
Berlin Leak: 1.4 Million Government Files on Dark Web
The ransomware group Rhysida published 1,439,893 files stolen from Berlin's state administration on the dark web on September 4, 2026, after the German capital refused to pay a ransom of 30 bitcoin — roughly €2 million. The dump totals about 5.8 terabytes and is among the most serious breaches of a German state government on record.
Key facts
What happened: Rhysida leaked 1,439,893 files (~5.8 TB) taken from Berlin's state administrative network
When: Attackers had access between August 7 and 12, 2026, according to reporting; the data was published September 4
The ransom: 30 bitcoin, about €2 million. Governing Mayor Kai Wegner refused, saying paying would not guarantee deletion
What's in it: Personnel records, payroll lists, bank details, scanned identity documents, and a folder on chemical, biological, radiological and nuclear threat planning
Status: Berlin launched a crisis response September 5 and hired CrowdStrike to examine its systems
What was stolen in the Berlin cyberattack?
The leak covers ordinary administrative records and sensitive government material in the same dump.
On the personal side, reporting describes payroll lists, bank details, scans of identity documents, birth certificates, home addresses and telephone numbers belonging to state civil servants. One account of Rhysida's leak-site posting cited personal information on 12,076 individuals.
On the government side, researchers identified material tied to water systems, power infrastructure, prisons, defense firms and staff records. The item drawing the most alarm is a folder labeled "AG CBRN-Rahmenplanung" — CBRN stands for chemical, biological, radiological and nuclear. That means planning documents about how Berlin would respond to those threat scenarios may now be publicly accessible, including to hostile intelligence services.
Why did Berlin refuse to pay the ransom?
Governing Mayor Kai Wegner said the State of Berlin would not give in to blackmail, and that paying would not have guaranteed the stolen information was deleted.
That reasoning is supported by evidence. Ransom payments buy a promise from criminals, not a deletion. In the PowerSchool breach in the United States, the company paid — and an actor tied to the attack kept a copy of the data anyway and used it to extort schools weeks later.
Rhysida ran an auction for the data with a starting price of 30 bitcoin. When the countdown expired on Friday, September 4 without payment, the group published everything.
Double extortion is when attackers steal a copy of the data before encrypting systems, so they can threaten publication even if the victim restores from backups. Berlin's case shows the limit of that leverage against a government willing to absorb the exposure.
What is Berlin doing now?
The state government announced a coordinated crisis review on September 5 to work through the dumped data and determine whether any of it creates a security risk to critical sites or sensitive government bodies.
Berlin also brought in the US security firm CrowdStrike to inspect its IT systems using the company's Falcon tool, to establish whether Rhysida is genuinely out of the network and whether anything was left behind.
That step has caused friction. According to an internal letter obtained by public broadcaster rbb, the Lichtenberg district is refusing to allow CrowdStrike access to its servers, arguing the software would gain effectively unlimited access to all its data including personal information, would likely be impossible to remove, and could monitor both employee work devices and the employees using them.
What businesses should take from the Berlin breach
Three things carry over regardless of sector.
First, the window matters more than the headline. Attackers were inside for roughly a week before anyone noticed. Detection speed, not perimeter strength alone, determines how much leaves the building.
Second, paying is not a clean exit. Berlin's refusal made the leak certain, but payment would have made it merely likely — with a criminal group holding the only copy of the promise.
Third, incident response creates its own governance problems. The Lichtenberg dispute is a preview of a question many organizations face mid-crisis: how much access do you grant an outside investigator, and who decides? That's worth settling before an incident, not during one.
Sources: Cybernews; Euronews; Security Affairs. Figures on file counts and the intrusion window vary slightly between outlets.