Berlin Said No to the Hackers — Then 5.8 Terabytes of Its Files Hit the Dark Web

AI customer support

Never lose a customer to a missed message

An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.

Try it free →replio.live

Hackers published roughly 5.8 terabytes of data stolen from Berlin’s state government on August 28, 2026. City officials had refused to pay a ransom demand that expired that day. The Berlin ransomware city attack exposed more than 5,000 personnel files and payslips. It also exposed fine proceedings, confidential parliamentary committee documents, and vulnerability analyses of Berlin’s drinking water supply, according to Help Net Security.

The Rhysida ransomware group claimed responsibility for the attack. It is believed to operate out of Russia and eastern Europe. The group had demanded 30 bitcoin, worth roughly €2 million ($2.3 million), according to The Hacker News. The same group previously hit the British Museum.

Rhysida follows a clear pattern across its attacks. It breaches a target’s network first. Then it pulls out as much data as it can before detection, and threatens public release on a deadline to force payment. The tactic works because it shifts the cost for victims. A private ransom negotiation becomes a public data-exposure event, carrying reputational and legal consequences well beyond the ransom itself. Berlin’s refusal echoes a stance other European public-sector victims have taken this year. Government bodies increasingly treat paying ransoms as rewarding the tactic rather than resolving it.

How the Berlin ransomware city attack unfolded

The initial data leak happened between August 7 and 12. Affected Berlin departments were not disconnected from the state network until August 14. That gap, roughly seven days, gave the attackers extended access to internal systems. Some of the city’s online services shut down as a direct result, disrupting routine government functions while the network was isolated.

Berlin’s state executive said, as a matter of principle, it would not give in to extortion. It held that position through the deadline. When the deadline passed without payment, Rhysida released the stolen files publicly instead of continuing to hold them privately. That is a common escalation tactic once ransomware negotiations fail.

What was actually exposed

Berlin government building affected by the Berlin ransomware city attack

The released package included about 1.44 million files. Beyond personnel records and payslips, the leak reportedly held confidential parliamentary committee documents. It also held technical vulnerability analyses of the city’s drinking-water infrastructure. That raises concerns beyond privacy, reaching into potential physical infrastructure risk. City officials have not detailed how many residents or employees the personnel-file exposure affects.

Why the seven-day delay matters

Security researchers flag the week-long gap between the initial breach and full network isolation as a critical failure point. It gave Rhysida extra time to locate and extract sensitive files before Berlin cut off access. Ransomware response plans generally call for near-immediate isolation once a breach is detected. The delay will likely be a focus of any post-incident review.

Simple to send.
Safe to verify.

OTPs over WhatsApp, one API call away

Try it free →replio.live

What happens next for Berlin

Berlin’s government has not announced a timeline for restoring all affected online services. It also has not said when it will notify individuals whose personnel data appeared in the leak. Cybersecurity researchers continue analyzing the released files to map the full scope of exposure. That includes checking whether the drinking-water vulnerability data poses an ongoing risk needing separate remediation.

The incident lands amid a broader pattern of ransomware attacks on European public-sector targets this year. City and regional governments prove attractive because they often run older IT systems alongside genuinely sensitive records. Berlin’s stance against paying mirrors guidance from several national cybersecurity agencies across Europe. Those agencies generally discourage ransom payments, arguing they fund further attacks without guaranteeing stolen data is actually deleted. Employees whose personnel files appeared in the leak have limited recourse beyond monitoring for identity theft. The files are already public on the dark web and cannot be recalled.

Berlin’s experience is likely to influence how other German states approach network segmentation going forward. Security consultants typically recommend isolating a breached department immediately, not after a week’s delay. Whether Berlin implements that change before facing another attempt remains an open question the city has not yet addressed publicly.

The 5.8 terabyte figure places this among the larger public-sector leaks reported in Europe this year. Full comparisons are difficult, since not every victim discloses how much was taken. Journalists and researchers with leak-monitoring tools have begun cataloguing the exposed files. That process typically takes weeks, given the sheer volume involved. Standard practice after a leak like this is to watch for phishing attempts referencing personal details only a leaked file would contain. Stolen data is frequently reused in follow-on scams.

Frequently asked questions

What happened in the Berlin ransomware attack?
Hackers linked to the Rhysida group breached Berlin’s state government network in early August 2026 and stole data. They published about 5.8 terabytes of it after the city refused to pay a ransom.

How much ransom did the hackers demand?
Roughly 30 bitcoin, worth about €2 million ($2.3 million).

What data was exposed?
About 1.44 million files. That includes over 5,000 personnel files and payslips, plus fine proceedings, confidential parliamentary documents, and vulnerability analyses of Berlin’s drinking water supply.

Who is behind the attack?
The Rhysida ransomware group, believed to operate from Russia and eastern Europe, claimed responsibility. The group was previously linked to an attack on the British Museum.

Did Berlin pay the ransom?
No. City officials said as a matter of principle they would not pay, and the hackers released the stolen data after the deadline passed.

Related coverage

Sources

  • Help Net Security — Berlin refuses to be blackmailed after network breach. helpnetsecurity.com
  • The Hacker News — Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network. thehackernews.com

WhatsApp OTP API

Verification your users actually receive.

Send one-time passcodes over WhatsApp with a single API call. Replio can generate, hash and verify the code for you.

Try it free →replio.live