"The ultimatum issued by the hacker group Rhysida following its cyber-attack on Berlin’s state network expired on Friday afternoon. According to experts, the entire dataset was published on the dark web."
State of Berlin: refusal to pay a €2m ransom
The State of Berlin confirmed on September 4 that it rejected an extortion demand from the Rhysida ransomware gang and that the attacker's payment deadline expired that day. Rhysida had demanded 30 bitcoins — reported as equivalent to €2m — to withhold data it had stolen from the state's network. In its official statement the Senate Chancellery reiterated that the government "will not give in to blackmail," stressing that the safety of state staff and the people of Berlin is its "top priority," a point echoed by Florian Hauer, the state's chief digital officer.
Rhysida's claim and the published dataset: 5.7 TB and 1.4 million files
Rhysida claimed to have accessed approximately 5.7 TB of data. Authorities and reporting indicate that the gang subsequently published the full dataset on the dark web; the State of Berlin said experts concluded the dataset had been released after the ultimatum expired. Reporting on the leaked corpus describes roughly 1.4 million files in total.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildSensitive state disaster plans reportedly exposed
Media reporting cited in the public record indicates the leak includes highly sensitive emergency and disaster plans for the state. Euronews reported that documents related to terrorist attacks and other disaster scenarios were among the files, contained in a folder labelled "AG CBRN‑Rahmenplanung" — CBRN being the acronym for chemical, biological, radiological and nuclear threats. The State of Berlin had warned earlier that personal data of employees, citizens and businesses could be affected, and Rhysida claims the dataset contains personal information on tens of thousands of people, including personnel files, absence lists, payroll data and home addresses.
Forensic analysis, notification plans and law enforcement
IT forensic experts are actively analysing the published dataset to determine precisely what was taken and exposed. The Senate Chancellery said there are currently "no indications" the state network remains compromised. Authorities will contact affected individuals once forensic review identifies them: notifications will be issued by the relevant Senate departments on a risk‑based basis and in accordance with legal requirements. The government also urged any citizen who discovers their personal data in the leak to report the matter to law enforcement.
What this means for IT forensic experts, Senate departments, and Berlin citizens and businesses
- IT forensic experts — Already tasked with analysing the 5.7 TB dataset, forensic teams will need to map file contents to systems and people, and to confirm whether additional operational details in the publication pose immediate risks to safety or continuity.
- Senate departments and administrators — Departments responsible for affected records must prepare legally compliant, risk‑based notifications and coordinate with law enforcement as the analysis identifies impacted employees, citizens and businesses.
- Berlin employees, citizens and businesses — The state warned that personal data may be present in the leak and advised anyone who finds their information published to report it to police; individuals should expect contact from a relevant Senate department only after analysis identifies them.
Rhysida's known pattern and recent history
The public record describes Rhysida as a ransomware‑as‑a‑service operation first observed in May 2023 that has frequently targeted public institutions and critical services. The gang has been linked to a series of attacks cited by authorities and reporting: notably, a string of strikes on U.S. healthcare providers including Cookeville Regional Medical Center in Tennessee in 2025, which resulted in the compromise of more than 337,000 patients' records; and an affiliate believed responsible for the 2023 ransomware attack on the British Library, an incident that produced major disruption and recovery costs after the victim refused to pay extortion demands.
Berlin's authorities have drawn a line: they will not pay the ransom, forensic work is underway, and the immediate promise is to notify affected people once the analysis permits. The published dataset, its reported inclusion of sensitive CBRN planning materials, and the sheer volume of files — if confirmed by forensic teams — leave concrete tasks for investigators, public administrators, and law enforcement to complete in the coming days and weeks.




