Ransomware Group Leaks Berlin State Files After Refusal to Pay Bitcoin Demand
AI-generated from multiple sources. Verify before acting on this reporting.
BERLIN — The Rhysida ransomware group has published nearly six terabytes of sensitive state administration files from Berlin on the dark web, marking a significant escalation in a cyberattack that began earlier this year. The data dump occurred after German authorities refused to meet the gang's demand for 30 Bitcoin in ransom payments.
The release of the documents, which includes internal communications and administrative records, was made public on Monday morning. Rhysida announced the leak following a deadline set during negotiations with Berlin officials. The group stated that the decision to publish the data was a direct consequence of the city's refusal to comply with the financial demands.
Berlin state administration officials confirmed the breach but declined to comment on the specific contents of the leaked files or the extent of the potential damage to public services. The incident represents one of the largest data exfiltrations targeting a German municipal government in recent years. The 30 Bitcoin demand, equivalent to millions of dollars at current market rates, was rejected by authorities who have consistently maintained a policy against paying ransoms to cybercriminals.
Cybersecurity experts warn that the exposure of such a vast amount of data could compromise personal information belonging to residents and sensitive operational details of city departments. The files reportedly cover various sectors of Berlin's administration, though officials have not yet specified which departments were most heavily affected or if critical infrastructure data was included in the leak.
The attack on Berlin follows a pattern of increasing aggression by Rhysida, a group known for targeting government entities and large corporations across Europe. In previous operations, the group has threatened to release stolen data if ransoms are not paid within strict timeframes. The refusal to pay in this instance appears to have triggered the full-scale leak as a punitive measure.
German federal prosecutors have launched an investigation into the incident. Authorities are working with international partners to trace the digital footprint of the Rhysida group and identify the individuals behind the attack. However, the decentralized nature of ransomware operations often complicates such efforts, and no arrests have been announced in connection with this specific breach.
Questions remain regarding the long-term impact of the data leak on Berlin's administrative functions and public trust. Officials are currently assessing whether any compromised data requires immediate remediation or notification to affected individuals. As the investigation continues, cybersecurity firms are monitoring the dark web for further releases or attempts to sell additional stolen information from the Berlin administration.
The incident underscores the growing challenge faced by government bodies in balancing the risks of paying ransoms against the potential fallout of public data exposure. With no immediate resolution in sight, Berlin officials face the difficult task of managing the aftermath of the leak while strengthening defenses against future cyber threats.