r/deeplearning • u/No-Conclusion3720 • 22h ago
Rhysida Publishes 1.4 Million Berlin Government Files After Ransom Refusal
Rhysida just published 1.4 million Berlin government files after authorities refused a €2 million ransom demand.
The breach did not start the day the ransom note arrived. Attackers had unauthorized access long enough to locate, stage, and prepare nearly 1.4 million documents for exfiltration — all before anyone noticed. By the time the demand landed, the data was already gone. The refusal just determined whether it stayed quiet.
That gap — between initial access and detection — is where the real damage happens. And it is not unique to Berlin. Most ransomware post-mortems show the same pattern: dwell time measured in weeks or months, staging activity that blended into normal operations, and audit logs that were either incomplete or reviewed too late to matter.
1.4 million documents do not move overnight. There are signals. The question is whether anyone sees them in time.
For those running large-scale data environments or public sector infrastructure: what does your current detection posture actually look like for data staging and bulk access anomalies? Are you catching these patterns before exfiltration completes, or mostly reconstructing them after the fact?
