Berlin's Refused Ransom Leads to a Massive Data Dump
The Rhysida ransomware group has followed through on its threat against Berlin's government, publishing nearly six terabytes of stolen files on the dark web. The leak marks the latest chapter in a case that has been unfolding for weeks, and it offers a clear illustration of how ransomware extortion campaigns typically play out when a victim refuses to pay.
According to reporting, the attackers followed a familiar playbook: infiltrate a network, exfiltrate large volumes of data, threaten publication, demand payment, and set a countdown clock to pressure the victim into compliance. In this case, Rhysida reportedly demanded 30 Bitcoin. As vpn.social previously covered when Berlin refused the $2.3M Rhysida ransom after the 5.79TB theft was first disclosed, city officials declined to negotiate, setting the stage for the data's eventual release.
From Threat to Publication
The timeline here is worth understanding, since it mirrors a pattern seen repeatedly with ransomware groups that rely on "double extortion" tactics: stealing data first, then encrypting or threatening to leak it as separate leverage. When Rhysida first claimed the 5TB Berlin data theft, the city government publicly stated it would not pay. That refusal appears to have triggered the countdown that ultimately ended with the group dumping the files.
The scale of the leak, described as nearly six terabytes, suggests the stolen material goes well beyond a narrow set of records. Government files of this volume often include a mix of administrative documents, internal communications, and personal data belonging to employees or residents. Once material like this is published on the dark web, it becomes accessible to anyone willing to look, including other criminal actors who may use it for identity theft, phishing campaigns, or further targeted attacks against individuals named in the files.
This isn't an isolated incident for Rhysida, either. The group has claimed attacks on Berlin alongside other targets like Alumax, and ransomware crews more broadly have kept up a steady pace of attacks against government and infrastructure targets. Just as notably, Germany has reported that a growing share of its cyberattacks now trace back to state-linked actors rather than purely financially motivated criminals, a trend documented when foreign spies were found to drive 37% of cyberattacks in Germany. Whether or not Rhysida has any state connection, the broader threat landscape facing German public institutions is clearly intensifying.
Why Refusing to Pay Still Has Consequences
Berlin's decision not to pay the ransom reflects standard guidance from cybersecurity agencies and law enforcement, who generally discourage ransom payments because they fund further criminal activity and offer no guarantee that stolen data will actually be deleted. But that guidance comes with a hard trade-off: refusing to pay often means the data gets published regardless.
That's exactly what appears to have happened here. The Rhysida data leak underscores that once information is exfiltrated, the victim organization loses control over it almost entirely. Payment or no payment, the underlying exposure already occurred the moment attackers copied the files off Berlin's systems. The public leak is simply the final, most visible stage of a breach that began much earlier.
What This Means For You
If you are a Berlin resident or public employee, or if you interact with municipal services in the affected departments, there's a reasonable chance some of your personal information was included in the stolen files. The safest assumption is that any data held by an affected government office should be treated as potentially exposed.
Practical steps include monitoring your financial accounts and credit reports for unusual activity, being alert to phishing emails or calls that reference personal details that could have come from a leaked government record, and changing passwords for any accounts tied to government services if credentials were part of the exposed material. Multi-factor authentication remains one of the most effective defenses against account takeover attempts that follow large data leaks like this one.
Key Takeaways
The Rhysida ransomware leak against Berlin's government is a reminder that ransomware extortion doesn't end when a ransom goes unpaid, it often just shifts to public exposure. For residents and employees connected to the affected systems, vigilance around identity theft and phishing is the most immediate defense. For public institutions more broadly, the incident adds to a growing body of evidence that government networks remain high-value targets, and that recovery plans need to account for the reality that stolen data may end up public no matter what decision is made about payment.




