Bremen, September 9, 2026 – Between August 7 and 12, 2026, attackers from the Rhysida ransomware group secretly copied data from two Berlin Senate administrative departments before the attack on the BeLa state network was discovered on August 14. After the State of Berlin refused to pay the demanded ransom of approximately 2 million euros, Rhysida published the entire dataset—5.79 terabytes, 1.44 million files—on the dark web on September 4. The data includes personal information on more than 12,000 people as well as emergency plans for critical infrastructure. For the IT security consultancy team neusta and the crisis communications specialists at NetFed, this case exemplifies a risk to which companies of all sizes are exposed.
From team neusta’s perspective, the Berlin case exemplifies three technical lapses that are widespread far beyond the public sector: login credentials were stored in plain text within Office files, the data breach went undetected for several days, and inadequate network segmentation apparently allowed access to sensitive data belonging to another government agency. Crisis communication was similarly prone to errors: The first press release was issued only four days after the network was disconnected and remained vague with phrasing such as “investigative reasons”; an early reassurance from Governing Mayor Kai Wegner, stating that no sensitive data had been compromised, had to be corrected days later; and there was no central channel through which citizens and the media could obtain updates on the current situation. For citizens, this had tangible consequences: For over a week, approximately 50,000 households were unable to apply for housing assistance, and both administrative offices were at times only reachable by phone.
team neusta sees this as a problem that extends far beyond Berlin. Cyberattacks on German organizations are “long since an everyday occurrence, not an exception,” says Tascha Schnitzler, Business Development Public Sector at team neusta. “Nevertheless, we feel that this issue is still not being treated with the seriousness it deserves,” Schnitzler continues. This also affects public trust in government action: Voter turnout and the mood during the recent elections in Saxony-Anhalt showed just how fragile this trust already is, and incidents such as the hacker attack in Berlin, in Schnitzler’s assessment, do nothing to strengthen it. Digital sovereignty, resilience, and security are “not optional extras, but a foundation that we can only build together,” Schnitzler said; as neusta, the company aims to do its part to support public administrations, businesses, and citizens alike.
From an educational tool to a weapon of attack
According to team neusta, a particular danger in this case lies in the fact that a great deal of information—organizational charts, phone numbers, service provider contracts, login credentials, emergency procedures—which is harmless on its own, can, when taken as a whole, paint a detailed picture of an organization. An attacker would normally have to painstakingly piece together this intelligence through OSINT, scanning, phishing, and internal reconnaissance; a leaked internal document archive anticipates part of that process.
This has a particularly immediate impact on social engineering: A phishing email containing real names, real processes, and the actual service provider is significantly harder to detect than a generic mass email—a risk that is not limited to Berlin but affects every company that works with the affected agencies. Furthermore, should reports of documents related to total defense and civil-military cooperation in the published dataset be confirmed, security experts believe such material would also be of interest to state actors, for example, in preparing hybrid activities. However, as things stand today, it is not possible to make reliable statements about exactly which documents are included or how current they are.
For André Conin, Key Account AI at team neusta, the publication of the stolen data on the dark web marks a turning point in how such cases are assessed. The crucial question can no longer be whether every cyberattack can be prevented, but whether an organization is prepared if one occurs anyway: “Technical security, incident response, and crisis communication must be considered together today,” says Conin. “Systems can be restored, but lost trust is much harder to regain.” In the worst-case scenario, an organization loses not only data in a cyberattack, but also something that is even harder to restore: trust. At the very latest when stolen information is published on the dark web, an IT security incident turns into a crisis of trust. Cyber resilience therefore means not only protecting systems but also remaining capable of taking action in an emergency, communicating transparently, and maintaining trust, Conin explains.
Structures Instead of Secrets
Thorsten Greiten, CEO of team-neusta partner NetFed, sums up the difference between a traditional data breach and the Berlin case in a simple way: A password can be reset on Monday, but a water treatment plant cannot. Greiten emphasizes that the 1.44 million files that were published are “not a stack of files, but a dataset.” Taken individually, most documents are harmless, but taken together, they paint a picture of how an organization functions and where it is vulnerable. The crucial security barrier must therefore be in place before the data leak occurs and not only afterward, once the search engine has indexed it; likewise, the communication crisis does not begin when systems fail, but when data is published, according to Greiten. Requests to platforms to delete content or to search engines to delist results—which are frequently made after such incidents—do not restore confidentiality; they come too late to serve as the actual security barrier.
Five Building Blocks for Greater Resilience
team neusta and NetFed have been helping companies and government agencies prepare for IT security incidents for several years now. Based on their analysis of the Berlin case, the two companies have identified five key components that can be applied to companies of any size: a documented and rehearsed incident response plan that specifies who is notified when and who handles external communications; a pre-prepared, legally reviewed “darksite” with crisis communication templates that can be activated within minutes in the event of an emergency; regular, quarterly security audits and penetration tests instead of one-time, pro forma assessments; a backup strategy based on the 3-2-1 rule to remain operational in the event of encryption; and ongoing employee training with phishing simulations and a culture in which reporting a suspicion is not penalized.
Important to note: The communication crisis does not end with the restoration of systems, but often only begins when stolen data is published and affected parties, customers, regulators, and the media all reach out at the same time.
The goal is an organization that is technically secure and capable of communicating immediately in an emergency—rather than having to improvise for days on end when a crisis strikes.
Our IT Security Services
Your contacts




