:

BERLIN REVIEWS LEAKED STATE DATA AFTER REJECTING RANSOM

INDUSTRY DESK2 MIN READ
SAT, SEP 5, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Berlin's government is intensively reviewing 5.79TB of state data released by ransomware group Rhysida after refusing to pay a ransom demand. The leaked files reportedly contain sensitive information on national defense and threat response plans.

Berlin confirmed Saturday it is examining the data breach with maximum priority following Rhysida's public release of the stolen files. The ransomware group published the data after the city refused to meet its ransom demands. The leaked dataset reportedly includes documents related to national defense strategies and emergency response protocols. The exact scope of sensitive information exposed remains under review by German authorities. Rhysida has emerged as an increasingly active ransomware operation in recent months, targeting both public and private sector organizations across multiple countries. The group typically demands payment in exchange for not releasing stolen data, resorting to public disclosure when targets refuse to pay. Berlin's decision to reject the ransom demand aligns with guidance from German and international cybersecurity authorities, which generally discourage ransom payments as they fund criminal operations and incentivize future attacks. The incident highlights growing cybersecurity threats facing government infrastructure in Europe. German officials have not disclosed details about how the breach occurred or the timeline of the intrusion, though they indicated the data review process has begun with high-level government involvement. Authorities are expected to assess which specific documents were compromised and determine what security measures may be needed in response. The incident comes amid broader concerns about ransomware attacks targeting critical government functions across the EU. No statement has been issued regarding potential notification to affected parties or plans for additional security measures.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals are exploiting thousands of compromised small-business websites to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, amplifying the reach of a known threat.

5H AGOAI Desk

Quad9 provides an open DNS recursive service that prioritizes user privacy and security at no cost. The service blocks malware and phishing domains while maintaining minimal data collection.

7H AGOSecurity Desk

A government website running Ruby on Rails was exploited within hours of a critical vulnerability patch becoming public. The rapid attack demonstrates how quickly threat actors weaponize disclosed security flaws.

7H AGOAI Desk

Researchers have identified 39 distinct methods for compromising passkey authentication, exploiting weaknesses beyond the underlying FIDO2 cryptography.

15H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.