Rhysida Ransomware Hits Berlin With a 30 Bitcoin Demand

A new ransomware claim tied to Berlin has put the Rhysida group back in the spotlight. According to reporting on the incident, Rhysida is demanding 30 bitcoin, worth well over a million dollars at current exchange rates, in exchange for not leaking 5.79TB of data the group says it obtained. That is an enormous volume of information, and it raises the same question every major ransomware case does: what happens to the people whose personal data is sitting inside those stolen files?

Rhysida is not a new name in the ransomware world. The group runs on a ransomware-as-a-service model, meaning it leases its malware and infrastructure to affiliates who carry out the actual break-ins. This structure has made Rhysida one of the more prolific extortion operations tracked by government cybersecurity agencies, and it explains why the group's victim list keeps growing across different sectors and regions. As covered in our report on Rhysida and Akira's claims against Berlin and Alumax, Rhysida rarely operates in isolation. Multiple ransomware crews are often active at once, sometimes targeting the same regions or industries within days of each other.

Why the Data Volume Matters More Than the Ransom

Headlines about ransomware attacks tend to focus on the dollar figure of the ransom demand, but the more important number here is 5.79TB. That kind of data haul typically includes far more than internal business records. Depending on what systems were compromised, it can mean employee records, resident or citizen data, financial documents, contracts, and communications, all of which can contain personal information belonging to people who had no role in the security decisions that led to the breach.

This is the core privacy risk of double-extortion ransomware like Rhysida's. The group does not just encrypt files to disrupt operations. It steals copies of the data first, then threatens to publish it publicly if the ransom is not paid. Even if a victim organization has strong backups and can restore its systems without paying, the stolen data can still be leaked or sold. That means the privacy exposure exists independently of whether the ransom gets paid at all.

Government agencies that track Rhysida have published indicators of compromise and technique breakdowns to help defenders spot the group's activity before it escalates to encryption and data theft. These advisories describe patterns Rhysida affiliates commonly rely on, including exploiting exposed remote access points and using legitimate administrative tools to move through a network quietly before deploying ransomware. The value of these indicators is that they give security teams a chance to catch an intrusion in its early stages, well before terabytes of data have already left the network.

What This Means For You

If you are not an IT administrator, you might assume a ransomware attack on a city government or a company has little to do with you. That is rarely true. If Berlin's systems held any data connected to residents, employees, contractors, or partner organizations, that information could now be at risk of exposure regardless of whether officials negotiate with Rhysida.

The practical advice for anyone potentially affected by a breach like this is the same regardless of which ransomware group is involved. Watch for official notifications from the organization involved, since breach disclosure laws in most jurisdictions require affected parties to be informed. Treat any unexpected emails, calls, or texts referencing the incident with suspicion, since attackers and opportunistic scammers often use leaked data or public breach news to run follow-up phishing campaigns. If you have accounts or records with the affected organization, consider changing passwords, enabling multi-factor authentication where available, and monitoring for signs of identity theft such as new accounts opened in your name.

Reducing Your Exposure to Ransomware Fallout

Organizations bear the primary responsibility for defending against groups like Rhysida, and the published indicators of compromise exist specifically to help security teams close the gaps these affiliates exploit. But individuals are not powerless bystanders either. Being cautious about where you share personal data, using unique passwords across services, and keeping an eye on credit or account activity after a known breach can meaningfully reduce the damage when an incident like the Berlin case eventually touches your own information.

Ransomware groups like Rhysida thrive on speed and scale, hitting many targets and hoping enough of them pay to make the operation profitable. Staying informed about active campaigns, understanding what a double-extortion demand actually means for stolen data, and taking basic protective steps after a breach notification are the most realistic ways to limit your exposure. As Rhysida's activity continues into 2026, expect more claims like the one against Berlin, and expect the same privacy questions to follow each one.