September 4, 2026
The Berlin Mega-Leak: Inside the Massive 5.26 TB Leak of the City’s Most Sensitive Documents
The city of Berlin just had almost all of their fileservers leaked on the Darknet. A total of 5.26 TB with 1,439,893 files, including…

By Jan Kammerath
5 min read
The city of Berlin just had almost all of their fileservers leaked on the Darknet. A total of 5.26 TB with 1,439,893 files, including 77,939 legal complaints, 55,553 financial records, 11,777 highly confidental documents, 16,839 e-mails, 11,963 phone numbers, and personally identifyable information of 12,076 individuals. 148 IBANs (bank account numbers) form the icing on the data leak cake. Hacking group Rhysida broke into the city's network in late August, stole the data and demanded a €2M ransom, equal to $2.32M. The city didn't pay, so the data was published today.
Among the files are payslips, personnel files, documentation of disciplinary actions, work certificates and of course, as you would expect from German authorities, endless files with passwords in plain text. Addresses, phone numbers, signatures, IBANs, private photographs, and even passport scans. Basically everything you expect on the fileservers of a German city or minicipality. An absolute security nightmare.
What happened when?
On August 7th to 12th 2026, the hacker group Rhysida silently extracted data from file servers of Berlin's administrative network before encrypting every file on the systems. A classic ransomware attack, for which this group is widely known. The breach was detected on August 14th, around 2–3 days later. Berlin's departments for mobility, transport, climate protection and environment, as well as urban development, building and housing were subsequently disconnected from the city's network. On August 28th, the Rhysida ransomware group officially claimed responsibility on their Darknet leak site. They listed the stolen data and the payment demands.
On August 28th, governing Mayor Kai Wegner and Interior Senator Iris Spranger publicly stated that the city will not submit to extortion or pay the ransom. Two weeks later, when the deadline passed, the files were uploaded to Rhysida's Darknet site, browseable and downloadable for everyone interested in these files. Disclaimer and Warning:_ It is legally not allowed for me to share the Onion-address with you, and morally I can't either. Do not try to find these files, because these sites pose a threat to you as well._
The leak site offers a full tree based document view on all the leaked files, and of course the files themselves. Among these files aren't just documents, but also certificates, installations of network software, photos, videos and whatever else you would expect on a file server.
What was leaked
Rhysida had obviously gained access to the network and raided the local file servers of several departments of the city of Berlin. The leaks contain files that clearly indicate the origin of the data to likely be from Windows file servers, alternatively Linux Samba servers. The dump contains recycle bin and desktop.ini files from Windows as well as temporarily stored Word and Excel files, indicating users may have been active during the raid.
A lot of the published data contains personally identifyable information (PII). Shift plans, documented disciplinary actions, newly hired employees, payslips, salary increases and everything that should never be public. While it may be interesting to browse through the data, keep in mind that there's real people behind it. This is not just "the city", but real employees, real human beings with real feelings that have some of their most personal data leaked out to the public on the Darknet.
Why this happened to Berlin
Berlin is often joked about by Germans as a "failed city", citing its very liberal nature and Laissez-faire approach to running a city. An incident in 2019 revealed that even old and unsupported Windows installations and software were in use. Software as old as Windows 95, with Microsoft Word 95 as a requirement. This is nothing exclusive to Berlin, to be honest.
"The malware was successful partly because a key program at the Kammergericht (Berlin Court of Appeal) was based on Windows 95 and Word 95 — software named for the year it was released, 1995. Microsoft discontinued all support for this software in 2001." — DER SPIEGEL, 2019
The IT departments of municipalities in Germany have fallen victim to such attacks several times, and are known to lack the necessary amount of competent ressources to ensure safe operation of their software and systems. Further, tailor-made software and solutions for local governments are often provided by a small clique of software companies, specialised in public tenders, who solely work for local governments.
It is not yet publicly known how Rhysida got into the network and onto the servers. The investigations by forensics teams of the Federal Office for Information Security (BSI) and law enforcement are still ongoing. The exact entry point is not yet known. The FBI has extensively documented Rhysida's approach. The characteristic of their attacks is that they usually "log in rather than break in", meaning the initial entrance was likely gained through a phishing attack, social engineering or an insider.
Rhysida silently transfers data to a "command-and-control" server before all files and the system are encrypted. Considering the challenges the city of Berlin has with Information Security, it is likely that the group gained access through a little more advanced phishing and then elevated user privileges to gain full control of all files servers.
Conclusion
Rhysida is well known by the FBI and law enforcement in Germany. Their approach is what IT-Security departments all across Germany train and prepare for every day. This should not have happened. It also outlines that German municipalities have a lot of homework to do in this field. This was a disaster in the making. The question for cities like Berlin was never if this happens, but just when this happens.
I am all for total government transparency, but this is not it. When I see these leaks, the documents, and the PII that comes with them, I don't see an "evil government", I see employees. I see the young newly graduated girl in her early 20s starting her first job at the city, I see people shortly before retirement trying to make the city work for everyone. Such leaks don't just harm "the city of Berlin" as an anonymous entity. They harm real loveable humans, and that's why I hope that law enforcement will be able to finally make some breakthroughs. All German municipalities, not just the city of Berlin, need to ramp up their IT Security by yesterday.
Please don't share the leaked documents. I know it's interesting, and there's a desire to see what's in there. I hope my article gave you some insights and fulfilled your desire for information. Keep in mind, there's real people behind these documents, and that these documents cause real emotions for those people. If you share the content, you help the criminals. Don't.
Thank you for reading. Jan
Legal disclaimer: The screenshots and information were obtained in accordance with German law. No privacy or intellectual property rights were harmed during the research and investigation for this article.
All my articles are handicraft, handwritten by me. By reading and sharing my articles, you support my work and you support real human authorship.
I'm a software business owner from Germany, worked in various CTO roles, an active programmer in C++, Go, Swift and passionate technology enthusiast. My programming career started at a young age and I later acquired a professional institutional education in software engineering. My journey on Medium started out as note taking and documenting my projects. Over time, it became more and more popular with you, my beloved readers. Not because I am someone special, but because people crave for thoroughly researched technical articles. Following me, clapping and subscribing is one step forward in keeping technical writing and its community alive.