$ techbeacon▋
Ransomware

Berlin Declines 30‑Bitcoin Ransom, Hackers Release 6 TB of Classified Files to Dark Web

Berlin Declines 30‑Bitcoin Ransom, Hackers Release 6 TB of Classified Files to Dark Web

Berlin’s decision to reject a 30‑bitcoin ransom demand has resulted in the public exposure of roughly six terabytes of confidential state administration and national defence material on a dark‑web forum, according to a report from Security Affairs. The data dump, carried out by an unidentified ransomware group, includes internal communications, procurement records, and strategic defence documents, raising immediate concerns over operational security and diplomatic confidentiality.

The cyber‑criminals initially demanded payment in Bitcoin, a cryptocurrency favored for its pseudonymous nature, before threatening to release the information. City officials opted not to negotiate, citing a policy against rewarding illicit extortion. Within hours of the refusal, the gang fulfilled its threat, uploading the massive archive to a hidden service that is accessible only to those with the appropriate decryption keys.

Analysts estimate that the leaked files span multiple ministries and agencies, encompassing everything from budgetary spreadsheets to classified military plans. While the exact content remains difficult to verify without a thorough forensic review, the sheer volume suggests that the breach could compromise ongoing procurement contracts, expose personnel identities, and reveal strategic assessments that were meant to remain confidential.

Ransomware attacks on governmental bodies have surged in recent years, driven by the high value of public‑sector data and the perceived willingness of states to pay to avoid disruption. Berlin’s refusal aligns with a growing trend among European capitals to adopt a zero‑tolerance stance, hoping to deter future extortion attempts. Critics argue, however, that such a stance can backfire when the alternative is the uncontrolled dissemination of sensitive information.

German officials have condemned the leak as a “serious breach of national security,” and have pledged a coordinated response involving the Federal Office for Information Security (BSI) and law‑enforcement agencies. Cyber‑security experts warn that the leak could be weaponised by hostile actors, and they urge affected institutions to assume that any compromised data may already be in the hands of adversaries.

Authorities are now focused on damage control, including notifying potentially impacted parties, revoking compromised credentials, and strengthening network defenses across ministries. The incident also underscores the need for clearer international guidelines on how governments should respond to ransomware demands, a conversation that may gain urgency as similar threats loom on the horizon.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related