The Rhysida ransomware group has published nearly 1.44 million stolen files totaling 5.26 TB on the darknet after Berlin rejected a 30-bitcoin ransom demand worth around €2 million.
The Rhysida ransomware group has published nearly 1.44 million files on the darknet after stealing them from the Berlin city government. The total leak volume amounts to 5.26 terabytes.
The hackers demanded a ransom of 30 bitcoins, roughly equivalent to €2 million, but Berlin refused to pay. Following the non-payment, the group released the compromised data online, a standard extortion tactic meant to punish victims and signal pressure on future targets.
The leaked cache includes employee contracts, passwords, email addresses, and personnel records. It also contains documents related to Berlin’s critical infrastructure, civil defense, and health care system. Such material could be exploited for identity theft, targeted phishing, or deeper intrusions into public networks. The inclusion of infrastructure and health documents raises particular concern because these sectors are considered sensitive and essential to public safety.
The breach underscores the escalating threat ransomware gangs pose to city and national administrations. Berlin’s decision not to finance the ransom matches guidance from law enforcement and cybersecurity bodies, yet the subsequent dump now requires authorities to determine exactly what was exposed and to alert affected employees and institutions.
https://t.me/business_ua/19604