
Rhysida Leaks 6TB of Berlin Data After Ransom Refusal
The ransomware group Rhysida has published almost six terabytes of data stolen from Berlin's state administration on the dark web, after the German capital refused a ransom of 30 Bitcoin — roughly €2 million.
The leak contains 1,439,893 files, according to Euronews. Early reviews of the file listings suggest the material includes police investigation records, government emergency planning documents, and large volumes of personal data belonging to civil servants.
Berlin's administration and political leadership had said little publicly as of Saturday morning.
What actually happened
Rhysida is a ransomware gang that has been active since 2023. Like most modern ransomware crews, it uses a tactic known as "double extortion": it steals a copy of an organisation's files before encrypting them, then threatens to publish the stolen data if the victim doesn't pay.
That threat is the leverage. Restoring from backups solves the encryption problem, but it does nothing about the copy the attackers already walked away with.
Rhysida listed Berlin on its leak site and set a countdown clock. It expired at about 3:35 p.m. local time on Friday. The Berlin Senate had made clear before the deadline that it does not pay blackmail demands as a matter of principle. Shortly after the countdown ended, the data package went live, and members of the group began circulating lists of filenames on social media.
How the attackers got in, when the intrusion began, and which specific agencies were affected have not been disclosed.
Why security researchers are alarmed
The concern is not the volume. It's what appears to be inside it.
Among the published folders is one titled "AG CBRN-Rahmenplanung." CBRN stands for chemical, biological, radiological and nuclear — the category of threats emergency planners prepare for when they model worst-case scenarios. Documents of that kind can describe where the gaps are, how agencies would respond, and what they consider their weak points.
Investigative journalist Lars Winkelsdorf, who raised the alarm publicly on X, described the attack as being "of a magnitude that threatens the state." He said the files also include records from the LKA — Germany's state-level criminal police — as well as material on national defence, government emergency communication channels, and defence-related companies.
Those characterisations come from Winkelsdorf's review of the leaked material and from the attackers themselves. German authorities have not confirmed the contents, and independent verification of what a 1.4-million-file dump actually contains will take time. Treat the specifics as credible but not yet official.
What this means for the people in the files
The clearest and most immediate harm falls on individuals.
The leak reportedly includes birth certificates, telephone numbers, home addresses, and what appear to be staff absence lists for state employees. That combination is unusually dangerous for a specific reason: it is the raw material for convincing impersonation.
Someone holding a civil servant's home address, birth details, and work schedule can build a phishing message or a phone call that sounds legitimate. Fraudsters use exactly this kind of detail to bypass the instinct that normally makes people suspicious. Address and date-of-birth data is also the standard input for identity theft — opening accounts, taking out credit, or passing "security questions" at a call centre.
Unlike a password, none of this can be changed after the fact.
Why Berlin refused to pay
Governments across Europe and North America have largely converged on a no-ransom stance, and Berlin's position is consistent with that.
The reasoning is straightforward. Paying funds the next attack, and it buys nothing reliable. Criminal groups have repeatedly kept copies of data they promised to delete, or sold it on regardless. Once the files have been exfiltrated, the victim's leverage is already gone.
The trade-off is real, though, and Berlin is now living it. Refusing to pay means the data goes public. That is the cost the policy accepts in exchange for not sustaining the business model.
What other organisations should take from this
Know what you actually hold. Many of the most damaging leaks involve data an organisation had forgotten it was storing — old HR records, scanned identity documents, planning files from years ago. Data you no longer need is pure liability. Deleting it on a schedule is one of the cheapest security controls available.
Assume exfiltration, not just encryption. Backups are essential, but they only address half of a modern ransomware attack. Recovery planning should include a communications and legal plan for the scenario where your data is published.
Segment sensitive material. A single compromised administrative network should not provide a path to emergency planning documents or police records. Separating the most sensitive systems from general-purpose ones limits how far one intrusion travels.
Decide the ransom question before you need to. Organisations that have never discussed their position end up making that call under extreme pressure, in the middle of an outage, with a countdown running.
What happens next
Expect German federal involvement, given the reported presence of defence and emergency planning material. Also expect the affected staff to need direct guidance — credit monitoring where applicable, and clear warnings that they are now higher-value targets for phishing and impersonation attempts.
We will update this story as officials confirm details.
Source: Euronews