The ransomware group Rhysida has followed through on its threat to dump Berlin's state administration data after a 30 Bitcoin ransom demand went unmet. Shortly after a countdown timer expired at 3:35 pm on Friday 11 September, the group published a 5.8 terabyte archive containing 1,439,893 files on its dark web leak site. Among the material is a directory titled AG CBRN-Rahmenplanung, which translates as the CBRN framework planning working group and contains scenario planning for chemical, biological, radiological and nuclear incidents.

What the archive contains

The scale of the breach is exceptional even by recent German standards. Previous intrusions against Berlin's Senate network in 2024 and 2025 yielded 5.7 and 5.8 terabytes respectively, but those datasets were dominated by infrastructure diagrams and personnel records. The current release adds a layer of operational security planning that has no precedent in public disclosure. Cybersecurity researcher Lars Winkelsdorf, who examined the file index, confirmed the CBRN folder contains threat matrices, evacuation protocols and inter-agency coordination plans for scenarios ranging from industrial accidents to deliberate attacks.

Beyond the security planning documents, the archive holds personnel files, payroll data, internal correspondence and contract details for thousands of civil servants and contractors. The sheer volume, nearly six terabytes, suggests the attackers maintained persistent access for months, exfiltrating data systematically rather than in a single smash-and-grab operation. Filename lists shared on Telegram and X within hours of publication indicate the attackers or their affiliates are actively indexing the dump for resale or targeted exploitation.

The ransom timeline

Rhysida's leak site displayed a countdown timer set to expire on Friday afternoon, accompanied by a demand for 30 Bitcoin, valued at roughly €2 million at the time of the deadline. The group has used similar countdown mechanisms in previous campaigns against healthcare and education targets in the UK and US, typically publishing within hours of expiry. Berlin's Senate administration did not publicly acknowledge the demand, nor did it confirm or deny negotiations. A spokesperson for the Interior Senator's office declined to comment on Saturday, citing ongoing forensic investigations.

The refusal to pay aligns with German federal guidance and the position of most European law enforcement agencies, which argue that payment fuels further attacks and offers no guarantee of data deletion. However, the decision carries a distinct cost: the CBRN planning documents are now accessible to any actor with dark web access, including state-aligned groups that monitor such leaks for intelligence value. The Federal Office for Information Security (BSI) has not issued a public alert as of Monday morning.

Why CBRN planning matters

CBRN framework planning is a standard function of any major European capital's civil protection apparatus. Berlin's documents would cover coordination between fire services, police, the Bundeswehr's specialist units and federal agencies such as the Federal Office for Civil Protection and Disaster Assistance (BBK). Their exposure does not reveal weapon designs or intelligence sources, but it does disclose vulnerability assessments, shelter locations, decontamination corridors and communication protocols, information that could be used to degrade response times or target first responders in a real incident.

The practical risk is not theoretical. In 2023, a similar leak of Swedish civil defence plans prompted a formal review of shelter signage and emergency frequency allocations after analysts found the documents on a Russian-language forum. German authorities will now face pressure to audit which plans remain current, which have been superseded, and whether any operational details, such as the exact locations of medical stockpiles, require immediate relocation or reclassification.

Rhysida's evolving model

Rhysida operates as a ransomware-as-a-service outfit, providing encryption tools and leak-site infrastructure to affiliates who conduct the initial intrusions. The group emerged in mid-2023 and quickly distinguished itself by targeting healthcare and public sector entities, the British Library, the Chilean army's payroll system, and Prospect Medical Holdings in the US among them. Its leak site mimics legitimate data repositories, offering searchable file trees and torrent downloads, which lowers the technical barrier for secondary actors to exploit the data.

The Berlin operation bears hallmarks of an affiliate with prior knowledge of the Senate's network topology. The exfiltration volume and the specific inclusion of the CBRN directory suggest either extensive reconnaissance or insider guidance. German prosecutors have opened a formal investigation under Section 202a of the Criminal Code (data espionage) and Section 303b (computer sabotage), but attribution in ransomware cases rarely leads to arrests when operators are based in jurisdictions that do not cooperate with European law enforcement.

Precedent and pattern

This is the third major breach of Berlin's administration in as many years. In March 2024, a 5.7 terabyte leak exposed network topology maps and VPN credentials. In January 2025, a 5.8 terabyte dump included personnel records for the education and social services departments. Each incident prompted promises of improved segmentation, mandatory multi-factor authentication and accelerated patch cycles. The recurrence suggests either that remediation has been incomplete or that the attack surface, thousands of endpoints across dozens of agencies, is fundamentally difficult to secure with current resources.

The federal government's 2027 budget earmarks €109.7 billion for defence, including a cyber capability uplift for the Bundeswehr's Cyber and Information Domain Service. Yet municipal and state-level IT remains a patchwork of legacy systems, outsourced contracts and varying security maturity. The BSI's IT-Grundschutz catalogue provides a baseline, but compliance is voluntary for state administrations. Berlin's Senate has not published a post-incident report for either of the two previous breaches, making it impossible to assess whether lessons were applied.

What happens next

The immediate priority for Berlin's IT security team is containment: revoking compromised credentials, rotating encryption keys and verifying that no persistent backdoors remain in the Senate network. The BSI will likely issue a technical advisory this week detailing indicators of compromise associated with the Rhysida variant used. For the CBRN documents, the BBK must decide whether to reissue planning assumptions, rotate shelter designations or update communication protocols, a process that typically takes months. The next concrete milestone is the Bundestag's interior committee hearing on 23 September, where the Interior Minister is expected to address the breach. Until then, the 1.44 million files remain searchable on the dark web, and every day they remain there increases the probability that hostile intelligence services have already mirrored and indexed them.

People mentioned

  • Lars Winkelsdorf

    Cybersecurity researcher, Independent

Organisations

Berlin Senate Administration · Rhysida