- The Mess: The Rhysida ransomware group claims it stole 5.79 TB of data from Berlin’s city government and has put the haul up for auction with a starting price of 30 BTC. Berlin says it will not pay.
- The Damage: If the attackers’ claims are accurate, the stolen material could expose internal documents, communications and personal information across a major European capital.
- The Fix: Organizations should treat ransomware theft as a data-security incident even when core systems remain operational, with credential rotation, forensic investigation and notification decisions based on verified exposure.
Berlin has a price tag.
30 Bitcoin.
That’s what the Rhysida ransomware operation reportedly wants for a dataset it claims to have stolen from the Berlin city government.
The alleged haul?
5.79 terabytes.
Around 1.44 million files.
And the attackers aren’t threatening to delete it.
They’re selling it.
Rhysida Put the Data Up for Auction
The ransomware group claims it breached Berlin’s municipal administration and extracted a massive amount of information.
The alleged dataset reportedly contains approximately:
5.79 TB of data
and
1.44 million files.
Rhysida set the starting auction price at 30 BTC.
At current Bitcoin prices, that’s a very large ransom demand.
But the bigger issue isn’t the cryptocurrency.
It’s what may be sitting inside those files.
What’s Supposedly in the Dataset?
According to the attackers’ claims, the stolen material includes things such as:
contracts
emails
telephone numbers
passwords
and
internal documents.
Those claims have not all been independently verified.
That’s important.
Ransomware groups routinely exaggerate stolen-data volumes and victim lists.
Sometimes they publish real information.
Sometimes they publish samples.
Sometimes they recycle old material.
The correct response is therefore not:
“Rhysida stole 5.79 TB.”
It’s:
“Rhysida claims to have stolen 5.79 TB.”
That’s a very different statement.
Berlin Isn’t Buying the Argument
Berlin has reportedly rejected the extortion demand.
The city government says it will not submit to the ransom request.
That’s hardly surprising.
Paying attackers doesn’t guarantee that:
the data will be deleted
copies don’t exist
another criminal won’t buy it
or
the attackers won’t come back.
Once sensitive data leaves the environment, the victim loses control over it.
A Bitcoin payment doesn’t magically restore that control.
The Auction Changes the Threat
Traditional ransomware was simple:
encrypt files
↓
demand money
↓
restore or lose access
Modern ransomware increasingly works differently.
The attacker steals data first.
Then comes:
“Pay us or we publish it.”
If the victim refuses?
The attackers can auction the data to someone else.
That creates another revenue stream.
The ransomware operator doesn’t necessarily need to care whether Berlin pays.
Someone else might.
Why 5.79 TB Matters
Five terabytes is a lot of data.
But raw size isn’t the most useful measurement.
One terabyte of video footage isn’t necessarily more sensitive than 500 MB of documents containing:
identity data
passwords
contracts
internal communications
The value of stolen data comes from what it contains.
A relatively small database can be more damaging than terabytes of useless files.
That’s why the alleged 1.44 million files is arguably more interesting than the 5.79 TB headline.
Municipal Governments Are Attractive Targets
City administrations hold enormous amounts of information.
They operate:
public services
housing
transport
finance
procurement
education
social services
and
internal administration.
That creates a large attack surface.
A city isn’t one company with one clean network.
It’s a collection of departments, systems, vendors and legacy infrastructure.
Attackers love complexity.
One Credential Can Open Another Door
The most concerning part of the claimed dataset is the mention of passwords.
If genuine credentials were stolen, the incident doesn’t necessarily end with the Berlin network.
Employees frequently reuse passwords.
Service accounts may have excessive privileges.
Old credentials may remain active.
Third-party systems may trust municipal accounts.
A stolen password therefore has a potential lifetime far beyond the original compromise.
That’s why credential rotation is essential after a confirmed breach.
Not just changing the password for the account directly associated with the incident.
The investigation needs to determine what else could have been exposed.
Ransomware Groups Know How to Create Pressure
The auction is psychological warfare.
Imagine being a city administrator.
The attackers say:
5.79 TB stolen.
1.44 million files.
30 BTC.
Auction starts.
Every hour creates another question:
Is the data real?
Who downloaded it?
Will it be published?
Will journalists find it?
Will criminals buy it?
Are citizens affected?
The attacker doesn’t need to prove everything immediately.
They just need to create enough uncertainty to make the victim nervous.
The Dark Web Is the Marketplace
Ransomware groups increasingly operate like businesses.
They have:
leak sites
victim portals
negotiators
affiliate programs
payment infrastructure
and now:
data auctions.
That’s not random cybercrime anymore.
It’s an organized commercial ecosystem.
The currency may be Bitcoin.
The product is stolen access and stolen information.
But Don’t Trust the 5.79 TB Number Blindly
There’s a reason we’re keeping the wording conservative.
Ransomware operators have a long history of making inflated claims.
A victim appearing on a leak site doesn’t automatically prove:
full network compromise
or
massive data theft.
The only reliable way to establish the scope is through forensic investigation and evidence from the victim organization.
Until then:
claim ≠ confirmation.
That’s particularly important when reporting on government breaches.
Berlin’s Decision Creates an Interesting Test
If the stolen data is genuine, Berlin now faces a problem that cannot be solved simply by refusing to pay.
The city has to determine:
what was accessed
what was copied
which individuals are affected
which credentials need rotation
whether third parties are involved
whether regulators need notification
and
whether the attackers still have access.
The ransom decision is only one part of the incident.
Data Theft Can Outlive the Ransomware
This is the uncomfortable part.
Ransomware encryption eventually becomes irrelevant.
You can rebuild systems.
Restore backups.
Replace hardware.
Reinstall software.
But stolen information doesn’t expire just because the victim recovered.
A leaked:
passport number
phone number
contract
email archive
or
credential
can remain useful for years.
That’s why data theft is often more dangerous than the encryption itself.
The Secondary Attacks Could Be Worse
If the alleged dataset contains internal emails and phone numbers, criminals could use it for follow-up attacks.
For example:
phishing
business email compromise
identity theft
social engineering
credential attacks
The initial breach becomes the source material for the next campaign.
That’s how one compromise can turn into several.
This Is Also a Supply-Chain Problem
Municipal governments rarely operate everything themselves.
They depend on:
IT contractors
software vendors
cloud providers
payment processors
consultants
and
managed service providers.
If an attacker enters through one of those relationships, the city may not even be the original point of compromise.
That makes forensic attribution more difficult.
And it makes third-party access controls critical.
What Should a Victim Do?
First:
contain the compromise.
Then:
preserve forensic evidence.
Then:
identify persistence.
Then:
rotate compromised credentials.
Then:
determine exactly what data was accessed or exfiltrated.
Only after that should the organization start making confident public statements about the scope.
And if the stolen data is being auctioned?
Monitor the marketplace.
Not because criminals are trustworthy.
Because the appearance of samples can help confirm what was actually stolen.
The 30 BTC Number Is Almost a Distraction
Thirty Bitcoin sounds enormous.
But the real question is:
What is the data worth to someone else?
If the dataset contains information that can be monetized repeatedly, a criminal buyer might consider the auction price cheap.
The attackers only need one buyer.
And unlike a ransom negotiation, the buyer doesn’t care whether Berlin agrees.
Bugstoday Opinion
The interesting part of this incident isn’t that Rhysida wants Bitcoin.
Ransomware groups have been demanding cryptocurrency forever.
The interesting part is the transition from:
“Pay us or your systems stay encrypted.”
to:
“Pay us or someone else can buy what we stole.”
That’s a different business model.
Berlin says it won’t pay.
Fine.
But refusing the ransom doesn’t make the stolen data disappear.
If Rhysida’s 5.79 TB claim turns out to be genuine, the city could be dealing with something much more persistent than encrypted servers.
The files can be copied.
The credentials can be reused.
The documents can be sold.
And the auction can continue long after the ransomware itself is gone.
Bugstoday verdict: 30 BTC is just the opening bid. The real commodity is the data. Berlin can refuse to pay the criminals, but it can’t negotiate with every future buyer who might acquire a copy. That’s why ransomware isn’t really about encryption anymore. It’s about who controls the stolen information after the breach.




