Rhysida Follows Through on Its Threat
The cyber-extortion group Rhysida has published terabytes of data stolen from the administration that runs the German state of Berlin, much of it described as sensitive. The leak marks the culmination of a standoff that began weeks earlier, when the group breached Berlin's government systems and demanded payment in exchange for keeping the stolen files private.
Berlin officials had already signaled they would not give in to the demand. As covered in our earlier report on Berlin's refusal of a roughly 30 Bitcoin ransom, the city's government made clear it did not intend to negotiate with the attackers, a stance consistent with guidance from cybersecurity agencies that paying ransoms often does little to guarantee data won't still be leaked or sold.
That refusal set the stage for Rhysida to act on its threat. According to our coverage of the moment Berlin's data was dumped following the €2 million ransom refusal, the group made good on its promise once it became clear payment wasn't coming. The latest reporting confirms that the leaked trove is substantial, spanning terabytes of files pulled from Berlin's administrative systems.
Berlin's Crisis Response
Following the leak, Berlin's state government has launched a review of the exposed material, an effort officials describe as urgent given the volume and sensitivity of what was taken. The scale of a breach like this makes verification a slow process: administrations typically need to sift through enormous data sets to determine exactly what categories of information were exposed, whether that includes personal records, credentials, financial details, or internal communications, before they can meaningfully warn the people affected.
This pattern isn't new for Berlin. The city had already gone through a public standoff with the attackers once before, detailed in our piece on how Berlin refused the ransom and hackers moved to auction the stolen data. That episode showed the extortion group escalating its tactics step by step: first a ransom demand, then threats to sell the data, and now a full public leak. Ransomware and extortion groups frequently follow this playbook, using each stage as additional pressure to force a payout, even when the target has already stated it won't pay.
Why This Matters Beyond Berlin
Attacks on city and state governments carry a different weight than breaches at private companies. Government administrations hold records tied to residency, benefits, licensing, and other services that citizens can't simply opt out of. When that data ends up published on extortion sites, it isn't just the government that bears the consequences. Residents whose information was stored in these systems may find themselves at risk of identity theft, phishing attempts, or fraud carried out using details lifted from the leak.
The involvement of a group like Rhysida, which has targeted a range of public and private sector victims in the past, also underscores a broader trend: extortion groups are increasingly willing to publish stolen data in full rather than simply threatening to, especially when the target refuses to pay. That shift changes the calculus for governments and organizations weighing how to respond to a breach, since standing firm on a ransom no longer guarantees the data stays contained.
What This Means For You
If you live, work, or have interacted with Berlin's state administration, this Berlin data leak is worth paying attention to, even from outside Germany. Large-scale government breaches like this one tend to expose a wide mix of personal information, and it can take time for authorities to confirm exactly whose data was included. In the meantime, it's reasonable to assume that anyone who has submitted personal records to a government body affected by a breach could be impacted, and to act accordingly.
That means watching for unusual account activity, being cautious of unexpected emails or calls referencing government services, and treating any communication asking for personal or financial details with skepticism until it can be verified through official channels.
Actionable Takeaways
- Monitor official Berlin government communications for updates on which specific records or personal data categories were exposed in the leak.
- Be alert to phishing attempts that may reference this breach or impersonate Berlin's administration in the weeks following the leak.
- Consider placing fraud alerts or monitoring your credit and identity if you have direct ties to Berlin's government systems.
- Use unique, strong passwords for any accounts tied to government services, and enable two-factor authentication where it's offered.
This story is still developing as Berlin's government works through the scope of what Rhysida published. As with past extortion incidents, the full picture of who was affected and how may take weeks to emerge, so staying informed through verified updates remains the best defense for anyone with ties to the affected systems.




