Berlin has launched an urgent review after the Rhysida ransomware group published almost six terabytes of stolen government data.
The Berlin government data leak reportedly contains around 1.44 million files, totalling 5.8TB. Officials are now assessing whether the material could endanger critical infrastructure or sensitive public bodies.
Rhysida released the files after an auction with a starting price of 30 Bitcoin ended without Berlin paying the ransom.
Officials review sensitive infrastructure information
Berlin has created an additional task force to analyse the leaked files and support the two affected Senate departments.
The city said it would immediately alert any organisation if the review finds that exposed data could place a critical facility or sensitive government body at risk.
Researchers and media outlets that reviewed portions of the material reported finding information linked to Berlin’s water supply, power plants, fuel depots, emergency power systems, substations, prisons and waterworks.
The data may also include information connected to defence companies, the Bundeswehr and Berlin’s interior administration.
Leak reportedly includes staff and government records
The Chaos Computer Club said the dataset includes sensitive information about the city’s water systems. It also reportedly contains personal information on administrative staff, including employment references and emergency plans.
Another investigation identified more than 550 files related to the expansion of Germany’s Federal Chancellery. The documents reportedly include expert assessments, plans and statements from government bodies.
Rhysida claimed it stole 5.79TB of data. The group said the material included 46,500 contracts, emails, phone numbers, passwords and classified information.
Berlin has not confirmed the full scope or authenticity of the leaked data.
Berlin refuses ransom demand
Berlin received a ransom demand but refused to pay. Governing Mayor Kai Wegner and Interior Senator Iris Spranger said the state would not be blackmailed.
The attack took place shortly before Berlin’s state election on September 20. Officials said election infrastructure has not been affected.
The city described the incident as a serious crime and an attack on the state of Berlin. It also warned people not to spread unverified claims or material circulating online while authorities continue their assessment.
CrowdStrike investigation causes internal dispute
Following the attack, Berlin hired CrowdStrike to inspect government IT systems with its Falcon security tool. The goal is to determine whether Rhysida still has access to the environment or left behind tools for persistent access.
However, Berlin’s Lichtenberg district has objected to granting CrowdStrike access to its servers.
The district said the software could receive broad access to personal data and employee devices. It also raised concerns that deployment could disrupt specialist systems and public services.
Lichtenberg said it already uses another cybersecurity product and has found no indication that its systems were compromised. The district wants the Senate to take full responsibility for costs and potential damage before it permits access.
The Senate Chancellery has reportedly told the district that the tool is the only available option and that it will cover costs and accept responsibility for any disruption.


0 responses to “1.4 Million Berlin Government Files Leaked After Rhysida Attack”