The Berlin Senate has confirmed it will not pay a ransom demand following a significant cyberattack on its network, a decision that has resulted in the public release of sensitive government data. The hacker group Rhysida published a 5.8-terabyte dataset on the dark web late on 5 September 2026, roughly one hour after their payment deadline expired.

Criminals had demanded 30 Bitcoin, valued at approximately €2 million at the time, in exchange for deleting the stolen information. City officials reiterated their standing policy of not engaging with extortion attempts, prioritising long-term security incentives over short-term containment. The move places Berlin among several European public bodies testing the limits of non-payment strategies against organised cybercrime.

Scope of the exposed records

Initial analysis of the leaked material suggests the breach penetrates deep into administrative functions. Joachim Selzer, speaking for the Chaos Computer Club, reviewed the uploaded files and noted the presence of human resources documentation. These records typically contain personal identifiers, employment histories and performance assessments that are not intended for public circulation.

The exposure creates immediate risks for current and former employees of the Berlin administration. Work certificates and personnel files can be used to construct detailed profiles for identity fraud or targeted phishing campaigns. While financial data was not explicitly highlighted in the initial dump, the volume of information provides sufficient material for sophisticated social engineering attacks against staff members.

The cost of holding the line

Refusing to pay the ransom avoids funding criminal enterprises but guarantees the data becomes public. Security experts argue that paying encourages further attacks on the same target and signals vulnerability to other groups. The Berlin Senate's stance aligns with guidance from various security agencies, though the practical consequence is the loss of control over sensitive internal communications.

Public sector organisations face a distinct dilemma compared to private companies. A bank might calculate the reputational cost of a leak against the ransom price, but a government body must consider public trust and legal obligations regarding citizen data. The release of internal administrative documents could complicate ongoing policy work and expose deliberative processes to external scrutiny.

Regulatory pressure across Europe

This incident occurs as European Union member states implement stricter cybersecurity obligations for public administrations. Under the NIS2 Directive, essential entities must report significant incidents and maintain adequate security measures. The European Commission cybersecurity strategy emphasises resilience, yet local authorities often struggle with legacy IT systems and budget constraints that leave them exposed to groups like Rhysida.

Compliance does not guarantee immunity from attacks, but it does mandate a structured response. Berlin will likely face questions about whether its security protocols met the required standards prior to the breach. Regulatory bodies may investigate whether the intrusion could have been prevented with different infrastructure investments or staff training programmes.

Immediate technical fallout

Access to the leaked data was initially inconsistent. Reports indicated that links posted by the hackers led to error messages shortly after the announcement, suggesting potential instability in the criminals' hosting infrastructure. However, mirrors of the dataset typically appear quickly across multiple dark web forums once a leak of this size is verified by independent researchers.

IT teams within the Senate are now focused on containment and forensics. They must determine how the attackers gained entry and whether backdoors remain active within the network. Securing the remaining infrastructure is paramount before normal operations can fully resume, a process that often takes weeks for organisations of this size.

People mentioned

  • Joachim Selzer

    Spokesperson, Chaos Computer Club

Organisations

Berlin Senate · Rhysida · Chaos Computer Club