Breaking
SecurityDeveloping Story

Berlin's Stand Against Rhysida Puts Data at Risk

Berlin refused a €2m ransom; Rhysida leaked 5.7 TB, including emergency plans.

··3 hours ago·3 min read
Computer code on a dark screen with line numbers
Photo by Harshit Katiyar on Unsplash

Berlin's state government is now facing the fallout of a deliberate decision. After refusing to meet a ransomware gang's extortion demand, the city has confirmed that a massive trove of stolen data — including sensitive disaster response plans — has been dumped on the dark web. The move turns a cyberattack into a public disclosure event with potentially far-reaching consequences for employees, citizens, and public safety planning.

Ultimatum Expired, Data Released

The Rhysida ransomware group had set a deadline of Friday, September 4, for the city to pay 30 bitcoins — equivalent to roughly €2 million — to prevent the release of data stolen from Berlin's state network. The state government did not pay. In a statement published on its official website on September 4, the authority said the ultimatum had expired that afternoon and, according to experts, the entire dataset was published on the dark web.

The State of Berlin had earlier warned, in an announcement also dated September 4, that the personal data of employees, as well as that of citizens and businesses, could be affected. The state has stressed it has no intention of capitulating to extortion, a stance that sets the stage for a prolonged public data exposure.

5.7 TB of Files Released

Rhysida claimed to have accessed approximately 5.7 terabytes of data. Reports indicate the leak encompasses around 1.4 million files, making it one of the larger public-sector data dumps linked to a ransomware incident. The sheer volume suggests the group had deep access to the network before the attack was detected or contained.

Emergency Plans Exposed

Among the most alarming disclosures are reported to be sensitive state emergency plans. According to Euronews, the leak includes documents related to terrorist attacks and other disaster scenarios, contained in a folder titled "AG CBRN-Rahmenplanung." CBRN stands for chemical, biological, radiological and nuclear threats. The exposure of such planning materials raises concerns about operational security and could potentially inform malicious actors about response protocols.

Personal Data of Thousands at Risk

Rhysida also claims the dataset contains personal information of tens of thousands of individuals. This includes personnel files of state workers, such as absence lists, payroll data, and home addresses. The potential for identity theft, phishing, or targeted harassment against employees is significant, and the state is now tasked with a complex notification process.

Forensics Underway, Notifications to Follow

IT forensic experts are currently analyzing the stolen dataset. Authorities plan to contact all individuals affected once this analysis is complete. The Senate Chancellery stated that if affected persons are identified during analysis, they will be notified by the relevant Senate departments on a risk-based basis and in accordance with legal requirements. Berlin citizens who discover their personal data has been published are urged to report the matter to law enforcement.

State Takes a Hard Line

The State of Berlin will not give in to blackmail. The safety of the State of Berlin’s staff and the people of Berlin is our top priority.

— Florian Hauer, chief digital officer for the State of Berlin

The state government has also noted there are currently "no indications" the state network remains compromised. That suggests the initial intrusion vector has been closed, but the damage from data exfiltration is already done.

Rhysida's Track Record

The Rhysida ransomware-as-a-service (RaaS) operation was first observed in May 2023 and has frequently targeted public institutions and critical services. The group has been linked to a string of attacks on US healthcare providers, including Cookeville Regional Medical Center (CRMC) in Tennessee in 2025, which resulted in the compromise of more than 337,000 patients’ data. A Rhysida affiliate was also behind the high-profile ransomware attack on the British Library in 2023, which suffered huge disruption and recovery costs after refusing the attacker’s extortion demands.

Why It Matters

Berlin’s refusal to pay, while principled, carries consequences that extend beyond the immediate data dump. This incident could serve as a test case for other public institutions weighing whether to negotiate with ransomware gangs. The exposure of emergency plans, in particular, suggests that even non-financial data can have strategic value. For organizations considering a similar stance, the calculus may now include not just the cost of downtime and recovery, but also the risk of sensitive operational data becoming public. This could reshape how governments and businesses think about cyber resilience and data classification.

#rhysida#ransomware#berlin#data breach#cyberattack

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories