Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
20MAY

Rhysida names Stuttgart on leak site

3 min read
09:58UTC

Rhysida named Landeshauptstadt Stuttgart on its leak site on Tuesday 19 May with a double-extortion data-dump threat. Stuttgart is the state capital of Baden-Wuerttemberg and home to the corporate headquarters of Porsche and Mercedes-Benz.

TechnologyDeveloping
Key takeaway

Stuttgart's ransomware exposure touches the supplier records of Porsche and Mercedes-Benz alongside city services.

Rhysida, the ransomware-as-a-service crew active since 2023, named Landeshauptstadt Stuttgart on its leak site on Tuesday 19 May 2026 with a double-extortion data-dump threat 1. Landeshauptstadt is the official designation for Stuttgart as the state capital of Baden-Wuerttemberg, the German federal state that sits at the centre of the country's automotive industry. No German federal authority had issued a public response at the time of writing. Rhysida succeeds the Vice Society crew in the same operator lineage and has been active against European municipal targets continuously since 2023.

Stuttgart hosts the corporate headquarters of Porsche and Mercedes-Benz. A city-government breach exposes payroll, planning, permits, and supplier records that touch both companies' day-to-day operations, even without direct access to either OEM's own networks. Rhysida's standard tactic, double-extortion through encrypted exfiltration followed by leak-site publication, is the same pattern it has used against the British Library, Insomniac Games, and a string of European hospitals and councils.

Berlin published its NIS2 implementation law on 5 December 2025 with a 6 March 2026 registration deadline , but only around one-third of covered entities had registered by the cut-off, and the European Commission's parallel infringement proceedings against partial-transposition member states cover Germany. A municipal breach disclosed within the new statutory framework would be the first significant German test of the post-NIS2 incident-handling track. For automotive supplier risk Teams, the question is whether Stuttgart's vendor records form part of the exfiltrated set and how quickly the city will publish a scope.

Deep Analysis

In plain English

Rhysida is a ransomware gang that has been attacking public institutions across Europe since 2023, including the British Library. On 19 May 2026, it threatened to publish data stolen from Stuttgart's city government unless paid. Stuttgart is the state capital of Baden-Wuerttemberg and where Porsche and Mercedes-Benz are headquartered.

Deep Analysis
Root Causes

German municipal IT governance operates under a decentralised model in which federal states set minimum standards but municipalities have significant autonomy over security investment. Baden-Wuerttemberg's NIS2 implementation guidance post-December 2025 applies to essential service operators in the state; whether Stuttgart's administrative functions fall within NIS2 scope or outside it determines which enforcement framework applies.

Rhysida's operational pattern targets institutions with high public visibility because the reputational pressure on public bodies to restore services creates negotiation urgency that private-sector targets do not experience in the same way. Stuttgart's status as a state capital and home of two global automotive brands amplifies both the data reach and the negotiation pressure.

First Reported In

Update #4 · AI joins the breach column on both sides

DeXpose· 20 May 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.