
After a 30-bitcoin ultimatum expired, the hacker group Rhysida put around 5.8 terabytes of data from the Berlin state network online. The Senate had previously rejected a payment.
AI-generated summary
After a cyber attack on the Berlin state network on August 14th, blackmailers demanded a ransom of 30 Bitcoin. The Berlin Senate rejected payment.
In the blackmail case following the massive data theft in the Berlin national network, the criminal hacker group Rhysida carried out its threat. Around an hour after the ultimatum expired, the 5.8 terabyte data package was published on the dark web late on Friday afternoon.
The blackmailers had set up a countdown on their leak site that expired on Friday at around 3:35 p.m. A ransom of 30 Bitcoin (the equivalent of around two million euros) was demanded. The Berlin Senate had previously confirmed that it would not respond to such blackmail and would not pay a ransom.
After the deadline had passed, the “auction” was ended on the blackmailers’ website in the Darknet. “All files have been uploaded to the publicly accessible area – have fun browsing, data hunters!” it said. However, a link initially did not lead to the data, but rather an error message. An hour later you could start downloading the data.
Praise from experts for refusing to pay a ransom
The Senate's refusal to respond to blackmail attempts by criminal hackers was met with approval among experts. Bianca Kastl from the Chaos Computer Club said on RBB Inforadio that the Senate's decision was correct. “If you continued to support these groups with money or other things, then of course they would keep going,” she said. “You have to dry them out financially.”
The renowned IT security expert Christof Fischer pointed out that by law the state is not allowed to make payments in the event of extortion. However, the situation with incidents like those in Berlin is very difficult: "The data is in the hands of criminals, and publication in many cases has very damaging effects. So far, I have not come across any case in which payment was made and publication still took place." However, it can be assumed that the perpetrators, who mostly lived in Eastern European countries, made this data available to the authorities there in order to buy protection from investigations against themselves, Fischer told the German Press Agency.
Experience has shown that in comparable attacks it often takes several hours or days until stolen data sets are actually made available for download via archive files or so-called peer-to-peer networks. IT security experts and the Berlin investigative authorities continually monitor the relevant forums and leak sites.
Increased threat from data leaks
The Federal Office for Information Security (BSI) points to an increased threat situation. “The BSI explicitly points out that the publication of stolen data can result in various risks for those affected and ultimately for society,” explained a spokesman. There is a risk of so-called hack & leak operations in the political sphere, especially before elections. Stolen documents, emails or the like are published at a time that is convenient for the attacker and may be placed in the wrong context. A new House of Representatives will be elected in Berlin on September 20th.
The BSI also points out an increased threat from targeted phishing attacks following the data leak. People who have been in contact with affected people or institutions should therefore pay particular attention. “In addition, data that contains information about critical infrastructures, companies and organizations can also increase the threat level, depending on the sensitivity of the data,” warns the Federal Office. Those affected should check whether they are specifically affected by a data leak and what type of data is published and, if necessary, change processes.
Explosive details in the announcements
The listings and screenshots previously published by the attackers indicate a serious outflow of highly sensitive data. The group claims to have stolen around 1.44 million files. In addition to more than 5,000 personnel files, fines and pay slips, this also includes confidential documents from Federal Council committees and vulnerability analyzes of Berlin's drinking water supply. The blackmailers also boasted that they had obtained access data and passwords in plain text - including for administration databases and payment service providers.
The Berlin administration confirmed the cyber attack that became known on August 14th. Investigators from the State Criminal Police Office (LKA) and the Federal Office for Information Security (BSI) are involved in analyzing and dealing with the incident. If the data package becomes fully public, the authorities concerned and thousands of citizens and employees face significant data protection and security risks.
Because of the hacker attack, the Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Environment and Climate Protection were isolated from the state network for around a week on August 14th. Because of the cyber attack in Berlin, housing benefit could not be applied for or paid out for days.
AI outlook — possibilities, not facts
Increased phishing attacks on affected individuals and institutions
Likely · Within weeks

After the publication of stolen data from the Berlin administration, the BSI warns of increased cyber risks. The authority warns against phishing and hack & leak operations in the run-up to elections, although according to the BSI the act was financially motivated.

After the publication of 5.8 terabytes of stolen data from the Berlin administration on the Darknet, the BSI is warning of an increased threat situation, phishing and targeted manipulation.
The federal government is planning to build a national Hyperloop reference route and is providing 100 million euros. The project promises fast and energy-saving travel, but raises questions about its usefulness and parallels to controversial air taxis.

OpenAI and Anthropic release major updates to ChatGPT and Claude. While OpenAI conjures up a new age of AI, concerns about a loss of control are growing among the population.
After the cyber attack on the Berlin administration and the publication of sensitive data by the hacker group Rhysida, the BSI warns of further attacks, in particular hack & leak operations before the House of Representatives election on September 20th and targeted phishing attacks. The Senate Chancellery will contact those affected.
The White House has published online games on its website in which users are supposed to build a border wall with Mexico or intercept migrants. The Tetris Company stated that it was not involved in the development and did not authorize any use of the Tetris trademark. Human rights organizations sharply criticized the games.