Rhysida Publishes Berlin State Data After €2M Ransom Refused, and a Second Leak Surfaces
Berlin refused a €2 million ransom, so the Rhysida group published its stolen state data, reportedly including sensitive emergency plans. Days later, a second leak of Berlin government login credentials appeared online, and Germany's BSI warned about the same actor.
Berlin refused to pay, and the data came out anyway. The Rhysida ransomware group has published the roughly 5.7 terabytes it claims to have stolen from Berlin's state government, doing so after the city let a €2 million ransom deadline pass on September 4. The leaked files reportedly include not only state employee records but sensitive state emergency plans, the kind of operational material a government never wants in public hands.
Berlin's Senate Chancellery confirmed the publication in a September 4 statement: “The ultimatum issued by the hacker group Rhysida following its cyber-attack on Berlin’s state network expired on Friday afternoon. According to experts, the entire dataset was published on the dark web.” As Infosecurity Magazine reported, Rhysida had demanded 30 bitcoins, worth about €2 million, and set a Friday deadline that the state deliberately let lapse. Chief Digital Officer Florian Hauer said the city would “not give in to blackmail,” and Governing Mayor Kai Wegner called it “a very serious crime” committed against the State of Berlin, according to The Record.
This is the next chapter in a case we covered when Berlin first went public with its refusal to pay. What is new now: the threat has been carried out, a second and separate leak has surfaced, and Germany's national cyber authority has issued a warning tied to the same actor.
What Rhysida Published
Rhysida has reportedly released the full dataset it advertised, around 1.4 million files, per Infosecurity Magazine's account of the leak. The group claims the trove holds personal information on tens of thousands of people, including personnel files of state workers with absence lists, payroll data and home addresses. Berlin's own data protection authority has separately said the exposed material includes personal information about public employees, and that data belonging to Berlin residents may also have been caught up in it: names, addresses, dates of birth, bank details, email addresses, phone numbers, correspondence with agencies, and copies of documents submitted to the administration.
Those figures come with an important caveat. The volume, the file count and the contents are Rhysida's own claims, and Berlin's forensic review of the published material is still underway. The city has confirmed that data was stolen and that it received an extortion demand, but it has not verified the attacker's numbers or the specifics of what was taken. Treat the 5.7 terabyte figure and the victim tally as unconfirmed until the state's own analysis says otherwise. It is also not established that Rhysida is holding anything back: Berlin's experts describe the entire dataset as published, but whether the group retains additional material is unknown.
The Emergency Plans Are the Harder Problem
Euronews reported, and Infosecurity Magazine relayed, that the leak includes highly sensitive state emergency plans covering terrorist attacks and other disaster scenarios, held in a folder labeled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological and nuclear. If that reporting holds, it moves this incident out of the usual data-breach category and into something closer to an operational-security failure.
The distinction matters for defenders. A leaked payroll record is a privacy problem with a known remediation path: notify the person, monitor for fraud, and in some cases reissue an identifier. An exposed emergency or continuity plan is different. Its value depends on the details staying private, and once those details are public they cannot be reset, reissued or invalidated. The only remedy is to revise the underlying procedures, which is slower, costlier and far harder to verify than resetting a credential.
A Second Leak, Not Yet Tied to the First
In parallel, German authorities have opened a separate investigation. Over the weekend, according to The Record, hackers published login credentials and other information drawn from Berlin's government network, and the city confirmed the release on Sunday. Berlin said the newly published data includes login credentials but did not say what systems those credentials unlock or whether they remain valid.
Two things are not yet confirmed about this second leak, and both are worth stating plainly. First, authorities have not attributed it to any specific group, Rhysida included. Second, it is not established whether the credential dump stems from the same intrusion as the Rhysida publication or from a distinct compromise. The Record frames the credential release as following the mid-August cyberattack, not as a confirmed second stage of it.
The affected agencies, by contrast, are named. The original breach compromised two Berlin Senate ministries: one responsible for urban development and housing, the other for transport, mobility, climate protection and the environment. Both were disconnected from the wider government network on August 14 and kept operating, though the cut left some staff without normal email and internet access and disrupted public services that depend on those systems. The urban development ministry has since tightened security controls, which officials warned could temporarily limit access to some of its applications. The timing is politically charged, coming shortly before Berlin's September 20 state election, though Interior Senator Iris Spranger has said there is no evidence data was stolen from election systems and that the election environment is secure.
Why Germany's BSI Weighed In
Separately, Germany's Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, or BSI) issued its own warning about a cyberattack campaign it links to the same financially motivated actors behind Rhysida. The BSI did not explicitly name Berlin, but said it had been informed in August about the compromise of a government institution. Per The Record, the agency likened the activity to the TerminalFix campaign documented by Microsoft, in which compromised websites display fake CAPTCHA verification pages that trick visitors into manually running malicious commands. It tied the activity to malware tracked as LoremIpsumLoader, also called AxolotLoader, and said the campaign appears to be the work of cybercriminals rather than state-sponsored or politically motivated actors.
Two BSI data points belong in any risk conversation about this group. The agency said government and public administration organizations are among the five sectors most frequently named on Rhysida's leak site, and that stolen data is ultimately published in 92 percent of cases where a victim is named there. For an organization staring at a Rhysida extortion note, that figure is the base rate: being named almost always ends in publication, which is exactly what Berlin just experienced.
What Public-Sector Defenders Should Do
Berlin's situation is now a live example of the phase most incident plans underrate: what to do after the data is actually out. Once publication happens, the work shifts from prevention to damage control, credential hygiene and honest notification. The checklist below is what a prepared public-sector security team runs at that point, and it maps directly to a rehearsed incident response process rather than an improvised scramble.
● PUBLIC-SECTOR BREACH-RESPONSE CHECKLIST What a government security team should do once stolen data is actually published. |
1 · TREAT THE LEAK AS REAL Assume the published dataset is genuine and act on it. Do not wait for full attribution or a verified file count before starting response. |
2 · ROTATE CREDENTIALS, ENFORCE MFA Reset every credential that could be in the dump and enforce phishing-resistant MFA on all remote-access services. Leaked logins are the fastest path back in. |
3 · REVIEW OPERATIONAL AND EMERGENCY PLANS Identify which sensitive operational documents (emergency, continuity and disaster plans) were exposed, and revise any procedure that depended on those details staying secret. |
4 · NOTIFY AFFECTED EMPLOYEES AND RESIDENTS Tell the people whose personnel or personal records were taken, and inform the data-protection authority, on a risk-based basis and in line with legal requirements. |
5 · COORDINATE WITH THE NATIONAL CSIRT/BSI Share indicators with the national authority (in Germany, the BSI) and pull its current advisory into your own detection and threat hunting. |
Source: CyberSignal analysis of Berlin Senate Chancellery statements and the CISA, FBI and MS-ISAC Rhysida advisory (AA23-319A). |
The response sequence a prepared public-sector security team runs once stolen data is published. Source: CyberSignal analysis of Berlin Senate Chancellery statements and the CISA, FBI and MS-ISAC Rhysida advisory (AA23-319A).
The one item defenders tend to skip is the third. Passwords rotate; emergency and continuity plans do not. If your operational playbooks assume secrecy, exposure means rewriting procedures, not resetting a value, and that work should start now rather than after the next drill. Notification, too, is a legal duty as much as a courtesy: for the timelines involved, see our overview of data breach notification laws.
My read: Refusing to pay is defensible and increasingly common. The CISA, FBI and MS-ISAC advisory on Rhysida says outright that authorities do not encourage paying, and a public no-pay stance removes an attacker's leverage to extract a quiet settlement. But the refusal is not the part of this that should keep Berlin's defenders up at night. The real operational harm here is the reported exposure of the emergency and CBRN planning material, because that is the piece you cannot claw back, re-issue or invalidate. A leaked payroll file is a privacy incident with a known remediation path. A leaked disaster-response plan is a standing operational problem until the underlying procedures are revised. (This is assessment, not a reported fact.)
Primary Documents
- Berlin Senate Chancellery statement on the published dataset and plans to contact those affected (September 4)
- Berlin Commissioner for Data Protection: guidance on the hacker attack
- BSI cybersecurity warning on the Rhysida-linked campaign
- CISA, FBI and MS-ISAC joint advisory on Rhysida ransomware (AA23-319A)