Hackers leak 1.4 million Berlin administration files to darknet after ransom refusal

This digest was compiled by AI from multiple sources — links to the originals are below.
The Rhysida hacking group published nearly six terabytes of Berlin state administration data on the darknet, including 1,439,893 files. The leak followed Berlin's refusal to pay a 30-bitcoin ransom, about two million euros, after the group's countdown expired Friday around 15:35. The published data includes a folder on CBRN emergency planning and personal records of state employees.
Key Facts
- The Rhysida group published 1,439,893 files, nearly six terabytes, from the Berlin state administration on the darknet.
- The hackers had demanded a ransom of 30 bitcoins, about two million euros, and set a countdown that expired Friday around 15:35.
- The leaked data includes a folder named 'AG CBRN-Rahmenplanung' containing planning for chemical, biological, radiological, and nuclear emergency scenarios.
- Berlin Mayor Kai Wegner stated the city would not give in to blackmail.
- The same group previously attacked the British Library, the German aid organization Welthungerhilfe, and the Stuttgart city administration, according to Der Spiegel.
The Leak
The Rhysida hacking group published nearly six terabytes of data from the Berlin state administration on the darknet, totaling 1,439,893 files. The publication followed the expiration of the group's countdown on Friday around 15:35, after Berlin authorities refused to pay the demanded ransom of 30 bitcoins, approximately two million euros. The Berlin Senate had signaled before the ultimatum expired that it does not comply with such demands and ignored the blackmail. Shortly after the countdown ended, the massive data set was published on the darknet, and group members began distributing file name lists on social media.
Sensitive Content
Among the published documents is a folder titled 'AG CBRN-Rahmenplanung', where CBRN stands for chemical, biological, radiological, and nuclear threats. Investigative journalist Lars Winkelsdorf warned on X that the cyberattack reached a 'state-threatening scale', noting that materials include plans for a defense situation, including secret communication channels of the federal government for doomsday scenarios. The leaked data also contains numerous personal records, primarily of state agency employees, including birth certificates, absence lists, phone numbers, and home addresses. According to RBB, the exposed materials may include employment documents, employee evaluations, and tender-related data.
Group Profile
The Berlin Senate described the group as highly professional and linked to various cyberattacks on targets in Northern and Southern Europe, Germany, and the United States in recent years. Der Spiegel reported that the same group previously attacked the British Library, the German humanitarian organization Welthungerhilfe, and the Stuttgart city administration. Berlin Mayor Kai Wegner stated that the city would not give in to blackmail.