BERLIN’S state government confirmed that the Rhysida ransomware gang published a stolen dataset on the dark web after the threat actor refused a €2 million extortion demand equivalent to 30 bitcoins. The ultimatum expired on Friday 4 September, the government said, and Rhysida claimed access to roughly 5.7 terabytes of data. Berlin warned earlier that personal data of employees, as well as citizens and businesses, could be affected.
IT forensic experts are analysing the seized data, and authorities will contact all individuals affected once the review is complete; affected persons will be notified by the relevant Senate departments on a risk-based basis and in line with legal requirements.
The leaked material reportedly comprises about 1.4 million files, including highly sensitive state emergency plans related to terrorist threats and other disaster scenarios, in a folder named "AG CBRN-Rahmenplanung" (CBRN stands for chemical, biological, radiological and nuclear threats).
Rhysida has a history as a ransomware‑as‑a‑service operation, with prior targets including US healthcare providers and the British Library; the Berlin case adds to concerns about the group’s willingness to publish data when extortion is refused. The state emphasised there are currently no indications the state network remains compromised, but a public-interest review and notifications to affected individuals will proceed under oversight of the Berlin administration.