/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Berlin is reviewing Rhysida's 5.79TB release of state data after refusing to pay a ransom; files reportedly include national defense and threat response plans

Berlin's state government said on Saturday it was reviewing with the highest intensity a trove of stolen data published by a ransomware group …

Reuters Miranda Murray

Context & Ripple Effects

The case extends a public-sector ransomware pattern in which data theft creates a second crisis beyond disruption: the DC Police breach involved threats to expose sensitive files, while the Port of Seattle attributed a cyberattack and data theft to Rhysida. Berlin’s review therefore centers on what the published material exposes, not only on restoring affected systems.

Berlin has also treated major state-network intrusions as a national-security concern, following the 2015 parliament data theft attributed by Germany’s domestic intelligence chief to Russia. Reports that the Rhysida files include defense and threat-response material raise the stakes, though the contents have not been independently established in the supplied record.

First-order effects

  • Berlin’s state government must identify affected records and assess exposure across agencies after Rhysida published the stolen trove.
  • Agencies responsible for defense and threat response face heightened operational review because such plans are reportedly among the files, an allegation that remains unconfirmed.

Second-order effects

  • The release makes exfiltration risk central for other public-sector Rhysida victims, including the Port of Seattle, whose 2024 incident already involved data obtained by the group.
  • Berlin’s containment and forensic work becomes a test of whether state administrations can limit harm after publication rather than treating ransomware recovery solely as a systems-restoration task.

Third-order effects

  • If public-sector attacks keep pairing disruption with publication, government cyber-resilience will be judged increasingly on data segmentation, exposure assessment, and contingency planning—not only uptime.
  • The pattern points toward ransomware as a pressure campaign against public institutions’ confidential operational information, with leak-site publication amplifying the cost of any breach.

The trend: Ransomware against public institutions is shifting from service disruption toward data-exfiltration extortion, making post-breach information exposure a core security risk.

Discussion

  • @dailydarkweb @dailydarkweb on x
    🚨 Rhysida publishes stolen State of Berlin data after ransom refusal The State of Berlin has now confirmed that stolen government data has been published following the expiration of Rhysida's extortion deadline on September 4. Berlin had previously confirmed that a group identify…
  • @lefterisjp Lefteris Karapetsas on x
    Don't see it much in the English speaking twitter but earlier today the hacker group Rhysida released ~5.4TB of data stolen from the Berlin government It ranges from personal data of people, state employees, to vulnerabilities of critical infrastructure such as the water supply
  • r/technology r on reddit
    Berlin launches crisis response after hackers publish stolen data
  • @dfir_radar @dfir_radar on x
    Rhysida hit German 🇩🇪 state administration in 2026: Stuttgart listed on the leak site in May, Berlin confirmed data exfiltration across five days in August before network separation. The attack chain runs far upstream of the ransomware binary. Key findings: - The Vanilla Tempest/…
  • @ctiacademy @ctiacademy on x
    Berlin Data Leak: A District Is Blocking the Senate's Forensics Vendor The Senate Chancellery contracted CrowdStrike to examine Berlin district systems for traces left by Rhysida. The district of Lichtenberg has so far refused access, and the dispute has become the operationally …
  • @coffereport @coffereport on x
    UPDATE: The Berlin government cyberattack has now escalated into a major security incident. Around 5.8 TB of stolen government data - reportedly some 1.44 million files - has been published after Berlin refused to pay the Rhysida ransomware group. German federal authorities are n…