Berlin is dealing with the fallout from a major ransomware attack after the Rhysida cybercrime group published a vast collection of stolen government files online, exposing personal and potentially security-sensitive information from the German capital’s administration.
Reuters reported that the group released 5.79 terabytes of stolen data after an auction for the information ended. Rhysida had set a starting price of 30 bitcoin, valued at $77,622 in the report, while Berlin had already said it would not submit to extortion.
Euronews reported that the leak encompasses approximately 1.44 million files from Berlin’s state administration, creating a sprawling dataset that authorities now have to examine for both individual privacy risks and broader security implications.
Personal and sensitive government data exposed
The scale of the leak is only one part of the problem. The information itself potentially gives criminals material that can be reused long after the original ransomware operation ends.
According to Euronews, a large amount of personal information relating to state civil servants was included in the published files. The exposed material includes birth certificates, apparent absence lists, telephone numbers and home addresses.
Indications of security-related documents, including material associated with chemical, biological, radiological and nuclear threat planning. Authorities were still working through the enormous dataset, meaning the complete scope of what had been exposed had not yet been established.
The attack affected two Berlin government departments, Reuters reported, and occurred less than a month before the city-state’s September 20 election.
Berlin creates central crisis response
The publication of the files has pushed the incident beyond intrusion containment and into large-scale breach management.
Reuters reported that Berlin established a central crisis unit to review, verify and assess the leaked data. The unit is also tasked with supporting efforts to identify and inform affected citizens and businesses.
Berlin described the incident as an extremely serious crime and an attack on the state itself, while urging people not to circulate unverified claims about the contents of the leak.
Individuals found to have been affected will be notified under German and European data-protection requirements, Reuters reported.
The breach does not end when ransomware is removed
For cybersecurity teams, Berlin illustrates the changing economics of ransomware.
Encrypting systems is no longer the attacker’s only leverage. Exfiltrating government data first allows criminals to continue applying pressure even if an organization can recover its systems without paying.
Once almost six terabytes of government information are released, incident response becomes a data-governance problem as much as a malware problem. Teams must determine what was taken, map files back to individuals and systems, reset exposed credentials and assess whether leaked information can enable phishing, fraud or further attacks.
That is especially consequential for government environments, where one breach can connect employee identities, internal documents and information concerning public services.
Berlin’s refusal to pay may have denied Rhysida its ransom. But the subsequent leak demonstrates the harder engineering lesson for public-sector security teams: recovery from ransomware does not automatically mean recovery from the breach.