Rhysida Publishes 1.4 Million Berlin Government Files After Ransom Refusal

Rhysida published nearly 1.4 million files stolen from Berlin after a €2 million ransom demand failed, exposing personal and sensitive government data.

Written By
KJ
Kezia Jungco
Sep 11, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Berlin refused to pay Rhysida. The ransomware group responded by publishing nearly 1.4 million stolen government files on the dark web.

Deutsche Welle said that the dump contains 1,439,893 files, while other reports put the stolen data at about 5.7 TB. The breach affected two Berlin government departments and exposed material ranging from employee records and official correspondence to potentially sensitive emergency-planning documents.

Berlin has since set up a central crisis response and said affected people will be notified under German and European data protection rules.

For German and EMEA security teams, the incident is a reminder that refusing a ransom does not end the damage when attackers have already stolen sensitive data.

Rhysida leak followed an August intrusion and failed ransom

The intrusion began in August. BBC reported that data was accessed between Aug. 7 and Aug. 12, and two departmental networks were shut down on Aug. 14, temporarily disrupting housing-benefit applications and payments.

Rhysida later demanded 30 bitcoin, worth roughly €2 million, and threatened to publish the stolen material. Berlin refused to pay. 

According to Reuters, the group released the data after its auction ended, prompting the city to create a central crisis unit to review the files, assess the impact, and support notifications to affected citizens and businesses.

“The State of Berlin will not give in to blackmail,” Chief Digital Officer Florian Hauer said in an official statement. At the time, Berlin said there were no indications that the state network remained compromised.

Leaked files may contain sensitive government plans

The dump goes beyond ordinary administrative records. Deutsche Welle reported that employee files, pay slips, official correspondence, scanned identity documents, phone numbers, and home addresses appeared in the leaked material.

Euronews also noted that a folder titled “AG CBRN-Rahmenplanung” was among the files. CBRN refers to chemical, biological, radiological, and nuclear threats, raising concerns that emergency-planning material may have been exposed. Other reported files relate to government investigations, defense planning, and emergency procedures, although authorities have not publicly verified every item in the dump.

Advertisement

The exposure could create problems long after systems are restored. A security expert cited by Deutsche Welle warned that detailed personal information can help criminals impersonate victims and determine what information they need to commit fraud.

Phishing reportedly opened the door

Deutsche Welle said that the attackers gained access after an employee in Berlin’s transport administration interacted with a phishing email and attachment. Berlin’s secure government network connects around 600 locations, including municipal offices and senate departments.

For German public-sector organizations, the attack shows how a phishing incident can lead to both service disruption and a much longer data exposure problem. Berlin has since created a coordination office involving its administrative agencies and contacted Germany’s Federal Office for Information Security, or BSI.

Authorities are also reviewing the leaked material to identify people and businesses that need to be notified. Reuters highlighted that affected individuals will be contacted in accordance with German and European data protection rules.

The incident has wider relevance across EMEA, particularly for public-sector organizations managing large amounts of citizen and operational data across interconnected systems. Phishing defenses and employee training remain important, but organizations also need access controls, network segmentation, and monitoring that can flag unusual data transfers before stolen information leaves the network.

Berlin officials said systems and processes needed for the Sept. 20 state election remain unaffected. The nearly 1.4 million files already published, however, cannot simply be recovered by restoring affected systems. 

For security teams in Germany and elsewhere in Europe, limiting what attackers can reach and remove after an initial compromise can be just as important as keeping them out in the first place.

Also read: Norway has also faced a major government cyberattack, with a pro-Russian group claiming responsibility for the country’s largest recorded DDoS incident.

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.