Key takeaways
- The Rhysida ransomware group has published the complete data set stolen from Berlin’s state network (Landesnetz) after the Senate refused a 30 BTC demand worth roughly €2 million. Independent scans of the dump put it at 5.79 TB and approximately 1.44 million files; the leak site’s own catalog lists 5.26 TB across 1,439,893 files.
- The material goes far beyond routine administrative paperwork: it includes more than 5,000 personnel files, health and severe-disability records, plaintext credentials for payment and administrative systems, passports and ID documents, Bundestag committee protocols with declassification correspondence, and KRITIS-relevant material such as vulnerability analyses of Berlin’s water supply.
- Berlin’s security authorities and commissioned IT forensics teams are reviewing the published data; affected individuals are to be notified on a risk basis, and citizens who spot their data in circulation have been advised to file criminal complaints.
- The exposure is not limited to Berlin. Researchers combing the dump have identified shared “best practice” documents that extend the blast radius to other German municipalities.
BERLIN — The extortion standoff between the state of Berlin and the Rhysida ransomware operation ended Friday the way security researchers feared it would: with the entire stolen corpus of the capital’s administration pushed to public access on the group’s darknet leak site, accompanied by a parting message to the criminal underground — “All files was uploaded to public access, data hunters, enjoy.”
The publication follows the expiry of a payment ultimatum set by the group after it infiltrated the Berliner Landesnetz in mid-August and exfiltrated what independent analyses now estimate at 5.79 TB of data. Berlin’s Governing Mayor Kai Wegner (CDU) confirmed last week that the state was being extorted, and Senate chancellery spokesperson Christine Richter disclosed that the attackers demanded 30 Bitcoin — approximately €2 million — while repeatedly stressing that the state would not pay. “It must be assumed that the data will subsequently be resold or published, in whole or in part,” Richter told the German press agency dpa. That assumption is now reality.
From ultimatum to full disclosure: how the leak unfolded
According to reporting by rbb, the intrusion was discovered in mid-August, when data was stolen from the network of the Berlin state administration. Once the theft became public, the attackers opened what the Senate described as a classic extortion scenario: pay, or watch the data go online. When the deadline passed on Friday afternoon, the “auction” mechanism on Rhysida’s leak site — a fixture of the group’s operation that pressures victims with a visible countdown — was terminated and replaced by the public dump. Initial links briefly returned error messages before numerous folders became visible, rbb reported, containing what appear to be employee evaluations, timesheets, recruitment and tender documents, and complete personnel files.
The Senate’s response so far is procedural but significant. Security authorities are conducting what the administration calls an “intensive data review,” with IT forensics specialists commissioned by the state examining the published material. Where individual affected persons can be identified, they are to be informed by the responsible Senate departments on a risk basis and in line with statutory requirements. Citizens who believe their data has been published or misused have been advised to file criminal complaints. The Senate has also characterized the attackers as a highly professional group linked to multiple cyberattacks across northern and southern Europe, Germany and the United States, adding that while there is no evidence of a connection to the Russian state, such a link “cannot be ruled out.”
Inside the dump: a category-by-category breakdown of 5.8 TB
The scale of the compromise becomes clearer when the dump is broken down by content category. Independent scanning of roughly 1.44 million files yields the following distribution:
| Category | Files |
|---|---|
| Maps / geodata | 124,823 |
| Legal / complaints | 77,939 |
| Financial | 55,553 |
| Contracts | 46,522 |
| Human resources | 27,299 |
| Government supervisory | 13,142 |
| Confidential | 11,777 |
| Infrastructure | 8,110 |
| Passwords | 5,941 |
| Health | 2,738 |
| Contacts | 2,287 |
Layered on top of those categories is a substantial personally identifiable information (PII) harvest: 16,389 email addresses, 11,963 phone numbers, records relating to 12,076 individuals, and 148 IBANs. Joachim Selzer, spokesperson for the Chaos Computer Club (CCC), told dpa that what he was seeing ranged from construction matters, emergency plans and application files to timesheets, employee reintegration measures and works council documents — “a lot of small things that could be interesting for identity theft.”
Two details in the metadata deserve special attention from a defensive standpoint. First, the leak site does not merely host raw archives; it presents a categorized “data catalog” with thumbnails and part-wise document bundles (Documents parts 1–3), which effectively performs the victims’ adversaries’ reconnaissance for them. Second, the discrepancy between the 5.79 TB measured by independent scanners and the 5.26 TB advertised in the site’s catalog suggests the operators curated or re-packaged the corpus before publication — a reminder that what is publicly indexed may not be identical to what was actually exfiltrated.

Plaintext credentials and a payment database: the part that should worry everyone
Among the most damaging findings in the dump are authentication secrets that were never protected in transit or at rest. The leaked material reportedly includes credentials stored in plaintext for the GebäudeAtlas building database, the ePayment PAYONE payment database used for citizen-facing transactions, personal “password safes” of individual users, Z_ADMIN database accounts, and leadership credentials. A dedicated “Passwords” category alone contains 5,941 files.
From an architectural perspective, this is the signature of an environment with no enterprise secret management, no enforced multi-factor authentication on privileged accounts, and no data loss prevention (DLP) controls capable of flagging credential material leaving the network. The downstream consequences are predictable and severe: account takeover against administrative systems, business email compromise chains seeded with real internal correspondence, payment fraud against the exposed IBANs, and highly convincing spear-phishing built on authentic personnel and legal documents. Compounding the problem, the dump contains Outlook PST archives and Postbuch SQL dumps spanning 2020–2026, Convotis payroll data, and more than 5,000 Ordnungswidrigkeiten (administrative offence) files — in other words, machine-readable bulk records rather than only unstructured documents, which dramatically lowers the effort required to weaponize them.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Civil protection files, CBRN planning and KRITIS assessments
The portion of the dump that elevates this incident from a privacy catastrophe to a physical-security concern is the civil protection (KatSchutz) material. Directory listings reviewed by researchers show a folder structure including working groups on CBRN framework planning (AG CBRN-Rahmenplanung) and critical infrastructure (AG KRITIS), coordination records with the Berlin Fire Department, fire service plans (Fw-Pläne), situation newsletters (Lagebild), on-call rosters (Rufbereitschaft), external emergency plans referencing the KatWarn and NINA warning apps, briefings on the federal modular warning system MoWaS in situation duty, internal instructions on preventive fire and hazard protection, and expert reports on industrial accident (Störfall) cases tied to immission-control licensing procedures.
Read individually, each document is bureaucratic routine. Read together, they constitute a near-complete picture of how Berlin plans for, warns about and responds to crises — including chemical, biological, radiological and nuclear scenarios — and where the seams in that planning are. The same logic applies to the reported vulnerability analyses of Berlin’s water supply, a classic KRITIS sector: publishing them is functionally equivalent to handing a sabotage-minded actor a site survey. On-call rosters and named protocols additionally create a ready-made social engineering directory for anyone who wants to impersonate duty personnel during a future incident.
Classified correspondence, personnel dossiers and the federal ripple effect
Equally sensitive is the material touching Germany’s classified information regime. The dump reportedly contains Bundesrat/Bundestag committee protocols with declassification correspondence, documents from the Geheimschutz (classified material handling) process, personnel files marked at the VS-Vertraulich level, recent passport and ID documents drawn from personnel files, and deeply private leadership data including IBANs, ID cards and at least one bank card. Ongoing disciplinary and litigation files appear as well — including the “ANDERSON” bundle (432 files, 2025–2026) connected to proceedings at the Berlin Administrative Court, a politically motivated misconduct case involving the LKA Staatsschutz, and forestry-related cases — alongside 3,226 NDA documents.
This is the dimension that will keep federal authorities occupied for weeks. Once committee protocols and declassification correspondence leave the controlled environment, the damage is not limited to Berlin; it implicates trust in inter-governmental information sharing at the federal level. Independent researcher KaterX (@DerKaterX), who has been reviewing the dump in detail, summarized it bluntly: personnel data, private contact details, individual personnel files including information on severely disabled employees, “defense-relevant materials,” protocols naming vulnerabilities and responsible individuals, and guidelines for secure communication. “Berlin is naked,” the researcher wrote, adding — in a detail that broadens the incident’s scope — that other cities are affected because shared best-practice materials are neatly filed in the same trees.
Rhysida: a repeat offender with a proven extortion playbook
Rhysida first surfaced in 2023 and quickly built a reputation for targeting healthcare and public-sector victims, most notoriously the Centro Hospitalar Universitário de Lisboa in Portugal and the Vatican, whose stolen documents the group attempted to monetize through a public “auction” — the same pressure mechanism now seen in Berlin. Joint advisories from CISA and the FBI describe the group’s playbook as phishing-driven initial access, abuse of valid accounts and remote desktop tooling such as AnyDesk for lateral movement and exfiltration, heavy reliance on built-in Windows utilities, and data theft completed before ransomware deployment.
The Berlin operation fits the broader industry shift toward pure data extortion, in which attackers skip disruptive encryption entirely and monetize the threat of publication alone. For a government network, this model is in some ways worse than encryption: there is no operational outage to force a response, no ransomware binary to analyze, and the victim’s incentive to pay is purely reputational and legal — incentives a state that has publicly committed to not negotiating can, as Berlin did, decide to resist.
“Criminals would have to sift through it first” — a risk model that doesn’t survive contact with AI
Several commentators have downplayed the severity of the leak on the grounds that the sheer volume of data — multiple terabytes, split into archives that take days merely to download — means adversaries must first sift through it to find anything useful. That argument was already weak when the corpus was unstructured; in the age of large language models it is obsolete. Entity extraction, classification and PII harvesting over a few terabytes of mostly text-based office documents, PDFs and SQL dumps is a commodity pipeline that a moderately resourced actor can run in hours, not months. The leak site’s own categorized catalog further collapses the sifting argument: the criminals have already indexed their loot.
The realistic threat chain is therefore not a single dramatic exploit but a long tail of low-effort, high-yield abuse: identity theft assembled from “administrative small stuff,” targeted smishing and vishing campaigns referencing authentic case numbers and employee names, fraud against the exposed IBANs and payroll records, and secondary extortion of individuals whose personnel files contain health or disability data — information that falls under the strictest protections of European privacy law precisely because its misuse can be life-destroying.
The legal fallout: GDPR Articles 9, 32 and 33, the BSI Act and classified-material law
The legal exposure radiates in several directions at once. Under the GDPR, the health and disability records in the dump implicate Article 9’s special-category data regime; the plaintext credentials and absent protective controls raise direct questions under Article 32 (security of processing); and the notification clockwork of Articles 33 and 34 — supervisory authority notification within 72 hours and communication to data subjects where high risk is likely — will be scrutinized for every identified affected person. Affected individuals also hold a damages claim route under Article 82, which, multiplied by more than twelve thousand identified individuals, is a non-trivial liability horizon.
On the national side, the picture is no gentler. The BSI Act (BSIG), including the NIS2-derived obligations now binding on public-sector entities, sets incident-reporting and security baselines that this incident will test in public view; the water-supply analyses bring KRITIS regulation directly into scope. And if the VS classification of the exposed material is formally confirmed, Germany’s classified-material framework (VSA) and criminal provisions on the violation of official secrets (§ 353b StGB) enter the equation, which is why the Senate’s careful phrasing — “insofar as individual affected persons are identified” — is doing so much work. Expect parliamentary pressure, and likely calls for a committee of inquiry, to follow in the coming weeks.
If you live in Berlin: what to do now
For ordinary residents, the risk is not that your laptop was hacked — it is that stolen administrative data makes you a better target. The Senate’s own guidance is the right starting point: file a criminal complaint (Strafanzeige) if you see concrete evidence your data is being misused. Beyond that, a few disciplined habits cover most of the realistic attack surface. Treat any unsolicited call, SMS or email referencing Berlin authorities, case numbers, fines or personnel matters as hostile by default — genuine authorities never demand payments, passwords or TANs by phone. If you know you appear in administrative, personnel or offence files, watch your bank statements and consider checking your Schufa self-disclosure for accounts or credits you did not open. Change any password you ever used on a public-sector portal if you reused it elsewhere, and enable multi-factor authentication on your email and banking first. Finally, watch for the slow indicators of identity fraud: unexpected dunning letters, invoices for goods you never ordered, or a suddenly declined credit application.
The accountability question
The most bitter commentary circulating in Germany’s security community is not about the attackers but about the defenders. As KaterX put it, this is what happens when responsible officials do not take secret-protection and sabotage-protection seriously and skip “the simplest BSI standards because they cost money to implement” — a reference to the BSI IT-Grundschutz baseline that remains optional in practice for much of the public sector. The uncomfortable precedent, too, is familiar: when the Anhalt-Bitterfeld district declared a formal state of disaster after its 2021 ransomware infection, the political consequences were similarly muted.
The structural fixes are well known and unglamorous: enforced secrets management and MFA for privileged and service accounts, DLP and egress filtering on the Landesnetz, immutable and offline backups, regular Grundschutz audits, KRITIS resilience exercises, and retained incident-response capability before the incident, not after. Whether this breach — one of the most consequential government compromises anywhere in the world to date — finally converts those controls from budget-line debates into obligations is the real test. The data is public, the countdown is over, and the bill for decades of deferred security hygiene has arrived. It will be paid by Berlin’s citizens, in phishing inboxes, fraud alerts and compromised identities, for years.
FAQ
How much data did Rhysida leak from Berlin?
Independent scans put the dump at 5.79 TB and roughly 1.44 million files; the leak site’s catalog advertises 5.26 TB across 1,439,893 files, published in three document bundles.
Did Berlin pay the ransom?
No. The Senate repeatedly stated it would not negotiate with the extortionists, who had demanded 30 Bitcoin (about €2 million). After the Friday deadline expired, Rhysida ended its “auction” and published everything.
What kind of data was exposed?
Personnel files (5,000+), health and severe-disability records, plaintext credentials including a PAYONE ePayment database and admin accounts, passports and IDs, IBANs, legal and disciplinary files, Bundestag committee protocols with declassification correspondence, CBRN and civil-protection planning documents, and KRITIS-relevant vulnerability analyses of the water supply.
Who is behind the attack?
The Rhysida ransomware group, active since 2023 and previously linked to attacks on hospitals in Portugal and the Vatican. The Berlin Senate describes it as highly professional with operations across Europe and the U.S.; a Russian state connection is neither confirmed nor excluded.
I live in Berlin — am I at risk?
If your data touched the administration, expect a long tail of targeted phishing and potential identity fraud. File a criminal complaint if misuse appears, monitor accounts and credit records, never share passwords or TANs by phone, and rotate reused credentials with MFA enabled.
This is a developing story. Figures are drawn from independent scans of the leak site and official statements and may be revised as the Senate’s forensic review progresses. In line with responsible reporting standards, we do not link to criminal infrastructure or reproduce the leaked material.









