
Rhysida leaks 5.8 terabytes of Berlin government data after €2 million ransom refusal
Berlin authorities established a central crisis unit on Saturday after ransomware collective Rhysida published 1.44 million municipal files, including emergency protocols and employee records, on the dark web.
The ransomware collective Rhysida published nearly 5.8 terabytes of stolen government data on the dark web on Friday, 4 September 2026, following Berlin authorities' refusal to pay an extortion demand. The cybercrime group had demanded 30 Bitcoin, an amount valued at approximately €2 million, before setting a deadline for the city administration. The published repository comprises roughly 1.44 million distinct files extracted from state servers during an intrusion detected weeks earlier. Berlin Governing Mayor Kai Wegner defended the municipal government's stance against extortion, stressing that yielding to ransom demands provides no assurance that stolen records will not be redistributed.
Mayor Kai Wegner outlined the administration's position during an interview with Bild.
Who can state that, even if we had paid, these data would not have already been somewhere else for a long time?
Administrative disruption across city departments
The breach occurred on 14 August 2026 and targeted the computer networks of the Berlin city-state, affecting two primary administrative departments. In response to the breach, IT officials severed network connections for several municipal branches for an entire week to halt lateral movement across state infrastructure. The shutdown particularly impacted the Senate departments responsible for housing and environmental affairs, paralyzing standard municipal workflows. As a direct consequence of the network disconnection, citizens were unable to submit housing allowance applications, and regular benefit payments remained blocked for several days. Municipal authorities affirmed that Berlin's state elections scheduled for 20 September 2026 remain fully secure and will go ahead as planned.
- Hackers breach Berlin city network, leading to a week-long shutdown of housing and environmental systems
- Rhysida publishes 5.8 terabytes of stolen files on the dark web after ransom deadline expires
- Berlin government forms a central crisis management unit to evaluate leaked data
- Scheduled date for Berlin municipal elections
Scope of leaked personnel and security records
A large portion of the compromised data includes sensitive personal records of civil servants, including personnel salary lists, banking coordinates, identity document scans, and records of internal disciplinary proceedings and professional negligence allegations. In addition to administrative employee data, the archive exposes sensitive operational information, such as hazard prevention protocols belonging to the Berlin fire department and documentation concerning structural expansion projects at the Federal Chancellery. The files also contain national security materials, including State Criminal Police Office (LKA) investigative dossiers and emergency intervention blueprints for chemical, biological, radiological, and nuclear threats. Investigative journalist Lars Winkelsdorf noted that the published cache includes defense contractor details and federal contingency communications designed for catastrophic scenarios.
Crisis unit mobilization and past extortion campaigns
Berlin's state government established a centralized crisis management unit on Saturday, 5 September 2026, to oversee the line-by-line verification and forensic evaluation of the exposed files. City officials labeled the cyberattack an extremely serious criminal offense against the state itself and instructed the general public to refrain from circulating unverified materials on social networks. The administration announced that all individuals and corporate entities compromised by the data release will receive direct notification under German and European Union data protection regulations. The incident follows a similar campaign by the Rhysida group against the British Library in autumn 2023, where attackers demanded over €760,000 before dumping roughly 500,000 files of visitor, subscriber, and staff records onto the dark web when that institution also rejected the demand.
- British Library (2023)
- 500000 files
- Berlin Administration (2026)
- 1440000 files
