Berlin forms crisis unit as Rhysida publishes terabytes of Senate data after ransom refusal

Berlin sets up crisis unit after Rhysida hackers publish 5.8 TB of stolen data
Rhysida ransomware group stole and published 5.8 terabytes of data from two Berlin Senate departments after the city refused a 30-bitcoin ransom. Berlin created a central coordination unit to assess the leak and notify affected people and businesses. The data includes personal records and possibly sensitive infrastructure details. Investigations continue with federal involvement ahead of September 20 elections.

One Story. Many Angles.

🇸🇬
Singapore
The Straits Times
Reuters wire copy
Berlin launches crisis response after hackers publish stolen data
Read →
🇩🇪
Germany
Volksstimme
GERMAN
Carries dpa reporting
Hacker attack in Berlin: Senate sets up control unit for cyber attack
“Hackerangriff in Berlin: Senat richtet Steuerungseinheit für Cyberangriff ein”
Read →
🇩🇪
Germany
Bild
GERMAN
Original reporting
Hacker attack on Berlin: How insecure does the data theft make us?
“Hackerangriff auf Berlin: Wie unsicher macht uns der Datenklau?”
Read →
🇨🇭
Switzerland
Watson
GERMAN
Carries dpa reporting
Hacker attack: Horror after data leak in Berlin
“Hackerangriff: Entsetzen nach Datenleck in Berlin”
Read →
🇩🇪
Germany
Ostsee-Zeitung
GERMAN
Carries dpa reporting
Million data leaked: Hacker attack could have greater consequences than previously thought
“Millionen Daten geleakt: Hackerangriff könnte größere Folgen haben als bisher gedacht”
Read →
5 sources · 3 independent accounts — some share the same news agency’s report
Compared 57 outlets across 46 countries and 27 languages · 45 translated · read 10 in full
In Brief

German papers stress known security lapses and opposition outrage while the international wire sticks to official response language.

Reporting across outlets converges on the core sequence: Rhysida exfiltrated data in August from Berlin’s mobility and urban development administrations, published it after the ransom deadline passed, and Berlin responded by forming a coordination unit under State Secretary Florian Hauer. German domestic accounts uniformly cite dpa-sourced details on the 1.44 million files and 5.8 TB volume while adding expert criticism that security lapses were known and unaddressed. Bild stands out by interviewing Bundeswehr sources who describe a potential “datentechnischen Supergau” and questioning whether infrastructure plans reached adversaries. Watson and Ostsee-Zeitung amplify opposition and IT-expert accusations of gross negligence and possible defense-related leaks without introducing new primary evidence. The Straits Times relays the official Berlin statement and Reuters framing of an “extremely serious crime” against the state, omitting the domestic blame narrative. No outlet contradicts the refusal to pay ransom or the formation of the unit; the divergence lies in emphasis on whether the incident reveals systemic German administrative weakness or remains a contained Berlin administrative failure. Federal statements that Bund systems are unaffected appear in multiple chains yet sit alongside warnings that shared defense and civil-protection documents may be exposed.

Perspective Analysis

Berlin’s state government learned in mid-August that unknown intruders had reached deep into two Senate departments responsible for mobility, traffic, environment, urban development and housing. The attackers copied roughly 5.8 terabytes of material across 1.44 million files before the breach was detected on 14 August. Forensic work later showed the theft had occurred between 7 and 12 August. When the city refused to pay the 30-bitcoin ransom demanded by the Rhysida group, the stolen material appeared on the dark web on 4 September.

The published files contain personnel records, scanned passports, employment contracts, medical certificates and internal correspondence. Several German outlets also reported that the material includes documents on heating plants, water works, prisons, tank farms, emergency power installations and civil-defense planning that touches Bundeswehr responsibilities. No outlet claimed to have seen the full contents; every account stressed that a complete inventory remains impossible given the volume.

On 5 September the Senate chancellery announced a new central coordination unit to manage the aftermath. State Secretary for Digitalization Florian Hauer was placed in charge. The unit brings together the Berlin criminal police office, the two affected departments, the state data-protection authority, the state information-security commissioner and other security bodies. Its tasks are to sift the leaked material, assess risks and organise contact with affected citizens and businesses, normally by letter or email. Regierender Bürgermeister Kai Wegner said the city was working in close contact with federal security services. A federal government spokesman confirmed that Bund systems themselves were not affected and that information was being exchanged through the national cyber-defence centre.

The election scheduled for 20 September is not considered compromised. Landeswahlleiter Stephan Bröchler told Bild and Ostsee-Zeitung that voting systems, ballot preparation and result transmission had been checked and remained outside the compromised networks.

Rhysida has operated since 2023, communicating mainly in Russian and targeting organisations worldwide for ransom. It does not attack targets inside Russia or the Commonwealth of Independent States. The group had set an ultimatum; when Berlin declined to pay, the data were released with a message inviting others to “have fun with it.”

German domestic reporting added detail on prior warnings. IT expert Manuel Atug, who had testified twice before the Berlin interior committee in 2023 and 2025, told dpa that the city had acted with gross negligence by failing to apply the required protections for classified material. Jochim Selzer of the Chaos Computer Club examined samples and found unredacted passport scans and water-supply records. Opposition figures in the Abgeordnetenhaus described the episode as government failure and called for a formal major-damage declaration. Bild quoted Bundeswehr circles describing a potential “datentechnischen Supergau” and noted that defence-related civil-protection documents had been shared with Berlin authorities in the past.

The Straits Times account, drawn from Reuters, framed the incident as an “extremely serious crime” and an attack on the state itself. It recorded Berlin’s decision not to pay, the formation of the crisis unit and the plan to notify individuals under data-protection rules, but did not include the expert or opposition criticism that appeared in the German papers.

No reporting chain contradicted the sequence of theft, publication after non-payment, or the creation of the coordination unit. The divergence lay in scope. The international wire presented the administrative response as the central fact. The three German outlets that carried dpa material added the same volume figures and the same expert accusations, while Bild supplemented them with its own interviews on national-security implications. Watson, drawing on the same German sources, emphasised political shock in the run-up to the election.

A reader limited to the Straits Times piece would correctly understand the official actions taken but would not encounter the repeated claims that security shortfalls had been flagged years earlier. A reader limited to Bild would see the strongest warnings about possible infrastructure exposure and Bundeswehr concerns. The dpa-based accounts in Volksstimme and Ostsee-Zeitung sit between these poles, recording both the unit’s formation and the negligence allegations without adding new primary material.

The domestic German coverage therefore supplies the fuller record of prior warnings and potential downstream risks. Those warnings rest on named expert testimony and on-the-record opposition statements rather than anonymous assertion. The federal statement that Bund systems are untouched stands in every chain that mentions it, yet the same chains record that Berlin and federal authorities have routinely exchanged civil-protection and defence-adjacent documents. That overlap supplies the concrete basis for the concern that sensitive material may have left state networks.

What to Watch

The next weeks will show whether the coordination unit can identify and notify the individuals whose records appear in the leak and whether any of the infrastructure documents prove operationally useful to adversaries. The volume alone—5.8 terabytes—makes exhaustive review slow, and copies once posted on the dark web can be mirrored indefinitely. The election itself is unlikely to be disrupted, but the political cost to the governing coalition is already visible in the opposition statements carried across multiple German outlets.


That’s how the world told the story.

Get tomorrow’s bulletin by email — one briefing, up to six stories.

Subscribe free

No spam. One-click unsubscribe. See the latest email →

Share this story

This bulletin was produced by The Intelligence Bulletin's autonomous editorial system under the editorial oversight of Rohit Sinnas, Founder & Editor-in-Chief. How it works →