Breaking
ITIsraeli Defense Minister Katz warns of possible all-out war against Palestinian Authority after West Bank stabbingDEWanted Austrian arrested near Weil am Rhein after attempting to escapeUKHafidh Ameir Hassan, husband of Tanzania's President Samia Suluhu Hassan, dies in Zanzibar hospitalBRUnidentified man dies after being run over on Avenida Prefeito Hugo Bastos, in TeresinaVNC04 destroyed a drug transport network at sea, seizing 1.16 tons of ketamine worth 800 billion VNDITNational train strike: disruptions expected from 7 to 8 SeptemberCNQingdao's off-peak tourism ushered in a concert boom. Nearly 80,000 people watched Xu Song's concert, boosting cultural tourism consumption in the golden autumn.TRMuğla Chief Public Prosecutor's Office Conducted an Operation on Suspects Related to FETOPLMerz warns against radical right-wing government in Saxony-Anhalt, AfD targets 40%. in the federal electionsUKWSL Roundup: Palace win tainted by substitution breach, Chelsea draw, Arsenal debuts shineITIsraeli Defense Minister Katz warns of possible all-out war against Palestinian Authority after West Bank stabbingDEWanted Austrian arrested near Weil am Rhein after attempting to escapeUKHafidh Ameir Hassan, husband of Tanzania's President Samia Suluhu Hassan, dies in Zanzibar hospitalBRUnidentified man dies after being run over on Avenida Prefeito Hugo Bastos, in TeresinaVNC04 destroyed a drug transport network at sea, seizing 1.16 tons of ketamine worth 800 billion VNDITNational train strike: disruptions expected from 7 to 8 SeptemberCNQingdao's off-peak tourism ushered in a concert boom. Nearly 80,000 people watched Xu Song's concert, boosting cultural tourism consumption in the golden autumn.TRMuğla Chief Public Prosecutor's Office Conducted an Operation on Suspects Related to FETOPLMerz warns against radical right-wing government in Saxony-Anhalt, AfD targets 40%. in the federal electionsUKWSL Roundup: Palace win tainted by substitution breach, Chelsea draw, Arsenal debuts shine
BackBerlin: data stolen by the Rhysida group published after refusal to pay the ransom
Berlin: data stolen by the Rhysida group published after refusal to pay the ransom
Developing
Journal du Coin42 minutes agoCrime3 min readView original

Berlin: data stolen by the Rhysida group published after refusal to pay the ransom

After hacking two Berlin Senate administrations, ransomware group Rhysida uploaded 1.4 million files following the city's refusal to pay 30 bitcoins.

Quick Look

  • Berlin refused to pay a ransom of 30 bitcoins to the Rhysida group after a computer hack.
  • In retaliation, hackers published 1.4 million confidential files on the dark web, exposing sensitive personal and administrative data.

AI-generated summary

Why It Matters

The Rhysida group hacked two Berlin Senate administrations in mid-August, demanding 30 bitcoins. The city refused to pay, leading to the publication of stolen data.

Font size

Berlin chose not to play, undoubtedly at a high price. After the hack that took two Berlin Senate administrations offline in mid-August and the 30 bitcoins demanded by the Rhysida group, the city refused to pay. The sanction fell on September 4, as soon as the ultimatum expired, with 1.4 million files dumped on the dark web and a message that sounds like a calculated provocation. And the story didn't end there.

The promised bag emptying, executed to the letter

Remember the seven day countdown? Rhysida held it to the minute. A few moments after the deadline, the group posted around 1.4 million files online, as detailed by the specialized media IT-Administrator in its analysis of September 5: personnel files, financial and administrative documents, access identifiers. All accompanied by a message that is intended to be mocking, an invitation to “have fun” addressed to snoops on the dark web.

Nothing very original, actually. The British library made the same choice when faced with Rhysida in 2023, and nearly 490,000 files ended up leaking after its refusal. Berlin therefore knew perfectly well what to expect when standing up to the group.

A second data package, confirmed by the Senate Chancellery

Except that the story does not end on September 4. During the night from Saturday to Sunday, the hackers posted online what the Berlin Senate Chancellery itself described as “another data package”, this time focused on access identifiers, as the Berliner Zeitung reported on Sunday evening. The administration of urban development, construction and housing has reviewed and tightened certain security measures already in place, with a risk of occasional restrictions on online procedures, for example applications for housing assistance. The users concerned must be notified on a case-by-case basis.

The Senate remains tight-lipped about the details of the affected procedures. It only confirms that no element shows, at this stage, that the administrative network remains compromised: investigators from the Land criminal police and the Berlin public prosecutor's office, mobilized since the official announcement at the end of August, are continuing their investigations.

The real danger begins now

This is the paradox of a leak of this magnitude: the hacking itself is over, its consequences are only just beginning. Such a volume of authentic names, positions and internal records turns even the smallest future fraudulent email into a precision weapon. Targeted phishing (spear phishing, a fraud attempt tailor-made from real information about the target) no longer needs to improvise, it draws directly from the city's real files.

This is the principle of double extortion, which has become the norm among ransomware groups: stealing the data before encrypting the systems, then threatening to publish it, regardless of whether the machines are restored behind it. A clean backup repairs a server. It does not bring back a file already online. Double punishment, not double protection.

Rhysida, electoral calendar and coincidences that are not coincidences

Add to that the electoral calendar. The election for the Berlin regional parliament takes place on September 20, just two weeks after this second wave of leaks. The authorities say it bluntly, no link has been established between the attack and the vote, the operation remains classified as motivated by money. The fact remains that data stolen for money may very well be used later for other purposes, electoral or not.

What to Watch

AI outlook — possibilities, not facts

  • Continuing investigations by the criminal police and the Berlin public prosecutor's office.

    Very likely · Within weeks

Open Questions

  • What concrete measures to protect citizens whose data has leaked?
  • Is the full extent of compromised data known?

Related Topics

This article was originally published by Journal du Coin.

Related Stories

An 18-year-old suspect indicted in the DGFiP hacking case, a second released
Developing·

An 18-year-old suspect indicted in the DGFiP hacking case, a second released

The Paris prosecutor's office has confirmed the indictment and provisional detention of an 18-year-old man suspected of belonging to the ZeroBytes group, the claimed author of the massive hacking of the DGFiP this summer. A second minor suspect under the age of 16 was released after being taken into custody. This case directly concerns cryptocurrency holders due to the increased risk of wrench attacks facilitated by the leak of 678,000 tax files containing sensitive data.

Journal du Coin
2 min read
Four Uzbek nationals prosecuted in South Korea for financing terrorism via USDT transfers
Developing·

Four Uzbek nationals prosecuted in South Korea for financing terrorism via USDT transfers

Gwangju police arrested four Uzbek nationals in April suspected of financing the terrorist group Katibat Tawhid wal Jihad by sending 4,267 USDT in seven transfers between August 2024 and April 2025. The alleged ringleader received cryptocurrencies from the group, converted them into eleven used cars and two excavators shipped to Syria, and is now in pre-trial detention in court. The other three are being prosecuted without incarceration. The investigation is based on South Korea's anti-terrorist financing law and the travel rule, while the suspects claim that the money was used to support family needs.

Journal du Coin
2 min read
More on this topicberlin