Hacker group Rhysida publishes 5.8 terabytes of Berlin authorities' data on the dark web
The criminal group Rhysida has published stolen data from Berlin's state network on the dark web after the Senate refused to pay a ransom of 30 Bitcoin.

Berlin Senate refuses to pay ransom – Rhysida places 5.8 terabytes on dark web
Around an hour after their deadline expired, the criminal hacker group Rhysida published a 5.8 terabyte data package from Berlin's state network on the dark web late Friday afternoon. This is reported by the Frankfurter Allgemeine Zeitung. The Berlin Senate had previously refused to pay the demanded ransom of 30 Bitcoin – equivalent to around two million euros.
The extortionists had activated a countdown on their leak site, which expired on Friday at around 15:35. Shortly afterwards, they announced the "auction" was over and wrote: "All files have been uploaded to the publicly accessible area – have fun browsing, data hunters!" A link initially led to an error message; around an hour later the download was actually available.
Experts support Senate's decision
The Senate's refusal to accede to the extortion demand met with broad approval in expert circles. Bianca Kastl from the Chaos Computer Club said in RBB Inforadio that the decision was correct. "If one were to keep supporting these groups with money or other things, then of course they would just keep going," Kastl said. "You have to financially starve them out."
IT security expert Christof Fischer pointed out to the German Press Agency that the state is legally prohibited from making ransom payments. However, he acknowledged that the situation is nonetheless difficult: "The data is in the hands of criminals, and publication has very harmful effects in many cases." Fischer added that he was not aware of any case in which publication took place even after payment was made. At the same time, it is to be assumed that the perpetrators – who mostly live in Eastern European countries – make the stolen data accessible to authorities there in order to buy protection from investigations.
BSI warns of hack-and-leak operations ahead of election
The Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI) classifies the threat level as elevated. A spokesman explained that the publication of stolen data could pose various risks to those affected and to society. For the political sphere, there is a particular danger of so-called hack-and-leak operations before elections, in which stolen documents or emails are published at a strategically opportune time and possibly in incorrect context. A new state parliament is being elected in Berlin on 20 September.
The BSI furthermore warned of targeted phishing attacks in the aftermath of the data breach. People who were in contact with affected persons or institutions should be particularly vigilant. Data on critical infrastructure could generate additional security risks depending on sensitivity. Those affected should check whether and to what extent their data has been published and, if necessary, adjust their processes.
Highly sensitive content: personnel files, passwords, vulnerability analyses
Previous publications of listings and screenshots by the attackers indicate that the group has, according to its own claims, stolen around 1.44 million files. These are said to include more than 5,000 personnel files, penalty proceedings and salary statements. In addition, there are confidential documents from Federal Council committees as well as vulnerability analyses of Berlin's drinking water supply. The extortionists also stated that they had obtained access credentials and passwords in plain text – among other things for databases of the administration and payment service providers.
In comparable attacks, experience shows that it often takes several hours or days before stolen data sets are actually made available for download via archive files or peer-to-peer networks. IT security experts and Berlin investigators continuously monitor the relevant forums and leak sites.
Cyber attack known since 14 August
The Berlin administration confirmed the attack on 14 August. Investigators from the State Criminal Police Office (Landeskriminalamt, LKA) and the BSI are involved in the analysis and damage remediation. The Senate Department for Urban Development, Construction and Housing and the Senate Department for Mobility, Transport, Environment and Climate Protection were disconnected from the state network for around a week as a result of the attack. For days, Berlin citizens were unable to apply for or receive housing allowance due to the cyber attack. Should the data package be fully made public, affected authorities, thousands of citizens and employees face considerable data protection and security risks.
Source: Frankfurter Allgemeine Zeitung