Rhysida Moves Berlin Theft Into Auction Mode

Berlin said it will not pay after confirming stolen government data in a Rhysida ransomware attack, and the gang has now put the material up for auction with a countdown. The city also said the incident was discovered in mid-August and that investigators are still working to verify what was taken. Rhysida says it has roughly 5.7 terabytes of data, but Berlin has not confirmed that figure or the contents. The mechanism is simple: once stolen records are copied out of a government network, the group can threaten to leak or sell them even if the victim refuses the ransom, so the harm does not end when the extortion demand is rejected. For local-government networks, the exposed data can outlive the intrusion and reach people named in the records through fraud, doxxing, or follow-on targeting. The remaining uncertainty is scope, and that matters because the downstream risk follows whatever actually left the network, not the city’s public stance.

Part of the PlainSec briefing for 2026-08-31

Every edition of this story: Rhysida Moves Berlin Theft Into Auction Mode

Sources