Security News

Berlin Government Data Leaked After Refusing €2 Million Ransomware Demand

Infosecurity Magazine · 7 Sept 2026
Key Takeaway Australian SMBs should assume that refusing to pay ransomware demands can still result in full public data leaks, so investing in prevention and rapid incident response is more effective than planning to negotiate after a breach.

Berlin's state government has confirmed that ransomware group Rhysida published a large stolen dataset on the dark web after authorities refused to pay a demand of 30 bitcoins, roughly €2 million. The deadline for payment passed on September 4, and officials have stated firmly that they will not negotiate with cybercriminals.

The leaked dataset reportedly totals 5.7 terabytes across approximately 1.4 million files. According to reporting from Euronews, it includes sensitive state emergency planning documents related to chemical, biological, radiological and nuclear (CBRN) threats, as well as personal information belonging to tens of thousands of people, including state employee payroll records, absence lists and home addresses.

Berlin authorities say IT forensic experts are analysing the stolen data and will notify affected individuals on a risk-based basis once the review is complete. There are currently no indications the state network remains compromised, and citizens who suspect their data has been exposed have been urged to report it to law enforcement.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.