Overview
- The attacker’s deadline expired on Friday, Sept. 4, and Rhysida published the stolen dataset on the dark web after Berlin refused a 30 BTC ransom.
- The group claims roughly 5.7–5.8 terabytes of data across about 1.44 million files, including personnel records, payroll and operational documents.
- Reportedly sensitive material in the leak includes emergency and CBRN planning plus analyses of critical infrastructure such as the water supply.
- Berlin set up a central crisis unit to lead forensic verification, said there are no current signs the state network remains compromised, and will notify affected people on a risk-based legal basis.
- Rhysida is a ransomware-as-a-service operator with a record of targeting public bodies, and the publication raises risks of identity fraud, operational exposure and further criminal use of the data as investigations continue.