Home WorldBerlin Cyberattack Exposes Nearly Six Terabytes of Government Data

Berlin Cyberattack Exposes Nearly Six Terabytes of Government Data

by Phoenix 24

The breach has transformed a criminal extortion attempt into a potential threat to public security.

BERLIN, GERMANY

The Rhysida ransomware group has published approximately 1.44 million files stolen from Berlin’s state administration after the government refused to pay a ransom. The leaked collection reportedly contains nearly 5.8 terabytes of information taken from two Senate departments. Berlin has created a central crisis unit to examine the material, assess the consequences and identify affected citizens, employees and businesses.

The stolen files may include more than 5,000 personnel records, payroll documents, disciplinary proceedings, passwords and access credentials. Birth certificates, private addresses, telephone numbers and employee absence lists have also reportedly appeared in the material. Authorities have not yet verified every claim or determined how much of the published information remains current and operationally sensitive.

Particular concern surrounds documents apparently connected to chemical, biological, radiological and nuclear emergency planning. Files relating to police investigations, government communications, building plans and critical infrastructure may also have been compromised. Their presence in the leak does not automatically mean that security systems can be breached, but hostile intelligence services, terrorists and criminal groups could use authentic information to identify vulnerabilities or construct convincing deception campaigns.

The attackers reportedly extracted data between August 7 and 12, while the intrusion was discovered on August 14. The precise entry point and duration of unauthorized access remain under forensic investigation. Earlier audits had identified weaknesses in parts of Berlin’s digital infrastructure, including insufficient firewall documentation and irregular updates, although authorities have not established that those deficiencies enabled this specific attack.

Rhysida demanded 30 Bitcoin, valued at approximately €2 million, and released the data after Berlin refused to pay. No verified evidence currently links the group to a foreign government, and German cybersecurity authorities consider financial extortion the most likely motive. Nevertheless, the leak occurred shortly before Berlin’s September 20 election, creating risks of phishing, manipulated documents and selective disclosures intended to generate political confusion. Officials say the election infrastructure itself has not been compromised.

Detrás de cada dato, la intención. / Behind every data point, the intention.

You may also like