ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Rhysida leaks 5.79 TB of Berlin state government data after city-state refuses 30 BTC ransom

highRansomwareimportance 84
What's new: First merged summary for this story; no prior dashboard entry exists. Across the three same-day reports, disclosure progressed from the initial leak claim (5.79 TB, 30 BTC ransom refused) to additional specifics: identification of the two affected ministries, the August 14 isolation of systems, the September 4 ransom deadline and ~EUR 2m valuation, the regulator's description of exposed personal…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

The Rhysida ransomware group published 5.79 TB (~1.44 million files) of Berlin state administration data on August 28, 2026, including CBRN emergency plans, personnel files and plaintext credentials, after Berlin refused a 30 Bitcoin (~EUR 2m) ransom; Berlin…

Berlin is investigating a ransomware data leak after the Rhysida group published stolen data from a mid-August cyberattack on two city ministries, responsible for urban development/housing and transport/climate. Rhysida claims it stole and published 5.79 TB (~1.44 million files) on its leak site on August 28, 2026; Infosecurity Magazine cites roughly 5.7 TB (~1.4M files), a rounding difference between outlets. The dump reportedly includes personal data on 12,076 individuals (Rhysida's claim; Berlin's data protection regulator and Infosecurity indicate public employees and possibly residents could be affected, potentially tens of thousands of people), over 5,000 personnel files, absence lists, payroll records, IBANs, passport data, home addresses, contracts, emails, plaintext credentials for systems including PAYONE and Z_ADMIN, and Bundesrat committee protocols. Alleged sensitive content includes national defense emergency plans, federal secret communication channels, a CBRN threat planning folder titled 'AG CBRN-Rahmenplanung', and vulnerability analyses of Berlin's water supply; the 'state secrets' claim is attributed to Rhysida and not yet independently verified. The ransom demand was 30 Bitcoin (about EUR 2m) with a September 4, 2026 deadline, which Berlin refused. Affected systems were isolated from Berlin's government network on August 14; the city has activated a central crisis unit, says there are no indications the state network remains compromised, and will notify affected individuals on a risk-based basis after forensic analysis. Germany's BSI linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware tied to financially motivated Rhysida-associated hackers. Officials say there is no evidence Berlin's September 20, 2026 election systems were affected.

  • Rhysida claimed a breach of Berlin's state administration and published 5.79 TB (~1.44 million files) on its leak site on August 28, 2026 (Security Affairs, The Record); Infosecurity Magazine cites ~5.7 TB (~1.4M files) - sources differ…
  • The attack hit two Berlin ministries in mid-August 2026: those responsible for urban development/housing and for transport/climate (The Record).
  • Affected systems were isolated from Berlin's government network on August 14, 2026 (The Record).
  • Ransom demand: 30 Bitcoin, valued at about EUR 2m by Infosecurity Magazine, with a September 4, 2026 deadline; Berlin acknowledged the demand and refused to pay (all three outlets).
  • Leak contents reportedly include PII of 12,076 individuals, IBANs, passport data, plaintext passwords for PAYONE and Z_ADMIN, over 5,000 personnel files, absence lists, payroll data, home addresses, contracts, emails, and Bundesrat…
  • Sensitive materials allegedly include national defense emergency plans, federal secret communication channels, a CBRN planning folder titled 'AG CBRN-Rahmenplanung', and vulnerability analyses of Berlin's water supply; the 'state secrets'…
  • Scale of affected people differs by source: Rhysida claims 12,076 individuals, while Infosecurity Magazine reports the data could affect tens of thousands and Berlin's data protection regulator says it includes public employees and…
  • Germany's BSI linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware used by financially motivated Rhysida-associated hackers (The Record).

Coverage timeline

  1. · 9d ago
    Security Affairs· 84
    Berlin Ransomware Leak Exposes State Secrets

    Rhysida ransomware leaked 5.79 TB of Berlin state government data on the dark web after the city refused a 30 Bitcoin ransom.