The Rhysida ransomware group published data stolen from two Berlin Senate administrations after the state government refused its 30 BTC extortion demand. The group claimed to have exfiltrated 5.79 TB of material and initially offered it for auction; the released archive appears to include active file shares and mailboxes containing personnel, legal, identity, payroll, planning, certificate, credential, and infrastructure documentation. Berlin detected data exfiltration between August 7 and 12, disconnected affected departments on August 14, restored connectivity on August 23, and confirmed the public release on September 4.
Berlin has activated a central crisis unit to verify the archive, assess impacts, and notify affected citizens and businesses under German and European data-protection requirements. Officials reported no evidence that material carrying higher national-security classifications was released, but more than 1.2 million files still require review. The exposure creates sustained risks of identity fraud, targeted phishing, credential reuse, and further intrusion; the initial access vector and any political motive remain unconfirmed, with the incident currently assessed as financially motivated extortion.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
After Berlin refused payment, Rhysida made the stolen archive publicly accessible on its dark-web leak site. The listing catalogued 1,439,893 files and 5.26 TB of data, while the group claimed it had stolen 5.79 TB.
Berlin reconnected the affected departments to its network after the containment period.
Berlin disconnected the two affected departments from its network as part of containment actions following the confirmed data outflow.
Berlin confirmed that data was exfiltrated from the Senate administrations responsible for transport, climate/environment, and urban development/housing between August 7 and 12. The incident involved bulk collection of network file shares and mailboxes.
Berlin's state government launched a major review and established a central crisis unit to verify and assess the leaked material, identify affected people and businesses, and coordinate notifications. Officials reported no released material with higher national-security classifications, but continued examining more than 1.2 million files.
Rhysida demanded 30 BTC, reported as approximately €2 million, for data stolen from Berlin. Berlin publicly refused to pay the demand or the group's proposed auction price.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.