Washington | 22°C (clear sky)
Berlin's Digital Standoff: When Hackers Demanded 30 Bitcoin and a City Stood Firm, Triggering a Massive Data Dump

Berlin Government Defies Ransomware Gang Rhysida, Faces Aftermath of 6TB Data Leak

A brazen cyberattack by the Rhysida group on Berlin's state government escalated dramatically when officials refused to pay a 30 Bitcoin ransom. The decision led to a colossal dump of 6 terabytes of highly sensitive data, exposing everything from personal details to national defense plans. It's a stark look at the high stakes in the fight against digital extortion.

Imagine, for a moment, being the target of an audacious digital heist. That’s precisely what happened to the city of Berlin, Germany, when a notorious ransomware group known as Rhysida came knocking, or rather, hacking. Their demand? A cool 30 Bitcoin – a sum that, at the time, hovered around €2 million or roughly $2.3 million. It was a classic digital shakedown, but Berlin, to its credit, refused to blink.

The whole saga unfolded rapidly. It seems the hackers had been quietly siphoning off data from Berlin’s state government systems for a good while, specifically between August 7th and 12th. Authorities caught wind of the leak by August 14th, but it wasn't until August 28th that Rhysida officially claimed responsibility, making their hefty ransom demand public. Fast forward a little, around September 5th to 7th, and when Berlin didn't cave, the digital floodgates opened. The hackers began a continuous release of approximately 5.7 to 6 terabytes of stolen data – a truly staggering amount, roughly 1.44 million files, just dumped onto the dark web for all to see.

This wasn't some minor inconvenience. We're talking about deeply embedded government operations here. The attack specifically targeted two key Senate departments: those overseeing urban development, housing, mobility, transport, and environmental affairs. Think about it – the very gears of a major European capital. Berlin’s Governing Mayor, Kai Wegner, minced no words, stating unequivocally, “The state of Berlin will not allow itself to be blackmailed.” Interior Senator Iris Spranger stood alongside him, briefing a worried public. Their message was clear: no negotiation with cybercriminals.

But the refusal came with a heavy price. The subsequent data dump was, frankly, terrifying in its scope and sensitivity. Investigative journalist Lars Winkelsdorf was among the first to report on the sheer scale of the compromise. Leaked information allegedly included personal data for over 12,000 individuals – their names, 16,000 email addresses, nearly 12,000 phone numbers, even bank details (148 IBANs). Beyond that, birth certificates, absence lists, home addresses, and over 5,000 personnel files were reportedly exposed. It’s the kind of information that makes your stomach drop, knowing it could affect so many ordinary lives.

And it didn't stop at personal details. The hackers also claimed to have released a treasure trove of highly sensitive administrative and governmental records. Over 5,000 administrative-offence files, more than 46,500 contracts, internal leadership information, police investigation reports – yes, police reports – national defense plans, government crisis communications, and even emergency plans for defense-oriented firms. Documents pertaining to critical infrastructure and judicial matters were apparently also part of the haul. Perhaps most chillingly, plaintext passwords and login credentials for various government systems, including internal databases like GebäudAtlas, ePayment PAYONE, and Z_ADMIN accounts, were supposedly among the leaked files. Just imagine the potential for further exploitation.

In response, Berlin immediately launched an emergency operation, trying to get a handle on what exactly was exposed. Initially, there was a glimmer of hope that only publicly accessible data had been compromised, but that assessment quickly reversed. It became painfully clear that non-public, deeply sensitive information was indeed out there. The Berlin State Criminal Police Office and prosecutors swiftly launched an investigation to identify and bring the responsible group to justice. While some government digital services might face temporary restrictions as a result, officials were quick to reassure everyone that systems supporting Berlin's September 20th state election remained isolated and unaffected – a small comfort amidst a huge crisis.

Of course, the exact breadth of the damage is still being assessed. Berlin authorities haven’t independently verified every single claim made by Rhysida regarding the specific amount of data or the full list of compromised records. Nor have they confirmed Rhysida's accusations of violations against GDPR, German classified-information rules, or other critical regulations. What’s undeniable, however, is that this incident serves as a stark, unsettling reminder of the persistent and evolving threat of ransomware attacks against public institutions. It underscores the monumental challenge governments face in protecting citizens' data and critical infrastructure in an increasingly digital, and dangerous, world.

Comments 0
Please login to post a comment. Login
No approved comments yet.

Editorial note: Nishadil may use AI assistance for news drafting and formatting. Readers can report issues from this page, and material corrections are reviewed under our editorial standards.