Rhysida Ransomware Leaks 5.7TB of Berlin Government Data After €2M Extortion Refused
In a stark demonstration of the escalating stakes in public sector cybersecurity, the Rhysida ransomware gang has followed through on its threat to publish a massive trove of data stolen from Berlin’s state government network. The leak, which occurred after the German capital refused to pay a €2 million extortion demand, exposes sensitive emergency response plans and the personal data of tens of thousands of citizens and employees. This incident serves as a critical case study for security researchers on the operational tactics of modern ransomware-as-a-service (RaaS) groups and the harsh realities of data breach resilience.
The State of Berlin confirmed that the Rhysida group had published the stolen dataset on the dark web after the government declined to meet their financial demands. The threat actors had initially demanded 30 bitcoins—equivalent to roughly €2 million—to refrain from releasing the data, setting a hard deadline of Friday, September 4. In an official statement, the state government made its position unequivocally clear, stating, "The ultimatum issued by the hacker group Rhysida following its cyber-attack on Berlin’s state network expired on Friday afternoon. According to experts, the entire dataset was published on the dark web." This firm stance against paying the ransom highlights a growing consensus among cybersecurity professionals that capitulating to extortion only fuels the malware economy.
The scale of the data breach is staggering. Rhysida claimed to have accessed approximately 5.7 terabytes of information, a volume that translates to roughly 1.4 million individual files. In the lead-up to the publication, the State of Berlin issued warnings that the compromised data could include sensitive personal information belonging to state employees, as well as citizens and businesses that interact with government services. The confirmation of the leak has now shifted the focus from prevention to damage control, with IT forensic experts currently engaged in a painstaking analysis of the stolen dataset to identify exactly which individuals are affected.
Sensitive Disaster Plans and Personnel Files Exposed
While the sheer volume of data is concerning, the nature of the exposed files has raised significant alarm among security analysts. Reports from Euronews indicate that the leak includes highly sensitive state emergency plans designed for terrorist attacks and other disaster scenarios. Specifically, a folder titled "AG CBRN-Rahmenplanung" was reportedly included in the dump—CBRN being the standard acronym for chemical, biological, radiological, and nuclear threats. The exposure of such operational security protocols represents a significant vulnerability, as it could provide malicious actors with a blueprint of Berlin’s defensive infrastructure and response strategies.
Beyond the strategic emergency plans, the Rhysida group claims the dataset contains the personal information of tens of thousands of people. This includes detailed personnel files of state workers, such as absence lists, payroll data, and home addresses. The combination of sensitive operational data and personally identifiable information (PII) makes this one of the more severe attacks on German administrative infrastructure in recent memory. For the victims, this creates a high risk of identity theft, targeted phishing campaigns, and physical security concerns, given that home addresses are now circulating on the dark web.
In response to the leak, the Berlin Senate Chancellery has outlined a protocol for notifying victims. "If individual affected persons are identified during the analysis, they will be notified by the relevant Senate departments on a risk-based basis and in accordance with legal requirements," the statement read. Authorities have also urged any Berlin citizen who discovers their personal data has been published to report the matter to law enforcement immediately. This dual approach of proactive notification and public reporting is designed to mitigate the fallout from the data breach, though the sheer scale of the analysis will likely take weeks or months to complete.
The Rhysida RaaS Operation: A Known Threat
This attack is not an isolated incident but rather a signature move for the Rhysida ransomware-as-a-service operation, which was first observed in the threat landscape in May 2023. The group has rapidly established a reputation for targeting public institutions and critical services, which are often more likely to possess sensitive data and less likely to have bulletproof security postures. Their business model relies on "double extortion"—exfiltrating data before deploying the encryption malware, then threatening to leak the stolen information if the ransom is not paid. This tactic puts immense pressure on victims, as the damage of a data breach occurs regardless of whether the encryption is reversed.
The group’s track record includes a string of high-profile attacks on US healthcare providers. Notably, in 2025, an attack on Cookeville Regional Medical Center (CRMC) in Tennessee resulted in the compromise of more than 337,000 patients’ data. Furthermore, a Rhysida affiliate was identified as the mastermind behind the devastating ransomware attack on the British Library in 2023. That particular incident caused huge operational disruption and incurred significant recovery costs after the institution refused to give in to the extortion demands, mirroring the stance taken by the State of Berlin. These cases demonstrate a clear pattern: Rhysida targets organizations where the data is most sensitive, and they are willing to publish it to make an example of those who resist.
Florian Hauer, chief digital officer for the State of Berlin, reinforced the government's decision to refuse the ransom, stating, "The State of Berlin will not give in to blackmail. The safety of the State of Berlin’s staff and the people of Berlin is our top priority." While this stance is ethically and strategically sound to prevent the normalization of ransomware payments, it comes with immediate consequences. The state government has noted that there are currently "no indications" that the state network remains compromised, suggesting that the initial attack vector has been closed. However, the forensic analysis of the stolen data is just beginning, and the full scope of the damage to citizens' privacy is yet to be determined.
Conclusion: The Aftermath of a Refused Extortion
The Berlin data leak serves as a sobering reminder that in the world of cybersecurity, the refusal to pay a ransom is often just the beginning of the battle. While the State of Berlin has taken a principled stand against financing cybercrime, the publication of 5.7TB of data—including CBRN response plans and personnel records—represents a significant intelligence and privacy loss. For security researchers, this incident underscores the necessity of robust data classification, offline backups, and incident response plans that assume a breach will occur. The Rhysida group has once again proven that their malware is not just about locking systems, but about weaponizing stolen data to maximize pressure on their victims.