Particle.news

Massive Berlin Data Dump From Rhysida Forces Multi‑Agency Forensic Review

The city says no top‑secret defence files appear affected and federal cyber agencies are using AI to triage more than a million leaked files as investigations continue.

Overview

  • Rhysida, a ransomware‑as‑a‑service group, posted roughly 1.3–1.44 million files (about 5.7–5.8 TB) taken from two Berlin senatorial administrations after the city refused a 30‑Bitcoin ransom.
  • Berlin detected the intrusion in mid‑August and has since isolated affected systems and set up a steering unit; the Bundesamt für Sicherheit in der Informationstechnik (BSI), Bundeskriminalamt (BKA) and Bundesamt für Verfassungsschutz (BfV) are assisting the forensic work.
  • City officials say the published files do not include higher‑level national‑security secrets and are limited so far to VS‑NfD classification, but journalists and researchers report documents that could relate to critical infrastructure and emergency plans and the review is ongoing.
  • Authorities will use AI tools to prioritise files for human review and plan risk‑based notifications to people whose personal data appears in the leak; officials and experts warn of heightened phishing, identity theft and fraud risk.
  • The breach exposed long‑running IT weaknesses in Berlin’s decentralized systems, has prompted political pressure for transparency and funding, and sparked disputes over forensic tools after the district of Lichtenberg resisted installing a CrowdStrike agent.