Industry News

Berlin Refuses Ransom, Rhysida Gang Leaks 5.7TB of Stolen Government Data

Tokenpost · 6 Sept 2026
Key Takeaway Small businesses should assume that refusing a ransom may lead to public data leaks, so investing in backups, network segmentation and breach response planning matters more than deciding whether to pay.

Berlin's state government refused to pay a 30 Bitcoin ransom (worth roughly $2.4 million) demanded by the Rhysida ransomware group. When the September 4 deadline passed without payment, Rhysida published the stolen 5.7 terabyte dataset on the dark web.

The attack was first detected on August 14 and forced Berlin to disconnect two Senate departments, covering urban development and housing, and mobility, transport and environmental affairs, from the state network. This temporarily disrupted services including housing benefit payments and family support before systems were reconnected on August 23. Officials warn that personal information belonging to Berlin residents may be included in the leaked files, and a crisis unit with forensic specialists is now reviewing the data alongside police and Germany's federal cybersecurity agency.

Berlin's stance reflects a broader trend: on-chain ransomware payments reportedly fell about 8% in 2025 even as claimed attacks rose 50%, suggesting more organisations are refusing to pay despite the risk of data exposure.

Summarised by CISO AI from Tokenpost. We link back to every original so you can read it yourself.