Berlin Ransomware Attackers Dump Stolen Data Online After Refusing 30 BTC Demand
Rhysida's Berlin bitcoin ransom clock ran out on September 4, 2026, at around 15:35 local time. The city had refused a 30 BTC demand, and instead of deleting the stolen data, the attackers decided to post it online for anyone to download.
The files, which are nearly 5.8 terabytes in size, include personnel records, staff assessments, job references, and tender material. Berlin's Senate said that security officials and IT forensic teams were reviewing the published packages, and that people identified as affected would be notified under legal rules.
Rhysida is a professional ransomware outfit with prior hits across Europe and the United States, and German authorities suspect Russian links. The city's governing Mayor Kai Wegner said Berlin would not be blackmailed, and Senate spokeswoman Christine Richter had already told dpa that the likely next steps were resale or partial or full publication.
The dump of stolen data is a common tactic used by ransomware attackers when their demands are refused. It allows them to still make money from the stolen information, even if the original ransom is not paid.