Hacker group Rhysida publishes 5.8 TB of Berlin administrative data on the darknet
The group Rhysida made stolen data from the Berlin state network publicly accessible on the darknet after the Senate refused to pay a ransom of two million euros.

Berlin Senate does not pay – Rhysida publishes data packages
Roughly an hour after the expiry of an ultimatum, the criminal hacker group Rhysida made approximately 5.8 terabytes of data from the Berlin state network publicly accessible on the darknet on Friday afternoon. This is reported by WELT citing a letter from the office of the State Secretary for Digitalisation and Administrative Modernisation.
The extortionists had activated a countdown on their leak site that expired at approximately 15:35. They had demanded 30 Bitcoin – equivalent to approximately two million euros. The Berlin Senate had previously stated that it would not accede to such demands in principle.
"Enjoy browsing" – data initially inaccessible
After the deadline expired, the attackers declared the "auction" on their darknet site to be concluded. "All files have been uploaded in the publicly accessible area – enjoy browsing, data hunters!", it stated. A link initially led to an error message; it was only approximately an hour later that downloading the data was actually possible.
Screenshots of the directory structure of the data leak circulated on X. WELT was initially unable to verify these. One user reported having found their own personal data within it.
Affected employees encouraged to file criminal complaints
The Berlin state government informed its employees in writing that preparations were being made "to provide advisory support to employees affected by the data breach". State Secretary Florian Hauer states in the letter: "Those affected, whose data is published, should file criminal complaints."
Investigators from the State Criminal Police Office (LKA) and the Federal Office for Information Security (BSI) have been involved in analysing and managing the incident since the cyber attack became known on 14 August.
Experts: Senate made the right decision
The decision not to pay a ransom met with approval in expert circles. Bianca Kastl from the Chaos Computer Club said in RBB Inforadio that the Senate had acted correctly. "If you continued to support these groups with money or other things, they would of course just keep going", she explained. "You have to cut off their finances."
IT security expert Christof Fischer pointed out to dpa that the state is prohibited by law from making payments in extortion cases. The situation is nevertheless difficult: "The data is in the hands of criminals, and publication has very harmful effects in many cases." To date, he is not aware of any case in which payment was made and publication did not nevertheless occur. Fischer added that the perpetrators – mostly based in Eastern European countries – may make the stolen data accessible to local authorities in order to buy protection from investigations.
Over 1.44 million files stolen – passwords in plain text
The group claims to have stolen approximately 1.44 million files. These are said to include more than 5,000 personnel records, penalty proceedings and salary statements, as well as confidential documents from federal council committees and vulnerability analyses of Berlin's drinking water supply.
Furthermore, the attackers boasted of having obtained access credentials and passwords in plain text – including for administrative databases and payment service providers. Should the data package become fully public, affected authorities, thousands of citizens and employees face considerable data protection and security risks.
Source: WELT