Berlin's state government has confirmed that the Rhysida ransomware gang published a massive stolen dataset on the dark web after authorities refused to meet the group's extortion demand. The State of Berlin announced on September 4 that the criminal organization had demanded 30 bitcoins—worth approximately €2 million—in exchange for not releasing data stolen from its network, setting a Friday deadline for payment. The state government emphasized it would not yield to the blackmail attempt, and the entire dataset was subsequently published after the ultimatum expired.

Rhysida claimed to have accessed roughly 5.7 terabytes of data, encompassing around 1.4 million files from Berlin's state network. The State of Berlin warned that the personal information of government employees, citizens, and businesses may be affected by the breach. Media reports indicate the published dataset includes highly sensitive state emergency plans related to terrorist attacks and other disaster scenarios, found in a folder labeled "AG CBRN-Rahmenplanung," which refers to chemical, biological, radiological and nuclear threats. The ransomware gang also claims the stolen material contains personal details of tens of thousands of individuals, including personnel files of state workers with absence lists, payroll information, and home addresses.

"The State of Berlin will not give in to blackmail," said Florian Hauer, chief digital officer for the State of Berlin. The Senate Chancellery stated that IT forensic experts are currently analyzing the stolen dataset, and authorities will contact all individuals affected once this process has been completed. Officials indicated that identified victims will be notified by the relevant Senate departments on a risk-based basis and in accordance with legal requirements. The state government added that there are currently no signs the state network remains compromised, and any Berlin citizen who discovers their personal data has been published has been urged to report the matter to law enforcement.

The Rhysida ransomware-as-a-service operation was first observed in May 2023 and has frequently targeted public institutions and critical services. The threat actor has been connected to multiple attacks on US healthcare providers, including a 2025 incident at Cookeville Regional Medical Center in Tennessee that resulted in the compromise of more than 337,000 patients' data. A Rhysida affiliate was also responsible for the high-profile ransomware attack on the British Library in 2023, which suffered huge disruption and recovery costs after refusing the attacker's extortion demands. The pattern suggests ransomware groups continue to target government entities and public services with high-value data, calculating that either ransom payments or the public release of sensitive information will advance their financial objectives. Berlin's refusal to pay may embolden other public institutions to resist extortion, though it also demonstrates the steep cost of that stance when critical emergency plans and citizen data enter the public domain.