
Rhysida leaks 5.79 terabytes of Berlin city data after 2-million-euro ransom deadline expires
The Rhysida extortion syndicate published 1.4 million municipal files on the dark web after Berlin authorities refused to pay a 30-bitcoin ransom following an August network breach.
Refusal of the ransom demand
The extortion group Rhysida published approximately 1.4 million files stolen from Berlin municipal networks after the German capital refused to pay a ransom demand. The cybercrime group set a strict ultimatum requiring city authorities to transfer 30 bitcoins, an amount valued at approximately 2 million euros. The deadline for the transaction expired at 15:35 on Friday, 4 September 2026. Berlin Mayor Kai Wegner stated in the days leading up to the deadline that the city would not allow itself to be blackmailed by extortionists. After municipal authorities let the deadline pass without sending any funds, the attackers uploaded the extracted files across multiple downloadable packages to an open section of the dark web.
All files have been placed in a publicly accessible section - have fun browsing, data hunters!
Scope of the municipal network breach
The unauthorized access to Berlin's municipal servers took place between 7 August and 12 August 2026. On 14 August 2026, municipal IT administrators disconnected several online systems to restrict the breach and prevent further data exfiltration. The emergency shutdown paralyzed basic administrative functions for several days, leaving citizens unable to submit applications for housing allowances or process routine digital payments. Follow-up investigations conducted by Berlin officials established that the intrusion reached additional municipal infrastructure, specifically targeting the Berlin Department of Transport and Environmental Protection. The administration acknowledged the potential breadth of the incident following those forensic discoveries.
It cannot be ruled out that the breach may have also included personal data or other classified information.
- Hackers breach Berlin municipal networks and extract administrative data
- Berlin shuts down municipal web systems, halting housing allowance processing
- Der Spiegel publishes leak site screenshot detailing stolen contracts and passwords
- Ultimatum to pay 30 bitcoins expires as Berlin authorities refuse ransom demand
- Rhysida releases 5.79 terabytes of municipal data in public dark web packages
Nature of the published files
The released data dump has a total size of 5.79 terabytes distributed across several archive packages. According to dark web folder listings, the files include administrative personnel records, employment certificates, recruitment postings, and internal employee evaluations. In the second half of August 2026, the German weekly magazine Der Spiegel published a screenshot from Rhysida's leak platform detailing the stolen assets. The group claimed on that platform to possess internal contracts, non-disclosure agreements, passwords, personnel files, and thousands of private contact details belonging to individuals. Independent cybersecurity analysts have not yet verified the integrity of the uploaded packages, and officials have not confirmed whether the leak contains the full volume of data taken in August.
Background on the Rhysida group
Rhysida is a ransomware syndicate believed to operate from bases in Russia and Eastern Europe. The group has targeted institutional infrastructure in previous operations, including a cyberattack on the British Museum in 2023. In the Berlin attack, the syndicate followed its established method of stealing internal documents, encrypting or disabling access, and demanding digital currency under a strict timeline. When the municipal government refused the 30-bitcoin ransom, the group shifted to public dissemination of the files. German authorities continue to assess the legal and security ramifications of the published administrative data.


