Rhysida and Akira Ransomware Claims Put Berlin and Alumax Under Fresh Cyber Threat Pressure + Video

Listen to this Post

Featured ImageA New Wave of Ransomware Claims Raises Concern

Ransomware attacks rarely arrive as a single isolated event. Behind each victim listing is the possibility of stolen information, disrupted operations, prolonged recovery, and a second wave of extortion if attackers decide to publish what they allegedly obtained.

On August 28, 2026, two separate ransomware claims drew attention from threat-intelligence monitoring: Rhysida reportedly added Berlin, Germany, to its victim list, while Akira reportedly claimed Alumax. The activity was highlighted by the ThreatMon Threat Intelligence Team as part of its monitoring of dark-web ransomware activity.

The reports should be treated as claims rather than independently confirmed breaches. A ransomware group’s appearance of a victim on a leak site or an intelligence feed can indicate a real intrusion, but it does not by itself establish exactly what systems were compromised, what data was stolen, whether encryption occurred, or whether the attacker actually obtained everything claimed.

At the same time, the Berlin development deserves particular attention because German media reported on August 28 that the Berlin state government was facing a ransom demand following a cyberattack against its state network. Berlin’s governing mayor, Kai Wegner, confirmed that an extortion demand had been received, although officials had not publicly confirmed the amount or the full scope of allegedly stolen information.

tagesschau.de

+1

Berlin Appears in a Rhysida Ransomware Claim

According to the supplied ThreatMon alert, the Rhysida ransomware group reportedly added Berlin, Germany, as a victim on August 28, 2026.

The alert does not, by itself, establish which Berlin organization or government department was affected. The wording identifies the victim simply as “Berlin, Germany,” meaning readers should avoid automatically interpreting the listing as proof that every Berlin government system or institution was compromised.

However, the timing is notable.

German reporting published on the same day confirmed that the Land Berlin had been targeted in a cyberattack and was facing a ransom demand. Tagesschau reported that data had been flowing out of the Berlin state network since at least August 7, while officials confirmed the existence of a ransom demand.

tagesschau.de

The Timing Makes the Rhysida Claim More Significant

The coincidence between the threat-intelligence listing and confirmed reports of an ongoing Berlin cyber incident makes the claim particularly important to monitor.

It still does not prove that Rhysida was responsible.

A responsible security assessment has to distinguish between three separate facts: a cyberattack against Berlin was publicly reported, a ransom demand was confirmed, and a threat-intelligence service separately associated Berlin with Rhysida.

Those facts may ultimately prove to describe the same incident, but public information available at the time of writing does not establish that connection conclusively.

Berlin’s Data Exposure Could Be the Bigger Risk

The most serious consequence of a government network intrusion may not be the disruption itself.

If attackers successfully extracted information from government systems, the stolen material could potentially include administrative records, internal correspondence, documents, employee information, citizen-related information, or other sensitive material depending on the systems involved.

Tagesschau reported that the amount of data involved had not yet been publicly established. Another report cited an alleged figure of nearly six terabytes and a ransom demand denominated in Bitcoin, but those details should be treated cautiously until independently confirmed by authorities.

tagesschau.de

+1

Rhysida Has a Documented History of Extortion

The Rhysida threat is not new.

CISA, the FBI and MS-ISAC previously published a joint advisory describing Rhysida as an emerging ransomware operation that had targeted sectors including education, healthcare, manufacturing, information technology and government. The advisory recommends measures such as prioritizing known exploited vulnerabilities, enabling multifactor authentication and segmenting networks to limit ransomware propagation.

CISA

More recent threat research has continued to track Rhysida’s ecosystem and associated tooling. IBM X-Force reported in June 2026 that its research identified recurring malware and infrastructure relationships around Rhysida operations, including downloaders and backdoors used by actors associated with the group.

IBM

Akira Reportedly Adds Alumax

The second alert concerns Akira ransomware and Alumax.

According to the supplied ThreatMon report, Akira added Alumax to its victim list on August 28, 2026. As with the Rhysida report, this should currently be described as a ransomware claim, not as a fully independently verified breach.

No detailed information was provided in the original alert about the systems allegedly accessed, the quantity of stolen data, the initial access method, the ransom demand, or the operational impact on Alumax.

Those missing details matter.

A victim listing can represent anything from an early-stage extortion claim to a confirmed intrusion involving extensive data theft and encryption. Until the victim, investigators, or multiple independent intelligence sources confirm the incident, the precise impact remains uncertain.

Akira Remains a Serious Ransomware Threat

Akira has an established record of ransomware activity.

MITRE ATT&CK describes Akira as an active ransomware entity since at least March 2023. Its documented activity includes using compromised credentials for initial access through externally exposed mechanisms such as VPNs, followed by lateral movement using publicly available tools and techniques. MITRE also associates Akira operations with double-extortion activity in which attackers steal data before encryption and threaten publication if a ransom is not paid.

attack.mitre.org

CISA has also published a dedicated StopRansomware: Akira Ransomware advisory, underscoring that the threat has been significant enough to warrant federal guidance for defenders.

CISA

Why Alumax Matters From a Manufacturing Perspective

The Alumax claim is especially interesting because manufacturing remains an important ransomware target.

Manufacturers often operate a mixture of corporate IT networks, production environments, remote-access systems, engineering workstations, file servers and third-party connections. Even when production systems are not directly encrypted, an intrusion into surrounding infrastructure can create enough disruption to force operations to slow down or stop.

For ransomware operators, that operational pressure creates leverage.

The more expensive downtime becomes, the greater the potential incentive for a victim to negotiate, even when an organization has no intention of paying an attacker.

The Double-Extortion Model Changes the Equation

Modern ransomware is no longer simply about locking files.

Attackers increasingly combine encryption with data theft. This creates two separate sources of pressure: operational disruption and the threat of public disclosure.

Akira’s documented behavior reflects this model, with data exfiltration occurring before encryption and threats to publish stolen information when ransom demands are not met.

attack.mitre.org

Rhysida has similarly been associated with data-extortion tactics, making the alleged Berlin incident potentially more serious than a conventional malware outbreak if data theft is confirmed.

The Dark Web Is Not Automatically Proof

One of the most important lessons from these reports is the difference between threat intelligence and verified incident reporting.

A ransomware group can make a claim before an investigation is complete. A victim can appear on a leak site without immediately providing evidence that the attacker accessed the systems they claim to have compromised.

Security researchers therefore tend to compare multiple signals: leak-site activity, victim statements, forensic evidence, network telemetry, samples of allegedly stolen information, timestamps, infrastructure indicators and independent reporting.

This distinction is essential when reporting ransomware events because incorrectly presenting an allegation as a confirmed breach can create unnecessary reputational damage.

Berlin’s Confirmed Incident Gives the Claim Extra Weight

Although the Rhysida attribution remains unconfirmed in the available public reporting, the Berlin situation is not merely a rumor.

Berlin authorities confirmed that the government had received a ransom demand following a cyberattack against its network. Officials also said that Berlin would not allow itself to be blackmailed.

tagesschau.de

That means investigators now have a concrete incident to analyze.

The unanswered question is whether the Rhysida listing corresponds to that attack.

The Investigation Could Reveal More Than the Ransom Demand

A forensic investigation into the Berlin incident will likely focus on how attackers gained access, how long they remained inside the network, what accounts or privileges they obtained, whether lateral movement occurred, and whether information was exfiltrated.

Investigators will also need to determine whether the attackers encrypted systems or relied primarily on data theft and extortion.

These details can transform the understanding of an incident from a relatively contained intrusion into a major data-security event.

Ransomware Groups Benefit From Uncertainty

There is also a psychological component to ransomware.

Attackers do not necessarily need to prove everything immediately. A credible threat to publish sensitive information can itself create pressure.

Organizations must therefore investigate rapidly while simultaneously communicating with employees, customers, regulators and other stakeholders.

This is one reason ransomware response plans increasingly focus on preparation before an incident rather than improvisation during one.

What Organizations Can Learn From These Claims

The Berlin and Alumax reports demonstrate why organizations should assume that ransomware campaigns can move between sectors and geographic regions with little warning.

CISA’s ransomware guidance recommends preventative measures including vulnerability management, multifactor authentication, network segmentation, backups and structured incident-response planning.

CISA

These measures do not guarantee immunity.

They do, however, make it harder for attackers to turn a single compromised account or vulnerable system into organization-wide operational control.

Deep Analysis: Commands for Defenders

Command 1 — Verify Before You Escalate

Security teams should first establish whether the alleged victim listing corresponds to an actual incident.

Correlate the reported timestamp with authentication logs, endpoint alerts, firewall events, VPN activity, identity-provider records and unusual outbound traffic.

Command 2 — Hunt for Abnormal Authentication

Investigate unexpected successful logins, impossible-travel events, new administrative sessions, unfamiliar VPN sources and authentication attempts involving dormant accounts.

Compromised credentials remain an important ransomware access route, making identity monitoring particularly valuable.

Command 3 — Inspect Remote Access

Review externally accessible VPN, RDP, remote-management and administrative services.

Any unusual authentication activity should be investigated rather than dismissed as background internet noise.

Command 4 — Search for Lateral Movement

Once an endpoint is suspected, examine connections to file servers, domain controllers, backup infrastructure and other high-value systems.

The objective is to determine whether the attacker remained isolated or successfully expanded access.

Command 5 — Protect Backups

Backups should be treated as high-value targets.

Organizations should verify that backup systems cannot be easily reached using ordinary compromised credentials and that recovery procedures have been tested before an emergency occurs.

Command 6 — Watch for Data Exfiltration

Large or unusual outbound transfers can provide an important clue in suspected double-extortion incidents.

Security teams should investigate unexpected transfers involving archives, compressed files, cloud-storage services and unfamiliar external destinations.

Command 7 — Preserve Evidence

Do not immediately destroy compromised systems or erase suspicious accounts without considering forensic requirements.

Preserving logs, memory captures where appropriate, endpoint telemetry and relevant network records can help determine the attack path and support recovery.

Command 8 — Segment Critical Systems

Network segmentation can prevent an attacker who compromises one workstation from reaching every other system.

This is particularly important for government networks and manufacturing environments where IT and operational systems may have very different security requirements.

Command 9 — Enforce Multifactor Authentication

MFA should be enabled wherever practical, especially for VPN, administrative and externally accessible services.

CISA specifically recommends MFA as part of its ransomware mitigation guidance.

CISA

Command 10 — Prepare for Extortion

Organizations should plan for the possibility that stolen information will be used as leverage.

Incident-response plans should therefore include legal, communications, executive, technical and regulatory procedures rather than focusing exclusively on restoring encrypted systems.

What Undercode Say:

Two Claims, One Important Warning

The simultaneous appearance of Rhysida and Akira in fresh victim claims illustrates how ransomware remains a persistent threat even as individual groups change tactics, infrastructure and victim-selection strategies.

Berlin Is the More Significant Development

The Berlin claim deserves particular attention because public authorities independently confirmed that the city’s government network had suffered a cyberattack and received a ransom demand on the same day the Rhysida listing appeared.

Attribution Still Requires Evidence

However, timing alone does not prove attribution.

Until Berlin authorities or credible independent investigators confirm that Rhysida conducted the attack, the responsible wording is that Rhysida claimed or was reported to have listed Berlin as a victim.

Ransomware Claims Can Move Faster Than Investigations

Threat actors can publish allegations within hours, while legitimate forensic investigations may take days or weeks.

That creates an information gap in which sensational claims can spread faster than verified evidence.

Berlin Could Become a Major Case Study

If the Rhysida attribution is eventually confirmed, the Berlin incident could become another important example of ransomware targeting government infrastructure.

The combination of public-sector data, operational disruption and extortion creates exactly the kind of pressure ransomware groups seek.

Alumax Highlights the Industrial Risk

The Akira-Alumax claim reinforces another trend: manufacturing remains an attractive ransomware target.

Production downtime can quickly translate into financial losses, delayed deliveries, contractual problems and supply-chain disruption.

Akira’s Double-Extortion Strategy Raises Stakes

Because Akira is documented as using data theft alongside encryption, organizations facing an Akira intrusion have to consider both availability and confidentiality.

Restoring backups alone may not eliminate the threat.

Stolen Data Can Become a Second Attack

Even after systems are restored, leaked documents can create lasting consequences.

Sensitive information can trigger privacy concerns, regulatory obligations, fraud risks, competitive exposure and reputational damage.

The Real Battlefield Is Identity

Modern ransomware defenses increasingly depend on controlling identity.

A strong perimeter means little if an attacker can obtain a privileged account and move through trusted systems.

VPN Security Remains Critical

Akira’s documented use of compromised credentials against external access mechanisms demonstrates why remote-access infrastructure deserves continuous monitoring.

Old VPN accounts, weak passwords and insufficient MFA can become dangerous entry points.

Government Networks Need Defense in Depth

The Berlin incident also demonstrates why government cybersecurity cannot depend on one defensive layer.

Email security, endpoint protection, identity controls, network segmentation, logging, backups and incident response all have to work together.

Detection Speed Can Change the Outcome

A ransomware intrusion discovered within minutes is fundamentally different from one discovered after attackers have spent weeks inside a network.

Early detection can limit lateral movement and reduce the amount of information available for extortion.

Data Classification Is Increasingly Important

Organizations should know which information is truly sensitive before an incident happens.

Without effective data classification, defenders may struggle to determine which stolen files represent the greatest risk.

Backups Are Necessary but Not Sufficient

A clean backup can restore availability, but it cannot necessarily prevent attackers from publishing stolen data.

Organizations therefore need both recovery capabilities and data-loss prevention strategies.

Threat Intelligence Has Strategic Value

Threat-intelligence monitoring can provide early warning when an organization appears on a ransomware leak site.

But intelligence should trigger investigation, not automatically be treated as conclusive forensic evidence.

Leak-Site Claims Need Correlation

Security teams should compare ransomware claims against internal telemetry and external reporting.

The strongest conclusions come from multiple independent signals pointing toward the same event.

Public Attribution Should Be Conservative

Calling an organization “hacked by” a particular group without adequate evidence can be misleading.

The more responsible approach is to distinguish between an allegation, a suspected incident and a confirmed attribution.

Ransomware Has Become an Extortion Business

The modern ransomware economy increasingly resembles a professional criminal service industry.

Initial-access brokers, malware developers, affiliates, negotiators and data-extortion operators can all contribute to a single intrusion.

The Ecosystem Is More Important Than One Group

Focusing exclusively on Rhysida or Akira can obscure the larger problem.

The same vulnerabilities, stolen credentials and defensive weaknesses can potentially be exploited by completely different ransomware operators.

Manufacturing Should Assume Targeting

Industrial companies should not assume that ransomware groups are primarily interested in hospitals or governments.

Manufacturing downtime can provide attackers with substantial negotiating leverage.

Government Agencies Are Attractive Targets

Government organizations hold large volumes of sensitive information and often operate complex legacy environments.

That combination can make them valuable targets for extortion campaigns.

Public Confirmation Matters

The Berlin case shows why independent confirmation remains essential.

Officials have acknowledged the cyberattack and ransom demand, but the exact attacker attribution and full extent of the data exposure remain important unanswered questions.

tagesschau.de

The Next Phase Could Involve Data Publication

If negotiations fail, ransomware groups may escalate by publishing samples or larger portions of allegedly stolen information.

That would provide additional evidence but could also increase the damage to affected organizations.

Threat Actors Can Use Publicity as Leverage

A public victim listing itself can create pressure.

Organizations may face questions from employees, customers, regulators, investors and partners before technical investigators have completed their work.

Security Teams Need an Evidence-First Approach

The best response is neither panic nor complacency.

Organizations should treat credible claims seriously enough to investigate while avoiding assumptions that have not yet been supported by forensic evidence.

Ransomware Resilience Starts Before the Attack

Incident response becomes dramatically easier when organizations already know who has authority to isolate systems, communicate externally, preserve evidence and restore critical services.

Preparation is therefore one of the strongest defenses against extortion.

The Berlin Case Deserves Continued Monitoring

Because a confirmed ransom demand already exists, developments surrounding Berlin should be watched closely.

Any future statement from authorities identifying the threat actor, confirming data theft or describing the affected systems could substantially change the assessment.

Alumax Also Requires Verification

The Alumax claim should similarly be monitored for confirmation from the company, security researchers or additional independent intelligence sources.

Until then, it remains a reported ransomware claim rather than a conclusively verified breach.

The Broader Lesson Is Clear

The latest reports show that ransomware continues to combine technical intrusion with psychological pressure.

Attackers do not simply attempt to break systems; they attempt to create situations where organizations feel they have no painless option.

Defensive Priorities Are Straightforward

Patch exposed systems, secure remote access, enforce MFA, segment networks, monitor privileged accounts, protect backups and continuously investigate unusual data movement.

These measures remain among the most practical ways to reduce ransomware impact.

The Most Dangerous Assumption Is “It Can’t Happen Here”

Berlin is a major European government center.

Alumax represents an industrial target.

The two claims illustrate the breadth of the ransomware ecosystem: public-sector infrastructure and manufacturing can both attract criminal attention.

Ransomware Will Continue to Evolve

Groups disappear, rebrand, split into affiliates and adopt new infrastructure.

The names change faster than the underlying vulnerabilities.

Resilience Is the Long-Term Strategy

Organizations cannot guarantee that they will never be attacked.

They can, however, make attacks harder to execute, easier to detect and less destructive when they occur.

Evidence Assessment

❌ Rhysida's responsibility for the Berlin cyberattack is not independently confirmed in the available public reporting. Berlin authorities confirmed a cyberattack and ransom demand, while the separate ThreatMon alert associated Berlin with Rhysida; the two events may be connected, but attribution remains unproven. 
tagesschau.de
+1

✅ Berlin was publicly confirmed to be facing a ransom demand following a cyberattack. Berlin’s governing mayor confirmed the extortion attempt on August 28, 2026, although the precise amount and full data impact were not publicly established.

tagesschau.de

✅ Rhysida and Akira are established ransomware threats. CISA has published dedicated guidance on both threats, while MITRE documents Akira’s ransomware and double-extortion activity.

CISA

+2

CISA

+2

Prediction

(-1) More Extortion Pressure Is Likely

The immediate outlook remains negative because ransomware groups continue to combine data theft, operational disruption and public pressure. If the Berlin incident is confirmed as a Rhysida operation, the group could use the case to increase publicity and extortion leverage.

(-1) Additional Data Claims Could Follow

If attackers obtained substantial information from Berlin or Alumax, further leak-site activity could appear in the coming days or weeks. Such activity would not automatically prove every claim, but samples of authentic stolen information could provide stronger evidence of compromise.

(+1) Defensive Response Can Limit the Damage

Organizations that rapidly isolate compromised systems, disable exposed credentials, preserve evidence, protect backups and investigate data exfiltration can significantly reduce the consequences of ransomware.

(+1) Verification Will Improve the Picture

As forensic investigations progress, official statements and independent threat intelligence should make it clearer whether the Berlin incident was actually conducted by Rhysida and whether the Alumax claim represents a confirmed compromise.

(-1) Ransomware Targeting Will Remain Broad

The larger trend is unlikely to disappear. Government agencies, manufacturers, healthcare organizations, technology companies and professional services firms all remain potential targets because attackers can monetize both operational disruption and stolen information.

(+1) Prepared Organizations Have Better Odds

The strongest long-term defense is resilience: strong identity controls, MFA, segmentation, vulnerability management, continuous monitoring, tested backups and a rehearsed incident-response plan. Those controls cannot eliminate ransomware, but they can turn a potentially catastrophic intrusion into a far more manageable security incident.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube