Berlin said no to a €2 million ransom this week. On Friday afternoon, a countdown clock ran out and 1.4 million government files went public.
That's the whole argument about ransom policy, playing out in real time. Today's edition covers what's in the leak, why OpenAI is gating its newest model's hacking abilities while writing a $1 billion cheque to defenders, and one Microsoft outage worth telling your team about.
Four minutes. Let's go.
TL;DR
Ransomware group Rhysida published nearly 6TB of Berlin government data after the city refused a €2 million ransom — 1.4 million files, including police and emergency planning records
OpenAI released GPT-6 Astra and, the same week, committed $1 billion to help under-resourced defenders use AI
AI attacks have pushed the security chief into the boardroom, but budgets are only rising about 6% this year
Microsoft is still investigating Teams desktop app launch failures on Windows — no root cause, no fix date
Lead story
The ransomware group Rhysida demanded 30 Bitcoin — around €2 million — from Berlin's state administration and set a countdown. The city held its no-ransom line. Minutes after the clock ran out on Friday afternoon, roughly six terabytes and 1.4 million files hit the dark web.
Researchers reviewing the file listings report emergency planning documents, police records and personal data on civil servants, including home addresses and birth certificates. Officials have said almost nothing so far.
If your organisation has never decided its position on paying a ransom, this is the case study for having that conversation before the countdown starts.
GPT-6 Astra is the first OpenAI model to hit the company's own "Critical" threshold for cyber capability, so it's rolling out in stages with cyber features gated. In the same week, OpenAI committed $1 billion in subsidised access for utilities, small banks, local governments and nonprofits.
If you run or advise a small critical-services organisation, there is a real programme to apply to. If you don't, the signal still matters: a major vendor now considers its own model's cyber abilities dangerous enough to restrict.
Quick hits
One thing to do today
Ask your team a single question: if our data were stolen and we refused to pay, what would we do next?
Not the technical answer — the practical one. Who calls the affected people. Who talks to lawyers. What you tell customers. Berlin is finding those answers under pressure, in public, with journalists reading the files. It's a much easier conversation to have on a quiet Tuesday.
— SecureMindset