Berlin authorities are assessing a massive collection of government data after the Rhysida ransomware group released approximately 1.44 million stolen files on the dark web.
The publication followed Berlin’s refusal to meet the attackers’ ransom demand. Rhysida had attempted to auction roughly 5.8 terabytes of stolen information with a minimum price of 30 Bitcoin, worth around €2 million. After its deadline expired on September 4th, the group made the files publicly available through its dark web leak site.
The intrusion affected Berlin’s Senate departments responsible for urban development and housing, as well as mobility, transport, climate protection and the environment. Attackers are believed to have gained access between August 7th and 12th. Authorities discovered the incident on August 14th.
Officials are now examining the leaked material to determine whether its publication creates risks for individuals, government agencies, or critical infrastructure. Berlin has established additional teams to coordinate the analysis and respond when particularly sensitive information is identified.
Initial examinations indicate that the collection extends far beyond routine administrative documents. Reports describe files involving government employees, personnel matters, emergency plans, and other internal records.
More concerning material reportedly relates to critical infrastructure and sensitive facilities. Documents connected to Berlin’s water supply, power facilities, substations, fuel depots and emergency power systems have been identified. Information concerning prisons, defense companies and other security-sensitive organizations has also reportedly appeared in the leak.
Hundreds of documents concerning an expansion of Germany’s Federal Chancellery were found among the stolen material, including plans, assessments and statements from authorities. The full sensitivity of these records is still being evaluated.
Personal information presents another potential problem. Berlin previously warned that the stolen material could contain data belonging to government employees, residents and businesses. Authorities intend to contact identifiable individuals based on the level of risk created by the exposure.
Germany’s Federal Office for Information Security has also warned that information obtained through the breach could support targeted phishing attacks. Detailed internal documents can potentially make deceptive communications more convincing by giving attackers knowledge about organizations and individuals.
Berlin says there is currently no evidence that attackers remain inside the state network, although forensic investigations are continuing. Authorities are also investigating whether additional information may have been removed.
The incident comes shortly before Berlin’s September 20th state election. Election officials have said that, based on the information currently available, systems involved in preparing and conducting the election have not been affected.
Rhysida is considered primarily financially motivated, and German authorities have not publicly identified a political motive behind the Berlin attack. The immediate priority is now determining exactly what is contained within the nearly six terabytes of published data and whether any exposed information requires additional security measures.
