{"id":160991,"date":"2026-09-07T09:04:20","date_gmt":"2026-09-07T09:04:20","guid":{"rendered":"https:\/\/www.europesays.com\/dk\/160991\/"},"modified":"2026-09-07T09:04:20","modified_gmt":"2026-09-07T09:04:20","slug":"berlin-ransomware-leak-exposes-state-secrets","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/dk\/160991\/","title":{"rendered":"Berlin Ransomware Leak Exposes State Secrets"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tBerlin Ransomware Leak Exposes State Secrets\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> September 07, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/dk\/wp-content\/uploads\/2026\/09\/image-89.png\" alt=\"\"\/><\/p>\n<p>Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web.<\/p>\n<p class=\"wp-block-paragraph\">When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The <a href=\"https:\/\/securityaffairs.com\/tag\/rhysida\" data-type=\"post_tag\" data-id=\"15488\" rel=\"nofollow noopener\" target=\"_blank\">Rhysida ransomware<\/a> group recently carried out this exact threat against <a href=\"https:\/\/securityaffairs.com\/tag\/berlin\" data-type=\"post_tag\" data-id=\"17292\" rel=\"nofollow noopener\" target=\"_blank\">Berlin<\/a> after local authorities refused to pay a thirty Bitcoin ransom.<\/p>\n<p class=\"wp-block-paragraph\">At the end of August, Berlin\u2019s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state\u2019s administrative network, and officials have already refused the requested ransom. The ransomware group\u00a0<a href=\"https:\/\/securityaffairs.com\/tag\/rhysida\" rel=\"nofollow noopener\" target=\"_blank\">Rhysida<\/a>\u00a0claimed responsibility on its leak site August 28, posting an entry titled simply \u201cBerlin, Germany\u201d and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/08\/image-89.png?ssl=1\" rel=\"nofollow noopener\" target=\"_blank\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1717\" height=\"737\" src=\"https:\/\/www.europesays.com\/dk\/wp-content\/uploads\/2026\/09\/1788771860_48_image-89.png\" alt=\"\" class=\"wp-image-198071\" style=\"aspect-ratio:2.327272727272727;width:1024px;height:auto\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:<\/p>\n<p>Personal data:\u00a012,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.<\/p>\n<p>Sensitive records:\u00a0more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.<\/p>\n<p>Credentials:\u00a0plaintext passwords and credentials for systems including Geb\u00e4udAtlas, the ePayment PAYONE database and Z_ADMIN accounts.<\/p>\n<p>Government and legal material:\u00a0disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.<\/p>\n<p>Classified information:\u00a0data related to classified-material handling and documents allegedly containing state secrets.<\/p>\n<p>Critical infrastructure:\u00a0vulnerability analyses concerning Berlin\u2019s water supply.<\/p>\n<p>Identity documents:\u00a0passports and ID cards from personnel records.<\/p>\n<p>Other material:\u00a0contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL\/PST archives.<\/p>\n<p class=\"wp-block-paragraph\">The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS\/BSIG requirements. These are Rhysida\u2019s claims and have not been independently verified.<\/p>\n<p class=\"wp-block-paragraph\">The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/09\/image-19.png?ssl=1\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" width=\"735\" height=\"272\" src=\"https:\/\/www.europesays.com\/dk\/wp-content\/uploads\/2026\/09\/image-19.png\" alt=\"\" class=\"wp-image-198551\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">The fallout goes far beyond routine data theft. Investigative journalist Lars Winkelsdorf pointed out the gravity of the situation on social media. <\/p>\n<p lang=\"de\" dir=\"ltr\">Die absolute Vollkatastrophe ist eingetreten<\/p>\n<p>Dieses Datenleck ist schlimmer als alle bisherigen Terroranschl\u00e4ge zusammen 1\/x<a href=\"https:\/\/t.co\/epU4mCYgew\" rel=\"nofollow\">https:\/\/t.co\/epU4mCYgew<\/a><\/p>\n<p>\u2014 Lars Winkelsdorf (@winkelsdorf) <a href=\"https:\/\/x.com\/winkelsdorf\/status\/2095898068046512492?ref_src=twsrc%5Etfw\" rel=\"nofollow\">September 4, 2026<\/a><\/p>\n<p class=\"wp-block-paragraph\">\u201cIn addition to LKA documents related to investigations, the files also include plans concerning national defense\u2014ranging from the federal government\u2019s secret communication channels in the event of an apocalypse to defense-related companies and emergency plans developed by government agencies,\u201d Winkelsdorf wrote. <\/p>\n<p class=\"wp-block-paragraph\">Exposing crisis response plans and secret communication channels turns a financial shakedown into a national security headache.<\/p>\n<p class=\"wp-block-paragraph\">Worse still, the leaked material includes files concerning chemical, biological, radiological, and nuclear threats. <\/p>\n<p class=\"wp-block-paragraph\">\u201cAmong the published files is a folder titled \u201cAG CBRN-Rahmenplanung.\u201d CBRN stands for chemical, biological, radiological and nuclear threats,\u201d notes the <a href=\"https:\/\/www.euronews.com\/next\/2026\/09\/05\/berlin-cyberattack-hackers-leak-highly-sensitive-data-across-dark-web\" target=\"_blank\" rel=\"noopener nofollow\">Euronews report<\/a><\/p>\n<p class=\"wp-block-paragraph\">Having that kind of operational data floating around public forums gives hostile actors a blueprint for disaster.<\/p>\n<p class=\"wp-block-paragraph\">Refusing to pay ransoms is the right policy, but it rarely stops the bleeding once the network is compromised. Governments keep treating cybersecurity like an IT expense rather than an existential line of defense. <\/p>\n<p class=\"wp-block-paragraph\">Until boards start treating network segmentation with the same seriousness as physical security, we will keep watching expensive countdown timers tick down to zero.<\/p>\n<p class=\"wp-block-paragraph\">Berlin\u2019s state government <a href=\"https:\/\/www.reuters.com\/world\/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05\/\" rel=\"nofollow noopener\" target=\"_blank\">announced<\/a> the launch of a crisis response after the threat actors published the stolen data.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA \u200ccentral \u2060crisis unit will oversee the review, verification and assessment of the leaked data and support efforts to inform affected citizens and \u200bbusinesses, said the \u200bcity.\u201d <a href=\"https:\/\/www.reuters.com\/world\/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05\/\" rel=\"nofollow noopener\" target=\"_blank\">Reuters reports<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p class=\"wp-block-paragraph\">(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0Berlin)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Berlin Ransomware Leak Exposes State Secrets Pierluigi Paganini September 07, 2026 Berlin refused a 30 Bitcoin ransom, leading&hellip;\n","protected":false},"author":2,"featured_media":160992,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[99],"tags":[112,40886,75535,16616,190,44778,46412,46413,46414,72983,46415,72984,46417,46418],"class_list":["post-160991","post","type-post","status-publish","format-standard","has-post-thumbnail","category-berlin","tag-berlin","tag-cybercrime","tag-dark-web","tag-data-breach","tag-germany","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-malware","tag-pierluigi-paganini","tag-rhysida-ransomware","tag-security-affairs","tag-security-news"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@dk\/117228959849417875","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/posts\/160991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/comments?post=160991"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/posts\/160991\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/media\/160992"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/media?parent=160991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/categories?post=160991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/tags?post=160991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}