Berlin's state government just learned that skipping a ransomware payment carries a very public price tag.
Rhysida, a ransomware group, broke into the Berlin state government's network and exfiltrated 1.44 million files totaling roughly 5.8 terabytes. The group demanded 30 bitcoin, about $2.3 million, threatening to publish the data if Berlin didn't pay. Berlin refused, calling the incident a serious attack on the state, and opened a full investigation instead. When the ransom deadline passed, Rhysida dumped the entire archive onto the dark web.
Now Berlin has to comb through nearly six terabytes of leaked files to see who and what is exposed. The Chaos Computer Club, Germany's largest hacker organization, says the archive reportedly includes water supply information, staff personal data, and emergency plans, the kind of records that turn a routine breach into an infrastructure and public safety problem. Refusing to pay is standard government practice and probably the right call, but it shifts the cost of the group's leverage onto the residents and employees whose data just went public.
Rhysida has previously targeted hospitals and school systems, so aiming at a state capital's utilities and emergency planning fits a pattern: hit whichever target makes a leak hurt the most, not just the one with the deepest pockets.