The city of Berlin is facing a major security crisis following a cyberattack orchestrated by the criminal group Rhysida. After compromising the IT systems of two Berlin Senate departments in mid-August, the hackers demanded a ransom of 30 bitcoins. Staying firm in its policy, the city government categorically refused to give in to the blackmail. In retaliation, the attackers followed through on their threat once the deadline expired on September 4, leaking nearly 1.4 million sensitive files on the dark web.

The massive data dump includes financial documents, HR records, and, even more concerning, login credentials. The situation took a turn for the worse the following weekend when a second batch of data was released, specifically targeting access to administrative networks. Faced with this heightened risk, the Senate was forced to tighten its security protocols, leading to disruptions in online services, particularly for housing assistance. While local authorities claim there is no evidence of a persistent infrastructure compromise, investigations by the Berlin criminal police remain ongoing.

Beyond the technical incident, this confirms the era of double extortion. This practice involves exfiltrating confidential data before encrypting systems, rendering ransom payments useless for ensuring the privacy of stolen information. The publication of these actual files exposes public officials and Berlin citizens to a high risk of targeted phishing, as the attackers now possess a precise documentary database to craft sophisticated, personalized fraud attempts.

The timing of this attack also raises questions, as the German capital prepares to vote for its regional parliament. While authorities believe this to be a purely profit-driven operation, the availability of such data in the public sphere ahead of a sensitive election creates an additional layer of vulnerability. By refusing to pay, Berlin has sent a strong message against the ransomware industry, but it must now manage the long-term collateral consequences of this massive exposure of administrative and private data.