Berlin’s state government is facing a major data breach after the Rhysida ransomware group released around 5.7 terabytes of stolen government data following the city’s refusal to pay a 30 Bitcoin ransom. The leaked material is being examined for sensitive information involving public employees, residents and businesses.
According to Reuters, the hackers had demanded 30 Bitcoin, then offered the stolen data for auction before publishing it after the deadline expired. The group had claimed it had obtained emails, phone numbers, passwords, contracts and other sensitive material from Berlin’s state administration.
Berlin officials had rejected the ransom demand, saying the city would not give in to extortion. The group subsequently began releasing the stolen material online, prompting the government to launch an emergency response to assess what information had been exposed.
The breach affected two Senate departments, including those responsible for urban development, housing, mobility, transport and environmental affairs. Authorities have been working to determine whether personal information was among the stolen files and what risks the disclosure could create.
The situation worsened on September 6 when attackers released another package of data. Berlin said the latest material included access credentials, prompting officials to strengthen security measures in the affected administration. Some government digital services could face temporary restrictions as a result.
The city had warned before the initial release that the stolen material could include personal data belonging to government employees, citizens and companies. Officials have since begun examining the published files to identify people and organisations potentially affected.
The attack has also raised concerns about the security of Berlin’s wider government network. The city has created a central coordination unit to manage the response and is working with investigators and cybersecurity specialists to establish the full extent of the breach.
The incident comes less than a month before Berlin’s state election, scheduled for September 20. Officials have said the systems used to support the election were separate from the compromised network and were not affected by the attack.
Rhysida has previously targeted government bodies and other major organisations. The group emerged in 2023 and has been linked to ransomware attacks in several countries.
Berlin now faces the difficult task of identifying the leaked information, protecting potentially affected people and restoring confidence in its digital infrastructure. The investigation remains ongoing, and officials have yet to establish the full consequences of the data exposure.
Click Here For The Original Source.
