Rhysida Berlin Leak: Is Redistributing the Data a Crime?

Rhysida published Berlin government data after the city refused a ransom. Redistributing it is a crime under §202d StGB and §42 BDSG — the legal analysis, plus NIS2 lessons.
On September 4, 2026, the ransomware group Rhysida published data from two Berlin Senate departments on the dark web, after the Senate refused a ransom demand of 30 Bitcoin (roughly EUR 2 million). If you redistribute this data, you generally make yourself criminally liable under § 202d StGB and, in some cases, § 42 BDSG. Merely viewing it, by contrast, remains a legal gray area.
What Do We Know So Far?
Data exfiltration from two Berlin Senate departments took place between August 7 and 12, 2026, and around 5.8 terabytes were published on the dark web on September 4. The Senate rejected the 30-Bitcoin ransom demand. The exact contents and the number of identifiable victims are not yet officially confirmed.
The departments affected were the Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Action and the Environment. The attack was discovered on August 14, and the systems were disconnected from the state network (heise online). On August 28, Rhysida claimed responsibility and set a deadline of September 4 (Berliner Zeitung).
Berlin's Chief Digital Officer, Florian Hauer, stated: „Das Land Berlin lässt sich nicht erpressen. Die Sicherheit der Beschäftigten im Land Berlin und der Berlinerinnen und Berliner steht für uns im Vordergrund." (in English: "Berlin will not be blackmailed. Our employees' and residents' safety comes first.") (t-online) When the ultimatum expired, Rhysida published the data roughly an hour later (Handelsblatt). The attackers claim it includes personnel files and fine proceedings involving state employees, residents, and companies. Independent confirmation is pending.
For NIS2Compass readers, one question matters most: whether, and how, redistributing this data is a criminal offense. That's the focus of the next section.
Is Redistributing the Berlin Data a Crime?
If you pass on, obtain, or make accessible data from the Rhysida leak to enrich yourself or someone else, or to cause harm, you become criminally liable under § 202d StGB (handling of stolen data), punishable by up to three years' imprisonment. Where personal data is involved, § 42 BDSG may also apply. This is a general legal overview, not legal advice for a specific case.
This section does not replace legal advice. It gives a journalistic overview of the current legal situation. If directly affected, seek advice from a lawyer.
Under § 202d StGB, it is an offense to obtain, hand over, distribute, or otherwise make accessible non-public data that another person obtained unlawfully, provided this serves to enrich or harm someone. The penalty may not exceed the one for the underlying offense. An exception applies to lawful official duties, such as journalism. For private individuals, that's not a free pass.
Where personal data is involved, § 42 BDSG also applies: paragraph 1 covers unauthorized, commercial transmission of not-generally-accessible data belonging to many people, punishable by up to three years' imprisonment. Paragraph 2 covers processing or fraudulently obtaining such data for payment, or with intent to enrich oneself or cause harm, punishable by up to two years.
There's also a GDPR dimension: any disclosure without a legal basis is unlawful processing, with a possible fine under Art. 83 GDPR and damages claims under Art. 82 GDPR. Merely viewing the data without intent to enrich or harm sits in a legal gray area, since § 202d requires precisely that intent. Data protection and malware risks remain in practice, though.
What Does This Mean for Companies Subject to NIS2?
The Rhysida attack shows that ransomware combined with data exfiltration hits large, well-resourced organizations too. Had a company subject to NIS2 been hit, it would have triggered the three-stage reporting obligation under § 32 BSIG. Per the BSI's 2025 situation report, 72 percent of reported ransomware cases involved an additional data leak.
Berlin's state administration itself does not automatically fall under the nationwide NIS2UmsuCG.
Under the EU Directive, public administration counts as a sector of high criticality, but German states and municipalities implement it under their own authority. For exactly what applies to whom, see The KRITIS Umbrella Act and NIS2: What Applies to Whom?
Ransomware remains the most common attack vector according to the BSI: 950 reported incidents in the period, roughly 80 percent hitting small and medium-sized enterprises (BSI 2025 situation report). If a company subject to NIS2 were affected, the 24h/72h/1-month cascade from NIS2 Incident Reporting: When, What, and to Whom? would apply, with possible fines under § 65 BSIG and/or Art. 83 GDPR (details on NIS2 fines; estimate with the NIS2 fine calculator).
Berlin's decision against paying follows BSI guidance: payment doesn't guarantee deletion and only finances the criminal model. The same pattern (exfiltration before encryption, then extortion) regularly hits mid-sized IT service providers subject to NIS2 too.
What Can You Do Now?
Companies subject to NIS2 should check whether their reporting process could handle an incident like the Rhysida attack within 24 hours, test backups regularly, and assess their own exposure in a structured way. The NIS2Compass Pre-Check identifies gaps in under 15 minutes. This is about preparation, not panic.
Concretely: is it clear who reports to the BSI within 24 hours in an emergency? The article NIS2 Incident Reporting: When, What, and to Whom? walks through the cascade in detail.
Tested, separately stored backups, network segmentation, and minimized access rights are, per the BSI's 2025 situation report, core baseline measures against ransomware. The NIS2Compass Pre-Check shows in under 15 minutes which of the 124 implementation steps you already meet.
Sources:
- t-online, 09/04/2026: Hacker drohen mit Daten-Veröffentlichung am Freitag – das rät der Berliner Senat
- Handelsblatt, 09/04/2026: IT-Sicherheit: Berliner Hacker-Ultimatum abgelaufen – Kein Lösegeld
- Berliner Zeitung, 09/03/2026: Hacker drohen Berlin: Daten von Bürgern könnten am Freitag im Netz landen
- heise online, 09/01/2026: Berlin: Passwords exfiltrated, 12,000 systems scanned
- § 202d StGB (Datenhehlerei), gesetze-im-internet.de
- § 42 BDSG (Strafvorschriften), gesetze-im-internet.de
- BSI: Die Lage der IT-Sicherheit in Deutschland 2025 (Kurzfassung)
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.
Get startedÄhnliche Artikel
Blossom Health cyberattack: the extortion note landed in patients' inboxes
An extortionist sent his demand directly through Blossom Health's patient messaging. What is reported, what remains open, and which obligations would apply in Germany.
12 Min. Lesezeit
Security Incident at a Service Provider: Who Reports to the BSI?
Why every affected NIS2 entity reports a cloud or MSP incident itself, when its own 24-hour deadline starts, and how providers can inform customers in time.
9 Min. Lesezeit
Security Incident Logbook: Free Excel Template
Free Excel template: an ongoing register for every security incident in a given year, including non-reportable ones, with automatic §32 BSIG deadline calculation.
4 Min. Lesezeit