Berlin Government Data Leak: Rhysida Publishes 1.44 Million Files After Ransom Refusal
In August 2026, the Rhysida extortion group breached the network of the State of Berlin, copying roughly 1.44 million files from two of the city-state's Senate administrations. Berlin disconnected the affected departments on August 14 and refused a ransom demand of 30 BTC. On September 4, Rhysida published the full archive on its dark web leak site.
SOCRadar's Dark Web Team analysed the published file listing rather than opening any leaked content. The archive looks like a bulk capture of shared drives and mailboxes rather than a single database export. It includes roughly 367,000 PDFs, around 257,000 Word documents and about 57,000 spreadsheets, covering personnel and legal case files, identity document scans, payroll material and thousands of certificates and credentials. Mail data forms a second major component, with more than 166,000 individual mail objects and around 2,200 mailbox archives tied to several hundred user accounts. A further block of roughly 100,000 files relates to geospatial and land-use planning records, which is largely non-personal.
File dates span four decades, but a notable portion, roughly 90,000 files, date from 2023 through 2026, showing this was an active working environment rather than an old backup set. Forensic evaluation and notification of affected individuals were still ongoing weeks after the leak, meaning the full scope of harm remains unresolved.