Rhysida Dumps 1.44 Million Files, 5.8TB of Berlin State Government Data After Ransom Refusal

On September 5, 2026, the Rhysida ransomware group published a massive trove of data allegedly stolen from Berlin’s state government after authorities refused a ransom demand. Rhysida claimed the dataset contained approximately 1.44 million files totalling 5.79TB, following an intrusion into Berlin’s state network in August. The attack affected the Senate departments responsible for urban development, building and housing, and mobility, transport, climate protection and the environment. Berlin had previously confirmed that attackers extracted data between August 7 and 12 and disconnected the affected departments from the state network after detecting the incident.

Rhysida reportedly demanded 30 Bitcoin, valued at roughly €2 million at the time, and threatened to release the stolen information if Berlin did not pay. Berlin Governing Mayor Kai Wegner and Interior Senator Iris Spranger publicly rejected the demand, stating that the government would not submit to extortion. After the deadline expired, the attackers released the data. Reported material includes personal information, emails, telephone numbers, contracts, government documents and information relating to critical infrastructure, although Berlin authorities are still assessing the authenticity, scope and sensitivity of the published files. The Rhysida attribution and the precise volume of stolen data should therefore be treated as attacker claims, rather than fully independently verified figures.

The incident presents a significant government and critical-infrastructure security risk because the exposed information could support identity theft, targeted phishing, credential attacks and further intrusion attempts. German federal authorities, including the BSI, BKA and Federal Office for the Protection of the Constitution, are supporting Berlin’s investigation and assessing potential security implications. Berlin has established a central crisis unit to review the leaked material and identify affected individuals and organisations. The incident also demonstrates the consequences of refusing a ransomware payment when attackers have already exfiltrated sensitive data: even where systems are not encrypted or disrupted, data theft can become the primary extortion mechanism.

Share

Related Posts

getty-images-aTWKwJllPOA-unsplash
69430f5a293f984422fc4968_12-17-25digitization-5194814_1280[1]
getty-images-cZgRe9BlYR4-unsplash

Copyright © All Right Reserved

Privacy Policy