Berlin refused to pay Rhysida. The ransomware group responded by publishing nearly 1.4 million stolen government files on the dark web.
Deutsche Welle said that the dump contains 1,439,893 files, while other reports put the stolen data at about 5.7 TB. The breach affected two Berlin government departments and exposed material ranging from employee records and official correspondence to potentially sensitive emergency-planning documents.
Berlin has since set up a central crisis response and said affected people will be notified under German and European data protection rules.
For German and EMEA security teams, the incident is a reminder that refusing a ransom does not end the damage when attackers have already stolen sensitive data.
Rhysida leak followed an August intrusion and failed ransom
The intrusion began in August. BBC reported that data was accessed between Aug. 7 and Aug. 12, and two departmental networks were shut down on Aug. 14, temporarily disrupting housing-benefit applications and payments.
Rhysida later demanded 30 bitcoin, worth roughly €2 million, and threatened to publish the stolen material. Berlin refused to pay.
According to Reuters, the group released the data after its auction ended, prompting the city to create a central crisis unit to review the files, assess the impact, and support notifications to affected citizens and businesses.
“The State of Berlin will not give in to blackmail,” Chief Digital Officer Florian Hauer said in an official statement. At the time, Berlin said there were no indications that the state network remained compromised.
Leaked files may contain sensitive government plans
The dump goes beyond ordinary administrative records. Deutsche Welle reported that employee files, pay slips, official correspondence, scanned identity documents, phone numbers, and home addresses appeared in the leaked material.
Euronews also noted that a folder titled “AG CBRN-Rahmenplanung” was among the files. CBRN refers to chemical, biological, radiological, and nuclear threats, raising concerns that emergency-planning material may have been exposed. Other reported files relate to government investigations, defense planning, and emergency procedures, although authorities have not publicly verified every item in the dump.
The exposure could create problems long after systems are restored. A security expert cited by Deutsche Welle warned that detailed personal information can help criminals impersonate victims and determine what information they need to commit fraud.
Phishing reportedly opened the door
Deutsche Welle said that the attackers gained access after an employee in Berlin’s transport administration interacted with a phishing email and attachment. Berlin’s secure government network connects around 600 locations, including municipal offices and senate departments.
For German public-sector organizations, the attack shows how a phishing incident can lead to both service disruption and a much longer data exposure problem. Berlin has since created a coordination office involving its administrative agencies and contacted Germany’s Federal Office for Information Security, or BSI.
Authorities are also reviewing the leaked material to identify people and businesses that need to be notified. Reuters highlighted that affected individuals will be contacted in accordance with German and European data protection rules.
The incident has wider relevance across EMEA, particularly for public-sector organizations managing large amounts of citizen and operational data across interconnected systems. Phishing defenses and employee training remain important, but organizations also need access controls, network segmentation, and monitoring that can flag unusual data transfers before stolen information leaves the network.
Berlin officials said systems and processes needed for the Sept. 20 state election remain unaffected. The nearly 1.4 million files already published, however, cannot simply be recovered by restoring affected systems.
For security teams in Germany and elsewhere in Europe, limiting what attackers can reach and remove after an initial compromise can be just as important as keeping them out in the first place.
Also read: Norway has also faced a major government cyberattack, with a pro-Russian group claiming responsibility for the country’s largest recorded DDoS incident.





