NewsCryptoRhysida Publishes Berlin Data After City Refuses 30 BTC Ransom

Rhysida Publishes Berlin Data After City Refuses 30 BTC Ransom

Author: LiveBitcoinNews·

Key Takeaways

  • The Rhysida gang's ransom countdown expired on September 4, 2026, after Berlin refused to pay a 30 bitcoin demand valued at roughly €2 million.
  • Approximately 1.4 million files from Berlin's state network appeared for public download, reportedly containing personnel records, staff assessments, job references, and tender material.
  • Berlin disclosed the attack in mid-August, with investigators determining that large volumes of data were exfiltrated between August 7 and August 12.
  • Berlin's Senate, the public prosecutor's office, the LKA, and the BSI are responding, with affected individuals to be notified and residents advised to report suspected data misuse.
  • Rhysida, active since 2023 and previously linked to targets including the British Library and other German cities, marketed the stolen haul as nearly 5.8 terabytes.
Rhysida Publishes Berlin Data After City Refuses 30 BTC Ransom

A named ransomware gang put a price tag on a city in bitcoin, watched the auction fail, and turned Berlin's stolen files into a public download.

The Rhysida Berlin bitcoin ransom countdown expired on Friday afternoon. The state had refused a 30 bitcoin demand, and the crew then claimed to post stolen government data for anyone to download. German reporting places the countdown's end near 15:35 local time on September 4, 2026. The minimum bid had been framed at roughly €2 million. The city had already declared it would not pay.

This is the odd mechanics of modern crypto scams and dark web crime rails: the payment demand is a wallet address, the threat is a leak site, and the "sale" is a countdown. When the clock runs out unpaid, the theatre does not end — it widens.

What Rhysida Posted After the Auction Closed

On the group's leak site, the auction listing switched to a claim of public upload. heise and rbb reported the taunt, which told "data hunters" the files were now in the open section.

An early link returned an error. About an hour later, downloads became possible, according to heise's update. rbb reported that roughly 1.4 million files appeared in multiple packages. Folders appeared to contain personnel records, staff assessments, job references, and tender material. Verification of every folder's authenticity was still incomplete within the same reporting window.

Chaos Computer Club spokesman Joachim Selzer told dpa that the full dataset appeared live for browsing. He described personnel matters and work references among the material, and warned that small office details can fuel identity theft once they sit in the open.

Berlin's Senate said security officials and IT forensic teams were reviewing the published packages. Officials said people identified as affected would be notified under legal rules, and that residents who suspected misuse should file a police report. That notification duty tracks with European data protection law, which requires authorities to report personal data breaches to supervisors and, where risk to individuals is high, to inform the people concerned — obligations that a public dump of personnel files makes harder, not easier, to meet.

The Ransom Demand and Berlin's Refusal

Rhysida had marketed the haul as nearly 5.8 terabytes taken from Berlin's state network. Earlier leak-site claims, summarized by heise and other German outlets, listed city contracts, fine cases, login material, personnel files, and papers touching critical systems and courts. Those catalogs were the group's sales pitch rather than a finished forensic inventory.

Governing Mayor Kai Wegner said Berlin would not be blackmailed. Senate spokeswoman Christine Richter had already told dpa that the likely next steps were resale or partial or full publication. The state described Rhysida as a professional ransomware outfit with prior hits across Europe and the United States. Officials said Russian links could not be ruled out — but also could not be proven from available findings.

The bitcoin ask mattered as infrastructure, not as cultural metaphor. Thirty coins were the unlock condition; refusal was the policy. The dark-web auction was the pressure chamber between those two facts.

How the Berlin Network Breach Unfolded

Berlin disclosed the attack on its state network around mid-August. Investigators later said large volumes of data were taken between August 7 and August 12. Affected systems were cut off for days. By late August, Rhysida's auction and the 30 bitcoin floor were public, and the Senate's no-pay stance had become a governing message rather than a private negotiating position.

The Berlin public prosecutor's office is involved in the response, along with the state criminal police (LKA) and the Federal Office for Information Security (BSI). This follows the familiar ransomware choreography: exfiltration first, encryption or disruption as theatre, and then a leak site that turns secrecy into a product.

Rhysida is not a new name on that stage. The gang surfaced in 2023 and has been linked to earlier public-sector and cultural targets — including the British Library outage that disrupted services for weeks — and this year it also hit other German cities. The Berlin episode fits the affiliate-era model: steal enough that a government cannot quietly absorb the loss, price the silence in bitcoin, and use the dark web as both marketplace and pillory.

Why the Dump Matters Beyond One City Network

Unpaid bitcoin ransoms do not erase data; they change who can read it. A private auction at least pretended to ration access. A public dump lowers the skill floor, letting anyone with basic tools copy the packages. Those files may hold signatures, payroll traces, internal mail, cleartext passwords, or notes the city never intended to publish.

Selzer's warning was practical: the more a stranger knows about a person, the easier it becomes to impersonate them, order in their name, or craft a phishing lure that sounds local.

For crypto observers, the sequence is also a story about rails. Crypto did not invent extortion — it made the demand portable, borderless, and easy to post beside a countdown. Leak sites then turned refusal into content. The city kept its policy; the parallel crime economy kept its inventory.

Security specialists quoted in German coverage praised the no-pay stance as a way to starve the extortion model. They also noted that the dump still harms people whose files were never supposed to leave the network. Both statements can be true at once, and that tension is the point.

The Real Story Beneath the Countdown

New technology changes the surface of crime while the underlying bargain stays old: threaten exposure, name a price, and punish defiance in public.

Berlin's case has now moved past the auction metaphor. The files are either ready to download or are being treated that way by investigators, reporters, and anyone else watching the same leak page. What remains is slower work: matching packages to real people, rotating credentials, watching for identity misuse, and deciding which secrets were theatre and which were live ammunition.

Crypto did not create that dread. It gave it a wallet address, a dark-web storefront, and a Friday deadline. Rhysida used all three. Berlin declined the bid, and the dump followed anyway.

The post Rhysida Dumps Berlin Data After Unpaid 30 BTC Ransom appeared first on Live Bitcoin News.