6 September 2026
Executive Summary
Berlin’s state government has launched an intensified crisis response after a ransomware group published stolen government data following a major cyberattack against parts of the city’s administration.
The incident affected two government departments.
The Rhysida ransomware group previously claimed responsibility for stealing a substantial volume of data and attempted to extort the authorities.
Berlin refused to pay.
The stolen material has now been published, and officials are reviewing the data to establish the scale of exposure and potential consequences.
Earlier claims from the attackers included files containing contracts, emails, telephone numbers, passwords and potentially sensitive government information.
Those claims remain subject to official verification.
What is confirmed is that the breach has moved from attempted extortion to actual data publication.
That distinction materially changes the risk.
Once information has been released publicly or distributed through criminal networks, restoring systems does not restore confidentiality.
UK Impact
The incident has direct relevance to UK organisations holding:
- Personal information.
- Commercial contracts.
- Government data.
- Financial records.
- Employee information.
- Supplier information.
- Credentials.
- Sensitive correspondence.
Organisations often focus ransomware planning on whether they can restore systems from backup.
That is only one part of the exposure.
Modern ransomware groups increasingly use double extortion:
- Encrypt or disrupt systems.
- Steal information and threaten publication.
A company can successfully restore operations and still face:
- Regulatory notification.
- Privacy claims.
- Litigation.
- Contractual liability.
- Reputation damage.
- Identity fraud.
- Credential compromise.
- Supplier disputes.
Global Impact
Government and corporate organisations increasingly hold data across interconnected environments.
A breach may involve:
- Internal servers.
- Cloud infrastructure.
- Contractors.
- Managed-service providers.
- Document repositories.
- Email systems.
- Backup platforms.
That creates a difficult containment problem.
Changing passwords and rebuilding systems may stop the attacker accessing new information.
It does not retrieve information already stolen.
Organisations therefore need two parallel response plans:
system recovery and information-loss management.
The latter is often less developed.
Our View
Boards should test ransomware resilience against data publication rather than system encryption alone.
Businesses should ask:
- What data would cause the greatest harm if published?
- Where is it stored?
- Is sensitive data segmented?
- Are credentials stored within documents?
- Are old records retained unnecessarily?
- Are backups isolated?
- Can privileged accounts be rapidly disabled?
- Are third-party systems included in incident response?
- Who decides whether regulators must be notified?
- How quickly can affected customers be contacted?
- Are cyber insurers notified immediately?
- Are forensic-response providers pre-appointed?
- Does cyber cover include privacy liability?
- Does it include extortion response?
- Does it cover data restoration?
- Does it cover business interruption?
- Has management rehearsed a public data-leak scenario?
The critical assumption to challenge is:
“If we restore the systems, the incident is over.”
Once sensitive information has been stolen, the cyber incident can continue long after normal operations resume.
Risk Indicator: HIGH – RANSOMWARE, DATA & CYBER LIABILITY
Does This Risk Affect Your Business?
Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.
From individual businesses to major international organisations, risk is our business.
TALK TO INVICTUS →Disclaimer
The information contained within these Market Alerts is provided for general market awareness and informational purposes only. It does not constitute financial, legal, investment, regulatory or insurance advice. Whilst every effort has been made to ensure accuracy at the time of publication using multiple reputable and independently verified sources, geopolitical events, legislation, regulation and market conditions may change rapidly. Readers should obtain appropriate professional advice before acting upon any information contained herein.
Invictus Risk Solutions LLP – Helping organisations stay ahead of emerging risks through informed insight and independent analysis.
