
Share
Nearly 6 terabytes of stolen files are now public after Berlin refused to pay a ransomware gang's asking price. With elections weeks away, officials scramble to assess the damage and protect residents.
Imagine finding out that private records held by your city government, the kind of paperwork you assumed was locked away safely, are now sitting on the internet for anyone to download. That is the reality facing residents of Berlin this weekend, after a ransomware group made good on its threat to release nearly 6 terabytes of stolen data.
Berlin's state government said on Saturday it was reviewing the leaked material with the highest intensity, as investigators work to understand just how deep the damage runs. Two city departments were targeted in the original breach, though officials have not yet detailed exactly what kinds of records were taken or how many people might be affected.
The timing could hardly be worse. Berlin holds elections on September 20, meaning the fallout from this breach is unfolding in the same weeks that voters are forming judgments about how well their government functions. A cyberattack of this scale, landing less than a month before people go to the polls, adds a layer of political anxiety to what is already a serious public safety concern.
The group behind the attack, known as Rhysida, is no stranger to this kind of extortion playbook. Rhysida specializes in ransomware, a type of malicious software that locks victims out of their own systems or steals their files, then demands payment to prevent public exposure or to restore access. Think of it as a digital kidnapping: the hackers take something valuable, in this case sensitive government data, and hold it hostage.
Rhysida had put the stolen files up for auction, setting a starting price of 30 bitcoin, worth roughly $77,622 at the time. That auction ran for several days before closing on Friday. Berlin's government had already made clear it would not pay. City officials stood firm on that position even after the auction closed, and the group followed through by publishing the data publicly.
That refusal to negotiate reflects a broader shift among governments and institutions worldwide. Paying ransoms, even when it feels like the fastest way to make a crisis disappear, tends to reward and fund future attacks. It also offers no guarantee that stolen data will not be leaked anyway. Berlin's decision not to submit to extortion falls in line with guidance many cybersecurity experts have pushed for years, even though it meant accepting the near-certainty that the data would end up public.
Now that it has, the response shifts from prevention to damage control. A central crisis unit has been stood up to oversee three main tasks: reviewing the leaked data, verifying what it actually contains, and assessing the real-world impact on the people and businesses whose information may be exposed. That last part matters most. Data breaches can sound abstract until you realize they might include tax records, health information, or personal correspondence tied to real names and addresses.

City officials have been careful in how they describe the incident, calling it "an extremely serious crime" and framing it as an attack on the state itself rather than simply a technical failure. That language is deliberate. It signals that Berlin views this as a matter of public security, not an IT glitch to be quietly patched.
Officials have also asked the public not to spread unverified claims about the leak on social media. This is a common and important request after any large data breach. In the chaotic hours and days after stolen files go public, misinformation can spread faster than facts, sometimes doing as much harm as the breach itself. False rumors about what data was taken, or who was affected, can cause unnecessary panic or point blame in the wrong direction before investigators have a chance to verify anything.
For individuals whose information may have been compromised, the process of notification will follow established legal channels. German and European data protection rules require that people affected by a breach of this kind be informed by the relevant authorities. Those frameworks, some of the strictest privacy protections in the world, exist precisely for moments like this: to ensure people are not left in the dark about what happened to their personal information.
That said, notification takes time. Investigators first need to verify what the leaked data actually contains before they can determine who was affected and how. Given the volume involved, nearly 6 terabytes, that verification process alone could take weeks. Anyone anxious about their own exposure will likely need patience, even as the instinct to demand immediate answers is completely understandable.
Cyberattacks on city and state governments are not rare anymore. They have become a recurring test of institutional resilience, striking at moments when public trust is already fragile. What sets this incident apart is its collision with democratic timing. When a government's data security fails weeks before an election, it does more than expose personal records. It raises uncomfortable questions about whether public institutions can protect the basic infrastructure citizens rely on, right when citizens are being asked to place their trust in that same government at the ballot box.
Berlin's response, standing firm against the ransom demand, standing up a crisis unit, and committing to legal notification standards, offers a model of how institutions can respond responsibly even when the outcome is far from ideal. It will not undo the exposure that has already happened. But it may determine how much additional harm follows, and how much trust the city can rebuild once the immediate crisis passes.
Tags
Original Sources
Berlin launches crisis response after hackers publish stolen data
↗ https://www.reuters.com/world/berlin-launches-crisis-response-after-hackers-publish-stolen-data-2026-09-05
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
6 September 2026
56 articles
Related Articles
Related Articles
More Stories
© 2026 Cedar & Bloom. All rights reserved.