Berlin government data leak after ransomware attack
The Rhysida ransomware gang stole 6TB of Berlin's state administration and defense files after the city refused to pay a $1.2 million ransom. The leaked data includes personal records, payroll details, and system passwords for government systems.
- Report priority
- High
- Group
- Berlin government data leak after
What is known
- The attacker used ransomware to encrypt Berlin's internal files.
- When the city refused to pay the $1.2 million ransom, the attacker published the stolen data on the dark web instead.
- The leak includes personal records, payroll files, and system credentials for government systems.
What to do
If you live in Berlin or worked for the city government, check if your personal data (name, email, phone, or bank details) appears in the leaked files. The attacker claims to have exposed 12,076 individuals' records, but no public list has been verified. Contact Berlin's privacy office for confirmation if you suspect your data was included.
For help, contact Berlin's privacy office or report suspicious activity to local authorities.
Claim from the attackers
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom.
At the end of August, Berlin’s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included. Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files.
The alleged dataset includes: Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs. Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information. Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols. Classified information: data related to classified-material handling and documents allegedly containing state secrets. Critical infrastructure: vulnerability analyses concerning Berlin’s water supply. Identity documents: passports and ID cards from personnel records.
Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives. The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.
The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.
Reported details
The attacker posted a dark web page titled 'Berlin, Germany' listing 1.44 million files, including 12,076 individuals' personal data, 5,000+ personnel files, and plaintext passwords for government systems.