A data extortion crisis in Berlin has escalated after the Rhysida ransomware group published approximately 1.4 million files stolen from the city’s network, following Berlin’s refusal to pay a demand of 30 bitcoin—valued at around €2 million. The files were made available for download on the group’s leak site after the authorities let the auction deadline expire without payment.
Berlin’s Refusal and the Public Data Dump
Authorities in Berlin confirmed they would not pay the ransom, despite heavy pressure created by Rhysida’s public countdown and subsequent public posting of government data. Initial links to the leak site were unavailable, but German media outlets reported that downloads became accessible within an hour after the auction ended.
The dump consisted of files organized in several packages, containing what appeared to be personnel records, reports, and administrative documents. The content included staff evaluations, job references, tender-related documents, and other sensitive office records. While officials had not confirmed the authenticity of every file, reporting suggested the material was substantial and live for browsing.
Berlin Senate officials stated, “Security staff and IT forensic teams are now reviewing the released data packages, and anyone identified as affected will be notified according to legal requirements.”
Residents who feared their information might be misused were urged to contact police. The ongoing investigation is led by the Berlin public prosecutor’s office, state criminal police (LKA), and the Federal Office for Information Security (BSI).
Details of the Rhysida Attack and Demands
Rhysida claimed to have exfiltrated nearly 5.8 terabytes of data from Berlin’s systems during an attack in August. Ransomware groups like Rhysida typically operate by encrypting and stealing data, then threatening to leak it if their demands are not met. In this case, 30 bitcoin was set as the unlocking price, and failure to pay culminated in a public leak.
The files reportedly included city contracts, fine records, login credentials, and documents relating to court cases and critical systems. Berlin’s governing mayor Kai Wegner stressed the city’s refusal to accept blackmail, while authorities highlighted the group’s prior attacks in Europe and the United States and raised—but did not confirm—the possibility of Russian involvement.
Ransomware incidents such as this, with massive data exposure following refusal to negotiate, represent a common strategy among professional ransomware organizations operating under affiliate models.
Mini dictionary: Rhysida — A ransomware group known for high-profile cyberattacks against government and institutional networks, employing tactics such as public auctions and large-scale data leaks to pressure victims into paying cryptocurrency ransoms.
Risks and Security Warnings
Joachim Selzer, spokesperson for the technology advocacy group Chaos Computer Club, warned that the breach could lead to identity theft, as small administrative details can be exploited for impersonation. The widespread availability of the files means that even individuals with basic technical skills could access personal or official data, increasing the risk of fraud and phishing.
The exposure of internal memos, payroll records, and cleartext passwords could make it significantly easier for malicious actors to steal identities or launch targeted attacks, according to Selzer.
Security specialists in Germany have generally supported the city’s decision not to pay the ransom. They argued that refusing payment discourages further attempts by ransomware groups, but also acknowledged the resulting harm to those whose sensitive data is compromised.
| Detail | Before Leak | After Leak |
|---|---|---|
| Ransom Demand | 30 BTC (€2 million) | Unpaid |
| File Access | Private auction | Public download |
| Files Released | Secured by city | ~1.4 million files leaked |
Ongoing Investigation and Broader Implications
The breach has prompted an extensive digital forensic review, with teams working to identify those affected, assess the scope of the leak, and mitigate potential misuse of the information. Authorities advised public vigilance and instructed anyone noticing fraudulent activity related to their data to file a police report.
For cybersecurity experts, the episode highlights the operational shift enabled by cryptocurrencies, making ransom payments more accessible, while public leak sites allow threat actors to escalate pressure on victims and maximize exposure after negotiations fail.
Berlin now faces the complex task of addressing the consequences of this leak—verifying the contents, resetting compromised credentials, tracking misuse, and supporting affected individuals—against a backdrop where refusal to pay has immediate and widespread repercussions.





USDT
AAPL
