Rhysida Leaks Berlin Government Data After 30 BTC Ransom Goes Unpaid

Server room with a countdown screen showing zeros, symbolizing a ransomware attack aftermath.

The ransomware group Rhysida followed through on its threat on September 4, 2026, dumping stolen Berlin state government data on its dark web leak site after the city refused to pay a 30 bitcoin ransom. German technology publication heise and public broadcaster rbb reported that the group’s auction listing flipped to a public upload shortly after the countdown expired at approximately 15:35 local time. The initial link returned an error, but downloads became possible about an hour later, according to heise.

Rhysida published stolen Berlin government data after the city refused to pay a 30 BTC ransom. The dump reportedly includes around 1.4 million files, such as personnel records and tender documents. Berlin officials maintain their no-pay stance and are reviewing the leaked data.

A Public Dump After a Failed Auction

Rhysida’s leak site initially advertised the stolen data as an auction with a minimum bid of 30 BTC, roughly €2 million at the time. The city had already stated it would not negotiate. When the clock ran out, the group made good on its threat, posting what it claimed was the full dataset.

Also read: Is the Crypto Bull Market Back in September? Key Signals to Watch

According to rbb, the leak contained approximately 1.4 million files organized into multiple packages. Folders appeared to include personnel records, staff assessments, job references, and tender material. However, checks on every folder’s authenticity were still incomplete in the immediate aftermath. Chaos Computer Club spokesman Joachim Selzer told dpa that the full dataset appeared live for browsing, and he warned that even small office details could fuel identity theft once exposed.

Berlin’s Response and the No-Pay Policy

Berlin’s Senate confirmed that security officials and IT forensic teams were reviewing the published packages. Individuals identified as affected would be notified under legal rules, and residents who suspected misuse were advised to file a police report.

Also read: Oil Prices Jump Above $97 as U.S.-Iran Tensions Threaten Supply

Governing Mayor Kai Wegner reiterated that Berlin would not be blackmailed. Senate spokeswoman Christine Richter had earlier told dpa that the likely next steps were resale or partial or full publication. The state characterized Rhysida as a professional ransomware outfit with prior attacks across Europe and the United States, and officials said Russian links could not be ruled out but also could not be proven from available findings.

How the Breach Unfolded

Berlin disclosed the attack on its state network in mid-August 2026. Investigators later determined that large volumes of data were exfiltrated between August 7 and August 12. Affected systems were taken offline for days. By late August, Rhysida had publicly listed the auction with a 30 BTC floor, and the Senate’s refusal to pay became a matter of public record.

The response involves the Berlin public prosecutor’s office, the state criminal police (LKA), and the Federal Office for Information Security (BSI). This follows the familiar ransomware pattern: exfiltration first, then the threat of exposure, and finally a leak site that turns secrecy into a commodity.

Rhysida is not a newcomer. The group has been linked to previous attacks on public-sector and cultural institutions, including high-profile cases abroad. This year alone, it also targeted other German cities. The Berlin incident fits the affiliate-era model: steal enough data that a government cannot quietly absorb the loss, price the silence in bitcoin, and use the dark web as both marketplace and pillory.

What the Dump Means Beyond Berlin

The unpaid ransom does not erase the data; it changes who can access it. A private auction at least pretended to ration access. A public dump lowers the skill floor — anyone with basic tools can copy the files. These files may contain signatures, payroll traces, internal communications, cleartext passwords, or other sensitive material.

Selzer’s warning was practical: the more a stranger knows about a person, the easier it becomes to impersonate them, place orders in their name, or craft convincing phishing lures. For the cryptocurrency community, this incident underscores that bitcoin’s role in ransomware is not about ideology but about utility — it makes demands portable, borderless, and easy to post alongside a countdown.

Security specialists quoted in German coverage praised Berlin’s no-pay stance as a way to starve the ransomware business model. Yet they also acknowledged that the dump still harms individuals whose files were never meant to leave the network. Both positions can be true simultaneously.

As investigators work to match leaked packages to affected individuals, rotate compromised credentials, and monitor for identity misuse, the broader lesson remains: ransomware is not a technical problem but an economic one. The threat of exposure is the product, and the dark web is the storefront. Berlin’s refusal to pay is a policy decision, but the consequences will be felt by the city’s employees and residents for months to come.

Jackson Lee

Written by

Jackson Lee

Jackson Lee covers Bitcoin and Ethereum markets at CryptoNewsInsights, tracking price movements, network developments, and ecosystem news.

Leave a Reply

Your email address will not be published. Required fields are marked *