1.4 million stolen Berlin government files dumped on the dark web, triggering crisis response
The data allegedly includes sensitive data about Berlin's water supply, information from power plants, fuel depots, and more.

Image via Shutterstock
- Rhysida published 1.44 million stolen Berlin government files after the city refused to pay a ransom.
- Officials are urgently checking whether the leaked data endangers critical sites or sensitive government bodies.
- Researchers found information tied to water systems, power infrastructure, prisons, defense firms, and staff records.
- Berlin hired CrowdStrike to inspect systems, but Lichtenberg district objects over access and disruption concerns.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Berlin has launched a coordinated review of the almost six terabytes of data dumped on Friday by the Rhysida group to assess whether the information could pose a security risk.
The ransomware gang published the data after an auction with a starting price of 30 bitcoin ended on Friday without Berlin paying the ransom. The dump contains around 1.44 million files totaling 5.8 terabytes, according to German public broadcaster Tagesschau.
The government said on Saturday that “the files are being analyzed with utmost urgency.” Berlin has established an additional task force to evaluate the leaked data and support the two affected Senate departments.
In the press release, the Press and Information Office of the State of Berlin said that if the review finds that the leak could put a critical facility or a sensitive government body at risk, the affected organization will be alerted without delay.
While authorities are working to determine the scope of the leak, several researchers and publications have already examined parts of it.
According to the Chaos Computer Club, the data includes sensitive information concerning the state of Berlin's water supply, as well as the personal data of administrative staff, including employment references and emergency plans.
Der Tagesspiegel reportedly found data relevant to Germany’s security, such as information from power plants, fuel depots, emergency power systems, substations, prisons, waterworks, defense companies, the Bundeswehr, and Berlin's interior administration.
Der Spiegel’s investigation discovered more than 550 files relating to the expansion of the Federal Chancellery, including expert opinions, plans, and statements from government bodies.
“This hacking attack is an extremely serious crime and an attack on the state of Berlin. In the interest of Berlin's security, it is important to carefully examine information circulating, for example on social networks, and not to further disseminate reports that cannot currently be verified,” the government press release said.
The Rhysida group claimed responsibility for the attack last week, saying it stole 5.79 terabytes of data, including 46,500 contracts, emails, phone numbers, passwords, and classified information.
Berlin received a ransom demand but refused to pay, with Berlin's Governing Mayor Kai Wegner and Berlin's interior senator Iris Spranger saying: "The state of Berlin will not be blackmailed.”
The attack came just ahead of Berlin's state election on September 20th, but the election infrastructure has not been affected.
An internal disagreement
Following the cyberattack, Berlin hired US-based CrowdStrike to examine its IT systems using the company’s Falcon tool to determine whether Rhysida had truly left – and whether it left anything behind.
But not everyone is happy. The investigation would include separate district administrations, including Lichtenberg, which is refusing to allow CrowdStrike access to its servers.
According to the internal letter obtained by rbb, the district claims that the software would gain "virtually unlimited access" to all its data, including personal information, and would likely be "impossible to remove."
Lichtenberg is also concerned that Falcon would gain access to work devices and therefore be able to monitor both what happens on employees' computers, as well as the employees using them.
"According to feedback from other districts, it also leads to sometimes severe disruptions in the operation of specialized procedures, services, and programs, and poses a significant risk to the operational capacity of the district office,” the letter says.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Lichtenberg claims it already uses a competing security product and has found no evidence that its systems were compromised. It also said it will only grant CrowdStrike access if the Senate "assumes full responsibility”, including all costs.
The Senate Chancellery reportedly informed the district on Saturday that the software is “the only option” and said it would cover the costs and assume responsibility for any damage caused by its use.