Berlin’s state government suffered a ransomware breach by Rhysida, leaking 6 TB of data after refusing a €2 million ransom.
Berlin’s state government was hit by the Rhysida ransomware gang, which leaked roughly 6 TB of confidential data after the authorities refused to pay a €2 million ransom.
The breach and its immediate fallout
According to the investigation, Rhysida gained access to multiple departmental servers in early September, encrypting files and demanding a two‑million‑euro payment. When officials declined, the attackers exfiltrated the data and posted it to a public leak site on September 15.
What was exposed
The leaked archive contains internal memos, personnel records, budget reports, and contract details from ministries handling transport, education, and public safety. No evidence suggests that critical infrastructure controls were compromised, but the exposure of personal data raises privacy concerns.
Government response
Berlin’s Senate announced an emergency cybersecurity task force, pledging to audit all affected systems and provide support to victims whose personal information was disclosed. The state also warned citizens to monitor their accounts for phishing attempts linked to the breach.
- Immediate isolation of compromised networks
- Engagement of independent forensic experts
- Public notification to affected individuals
- Review and hardening of backup and encryption policies
Legal experts note that refusing to pay does not exempt authorities from liability under EU data‑protection rules, and the breach could trigger fines if the investigation finds insufficient safeguards.
The incident underscores the growing sophistication of ransomware groups targeting government entities, prompting calls for stronger cross‑border cooperation on cybercrime.
Tech Insider coverage of Rhysida ransomware breach on Berlin government