from Berlin Government - General Chat - Malwarebytes Forums
- Rhysida Claims Berlin Hack: 5.79 TB, 30 BTC Demand [2026]
- Berlin Government Allegedly Hit by Rhysida Ransomware - ThreatMon
- Berlin Confirms Data Theft After Rhysida Ransomware Attack
- Same threats, different ransomware | SOPHOS
- Analyzing Rhysida Ransomware Intrusion Introduction
- Rhysida Ransomware: History, TTPs and Adversary Emulation Plans
- Berliners to elect state parliament on September 20, 2026 – Berlin.de
- Elections in Germany - VoteSwiper
- 20 SEPTEMBER 2026 Elections to the Berlin House of Representatives
- 2023 Berlin state election
- Berlin House of Representatives
- Next elections in Germany
- 2021 Berlin state election
- Berlin Rejects Rhysida Ransomware Blackmail - BankInfoSecurity
- Rhysida Ransomware Attacks Berlin City Government – HackMag
- Berlin Rejects Rhysida Ransomware Blackmail – blog.aimactgrow.com