By Nela Heidner, Euronews
Published on 05/09/2026 – 9:17 GMT+2
The hacker group “Rhysida” has published nearly six terabytes of data from Berlin’s state administration on the dark web. The leak includes highly sensitive information across 1,439,893 files. So far, Berlin’s administration and political leaders have offered barely any response.
Among the leaked files is a folder titled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological, and nuclear threats, meaning highly sensitive information on potential threat scenarios is now publicly accessible—and could be viewed by terrorists or foreign intelligence services.
Investigative journalist Lars Winkelsdorf raised the alarm on “X,” stating that this cyberattack is “of a magnitude that threatens the state.” He noted that alongside files from the LKA relating to investigations, the data contains plans concerning a state of defence, including secret communication channels of the federal government for the event of the end of the world.
A substantial amount of personal data has also been exposed, particularly relating to state civil servants. This includes birth certificates, apparent absence lists, telephone numbers, and home addresses.
The extortionists previously threatened publication on their leak site and demanded a ransom of 30 Bitcoin, approximately two million euros. They set a countdown that expired at around 3:35 pm on Friday. The Berlin Senate had already made it clear before the ultimatum expired that it does not, as a matter of principle, yield to such blackmail demands, and it ignored the demand.
Shortly after the countdown ended, the leak followed: the massive data package was published on the dark web. On social networks, members of the hacking group were already circulating lists of file names, illustrating the extent of the attack and the volume of data siphoned off.

