Berlin refused to pay before the extortionists had even posted their claim. The same afternoon, a ransomware crew put what it calls 5.79 terabytes of Berlin state agency data up for auction.
That sequence matters, and it is easy to lose behind the ransom figure. Governing Mayor Kai Wegner and Iris Spranger, Berlin’s senator for the interior and sport, issued their joint refusal at 3:39 p.m. Berlin time on Aug. 28, according to the Senate Chancellery’s own release, and Reuters reported that the statement went out before the Rhysida group claimed the attack on its website. “The state of Berlin will not submit to extortion,” the two said in the rendering Reuters published; the German original reads “Das Land Berlin lässt sich nicht erpressen.” So the refusal was not a response to the auction. Whether the auction was a response to the refusal is not something the reporting establishes.
Rhysida’s listing claims about 1.44 million files, among them 124,823 mapping and geodata files and, by the count carried on the leak-site archive at ransomware.live, 77,939 filed under legal matters and complaints. Reuters, working from the live site, reported bidding opening at 30 bitcoin and a timer running just under seven days, which puts expiry around Sept. 4. Tagesspiegel, citing Der Spiegel, put the demand at about 2 million euros.
One number in that coverage will not survive contact with a calculator. Reuters rendered the demand as “30 bitcoin ($77,622),” offering the figure in parentheses as the dollar equivalent. Bitcoin traded at $79,132.61 on the morning of Aug. 28, Fortune reported, so 30 coins came to about $2.37 million. The published figure is close to what a single coin cost that day, which is the likeliest explanation for it, though the wire does not say so.
What Berlin has confirmed, and what it has not
The same scrutiny applied to Berlin’s own release opens a wider gap. Berlin says forensic work found further data outflows in the portfolio of one department, the Senate Department for Mobility, Transport, Climate Protection and Environment, and that the outflow occurred between Aug. 7 and Aug. 12. On content, the release commits to almost nothing: it cannot be ruled out that personal or other non-public data are affected, and the examination continues.
Nowhere does Berlin confirm that court files were taken. The judicial-document claim belongs to Rhysida, and Security Affairs said the group’s claims have not been independently verified. Wegner told reporters on Aug. 28 that officials had no account to give of what was taken or how much, with the assessment still running, Reuters reported.
That silence on content is the operative problem for anyone outside Berlin, because a transport and environment ministry routinely handles commercial filings, infrastructure tenders, and regulatory submissions. Rhysida’s listing claims 46,500 contracts. For external entities with regional bids, infrastructure projects, or public-private joint ventures, conducting a reliable notification analysis remains impossible until the state characterizes what is left, and Berlin has said only that it is still looking. The state has notified its data protection commissioner and the federal information security office, so the assessment is running; it is running somewhere the affected counterparties cannot see.
The official position has already moved once. Berlin first disclosed the incident on Aug. 17. Two days later Wegner said at a press conference that the city had been the victim of a hacker attack, and that the incident “war ernst und ist ernst,” it was serious and remains serious. He added that according to current knowledge no sensitive data had left the network. Seven days after that the chancellery published a release headlined “Mehr Daten beim IKT-Vorfall abgeflossen,” more data drained in the ICT incident. The revision landed about three and a half weeks before a Sept. 20 election. On the election itself Berlin has been specific: Spranger said the city’s election infrastructure had not been affected, and that according to security officials no data related to the election had been compromised, Reuters reported. On the wider question of what left, anyone building a chronology from press statements alone should assume the same thing can happen again.
Seven days from first signal to disconnection
The transport ministry first reported a data outflow on Aug. 7, the Berlin daily Tagesspiegel reported. That is the same date the chancellery gives as the start of the outflow window, and the two are different facts: only the second comes from an official document, and the internal report rests on Tagesspiegel alone. Both affected administrations came off the state network on Aug. 14, a date the chancellery confirms. Whatever explains the intervening week, the exfiltration Berlin now describes had finished two days before the cable was pulled, so the disconnection did not stop the outflow the state has since documented.
That interval is where the preservation question lives, and it is worth understanding why reconstructing it is hard. The joint advisory on Rhysida from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center, revised in April 2025, records that Rhysida actors used wevtutil.exe to clear Windows event logs, including system, application and security logs. Counsel who assume the logs will settle when a duty to preserve attached should ask early whether the logs still exist. Whether any were cleared in Berlin is not public.
The same advisory carries an instruction that reads differently once a victim reports stolen passwords. CISA and its partners record that Rhysida actors have dumped the NTDS.dit database from domain controllers, and they recommend domain-wide password resets plus double Kerberos ticket-granting-ticket resets wherever there is any indication that file was compromised. Rhysida’s Berlin listing claims plaintext credentials among the haul.
Refusal may also buy less deterrence here than it would against a single operator. The advisory records open-source reporting of observed instances in which Rhysida operated as a ransomware-as-a-service business, leasing tools and infrastructure to affiliates who split what victims pay. Whether the Berlin operators are affiliates or core members is not something the advisory establishes, and the distinction matters, because a refusal aimed at the brand may not reach whoever is actually holding the files.
The authorities do not converge on a leak-site download
If a refusal does not stop the files being published, the question moves to American counsel, and it has no uniform national answer. Suppose the dump lands and it contains a document your opponent would call privileged. Model Rule 4.4(b) is the reflex, and the reflex is wrong. The larger trouble sits underneath. Rule 4.4(b) is built around inadvertent transmission; the other authorities here reach retrieval from storage, or an unauthorized source, or say nothing about transmission at all. None squarely addresses a self-directed download from a criminal auction, and they do not converge on an answer.
Rule 4.4(b) reaches “a document or electronically stored information relating to the representation of the lawyer’s client,” and only where the lawyer “knows or reasonably should know” it was inadvertently sent. It then asks only that the receiving lawyer promptly notify the sender. James M. Altman, then a partner at Bryan Cave, wrote in The Professional Lawyer in 2011 that the rule requires nothing further: no duty to stop reading, none to return, none to destroy, none to follow the sender’s instructions. He was arguing the rule should be amended. The duties he proposed were never added, and the rule’s later broadening to cover electronically stored information alongside documents left the inadvertence limit exactly where it was.
Subsection (a) carries no such limit. It bars a lawyer from using “means that have no substantial purpose other than to embarrass, delay, or burden a third person,” and from using “methods of obtaining evidence that violate the legal rights of such a person.” The American Bar Association’s ethics committee raised 4.4(a) in a footnote to the opinion that follows, as a rule one might argue applies, and left it undecided. It is the provision that does not turn on whether anything was sent at all, and the opinion does not tell you what it means here.
The ABA’s Standing Committee on Ethics and Professional Responsibility drew the boundary in Formal Opinion 11-460 in August 2011. A document pulled by a third person from a place where it sits in storage was never inadvertently sent, the committee reasoned, and so the Model Rules impose no independent ethical duty to notify opposing counsel in that situation. Two qualifications travel with that conclusion and both get dropped in summary. Courts acting under their supervisory authority and rules of civil procedure may impose a notification duty that the Model Rules do not. And the committee said it will often be in the employer-client’s best interest to give notice and obtain a judicial ruling on admissibility before trying to use such material. That recommendation was framed for an employer that had pulled an employee’s emails off a workplace computer, not for a public criminal dump, and where no law compels notice it leaves the call with the client.
Which jurisdiction answered, and which one applies
Jurisdictions have supplied their own answers, and one comes close. The D.C. Bar Legal Ethics Committee, in Formal Advisory Opinion 318 in 2002, read what was then Rule 1.15(b), whose relevant language now sits in Rule 1.15(c), to require counsel in an adversary proceeding to refrain from reviewing and using a document obtained from an unauthorized source. Three conditions attach: the privilege is apparent on the document’s face, counsel knows the source lacked authority to disclose it, and counsel has no reasonable basis to conclude the privilege was waived. That is committee guidance rather than an adjudication, and it remains cited in current D.C. guidance. The comment to D.C.’s Rule 4.4 says the rule does not address the duties of a lawyer who receives a writing the lawyer knows or reasonably should know may have been wrongfully obtained by the sending person, and points readers to Opinion 318.
A limit rides inside that sentence. The comment does not define a sending person or say whether posting a file for download counts as sending it, so a self-directed leak-site download may not fit the formulation at all.
Which rules reach you is a separate question, and the Model Rules cannot answer it, because they are a model. The governing jurisdiction’s own choice-of-law provision controls, and the adopted versions differ. Model Rule 8.5 is the common template: a lawyer can answer to two jurisdictions’ disciplinary authority for the same conduct, and for conduct in connection with a matter pending before a tribunal the rules of the jurisdiction where the tribunal sits apply, unless that tribunal provides otherwise. Everything else falls to the rules where the conduct occurred, or where its predominant effect lands.
The first category is narrower than it sounds. It covers conduct connected to a matter already pending before a tribunal, which is not the same as litigation work generally. A lawyer who opens a dump during a pre-filing investigation is in the second category, which is a distinction that matters whenever counsel meets a leak before a matter is filed. D.C. shows how much the second category can move. For a lawyer licensed there and in another jurisdiction, its rule looks to the admitting jurisdiction where the lawyer principally practices, and reaches the predominant-effect result only where the conduct clearly has that effect in another jurisdiction where the lawyer is licensed. All of that governs your license. What a court will let you do with the file is a different question.
When stolen documents stay stolen
Publication does not launder provenance, at least not in an American decision involving documents published after a hack. In the Ashley Madison multidistrict litigation, Judge John A. Ross granted in part a motion to preclude use of stolen documents and barred plaintiffs and their counsel from using or referencing them in the consolidated complaint. Citing news coverage that quoted the material rather than the material itself bought the plaintiffs nothing, in the court’s reasoning, because the underlying information was stolen either way.
Its limit matters as much as its holding. The court expressly did not decide whether the same documents would ultimately be discoverable through formal discovery, so the ruling governs what counsel may plead from, not what counsel may ever obtain. Practitioners who cite Ashley Madison for a blanket prohibition are overreading it.
Waiver runs on a separate track and the authorities do not line up. Anne E. Conroy, in a student note published in the Brooklyn Law Review in 2017, found no consensus on whether privilege is automatically waived by an unauthorized disclosure. She mapped three judicial approaches: waiver on any loss of confidentiality, no waiver where a third party disclosed without authorization, and a futility view that treats privilege as spent once documents enter the public domain. A client alert published in October 2025 by Steven W. Teppler and Carly Rothstein of Mandelbaum Barrett, the firm’s own marketing content in a practice area it sells, takes the position that a breach does not automatically waive privilege. Both propositions can be true in different courtrooms, which is the practical problem.
Germany’s safe harbor names journalists, not lawyers
Cross-border matters pick up a second layer, and this one is written into a criminal code. Section 202d of the German criminal code makes it an offense to procure for oneself or another, transfer, disseminate or otherwise make accessible data that is not generally accessible and that another obtained through an unlawful act. The offense also requires intent, specifically to enrich oneself or a third party or to harm another. Punishment runs to three years or a fine, and subsection 2 caps it at whatever the predicate offense carries.
Every one of those elements does work. The intent requirement is a real filter, and a lawyer reviewing a public dump to advise a client on exposure is not obviously enriching anyone or aiming to harm. The threshold condition that the data be not generally accessible does similar work, though what it means for a dump already published to anyone who wants it is an open question the statutory text does not answer.
The exemption is where the drafting gets pointed. Subsection 3 lifts the offense for acts serving exclusively the fulfillment of lawful official or professional duties. It then names two categories in particular: officials feeding data exclusively into tax, criminal or regulatory-offense proceedings, and the professional acts of persons listed in Section 53(1) sentence 1 number 5 of the Code of Criminal Procedure, by which data are received, evaluated or published. Number 5 is the media category. Lawyers sit at number 3, and the cross-reference does not reach them. The enumeration is expressly non-exhaustive, so counsel would argue the general clause, but the statute names journalists and does not name lawyers.
Germany’s Constitutional Court addressed the provision in a chamber decision of March 30, 2022, declining to take up a journalists’ challenge to it. Declining is not deciding, but the reasoning is instructive. The chamber read subsection 3 as intended to exclude journalistic activity comprehensively, and read the intent element strictly, saying the harm or the enrichment has to be willed as a result rather than merely accepted. It addressed no profession other than journalism.
Steps worth taking before the clock runs out
Practical work is available this week and most of it is cheap. Run a conflicts-style sweep now for any matter with a Berlin nexus, meaning a German subsidiary, a pending Hague request, or discovery touching either affected Senate department. The point is to have the question arrive before the data does, rather than after an associate has already opened a file. Write the receipt protocol down while nobody is under deadline pressure: who may open a dump, who may not, where it gets stored, and who decides whether to tell the other side.
Then treat the ABA committee’s observation as risk management even though its facts are not yours. Giving notice and getting a ruling on admissibility before use may take a motion, or a simpler request for instructions. Guessing wrong can cost the matter. For anything already in litigation, a short letter to the court describing what arrived and asking for instructions builds a record and puts the question in front of a judge. It does not, on its own, make any resulting ruling immediately appealable. Nor does a favorable ruling displace whatever professional-conduct duties separately apply.
As for what the expiry is likely to produce, this group has run this play before. Rhysida opened a week-long auction of British Library data at 20 bitcoin, about 600,000 pounds at the time, Computer Weekly reported in November 2023. When it ended, the group published 573 GB across over 490,000 files, saying the release came to 90 percent of what it had taken and consisted of what it had not managed to sell, Computer Weekly’s security editor reported that Nov. 30. Whether the library ever engaged with the demand is not something the reporting establishes. What it establishes is that the data went out anyway.
Berlin’s forensic work continues and its emergency task force for the incident remains active, while the chancellery has published nothing after Aug. 28 answering the leak-site claim by name, based on its own 2026 press release index reviewed Aug. 31.
Coverage on this beat routinely focuses on a familiar question: what must you keep? This incident poses the opposite, addressing a scenario rarely addressed in standard firm incident-response playbooks. When the evidence arrives without a subpoena, who in your organization is authorized to decide whether anyone may read it?
News sources
- Der Regierende Bürgermeister Kai Wegner und Innensenatorin Iris Spranger: „Das Land Berlin lässt sich nicht erpressen” (Berlin.de, Senatskanzlei)
- Hackerangriff auf Landesnetz: Arbeit mit Hochdruck an Lösungen (Berlin.de)
- Pressemitteilungen 2026 (Berlin.de, Senatskanzlei)
- Ransomware group says it stole Berlin data, offers it for auction (Reuters, via Yahoo News syndication)
- Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network (The Hacker News)
- Rhysida Ransomware Group Targets Berlin Government Ahead of Vote (Security Affairs)
- Notfallpläne und Passwörter erbeutet? Wegner weist Erpresser-Ultimatum zurück (Tagesspiegel)
- #StopRansomware: Rhysida Ransomware (AA23-319A) (Cybersecurity and Infrastructure Security Agency)
- Rule 4.4: Respect for Rights of Third Persons (American Bar Association)
- Formal Ethics Opinion 11-460: Duty when Lawyer Receives Copies of a Third Party’s Email Communications with Counsel (American Bar Association)
- In re Ashley Madison Customer Data Security Breach Litigation, Memorandum and Order, MDL No. 2669 (U.S. District Court, Eastern District of Missouri)
- 202d StGB, Datenhehlerei (Gesetze im Internet, Bundesministerium der Justiz)
- 53 StPO, Zeugnisverweigerungsrecht der Berufsgeheimnisträger (Gesetze im Internet, Bundesministerium der Justiz)
- Model Rule 4.4(b) Should Be Amended (The Professional Lawyer, vol. 21 no. 1)
- Reevaluating Attorney-Client Privilege in the Age of Hackers (Brooklyn Law Review, vol. 82)
- When the Breach Hits the Docket: How Law Firms Should Respond When Client Files Leak to the Dark Web (Mandelbaum Barrett PC)
- Rhysida gang stole hundreds of gigabytes of British Library data (Computer Weekly)
- Internal documents leaked as Rhysida claims responsibility for British Library ransomware attack (Computer Weekly)
- British Library cyber attack explained: What you need to know (Computer Weekly)
- Current price of Bitcoin for August 28, 2026 (Fortune)
- Legal Ethics Opinion 318: Disclosure of Privileged Material by Third Party (District of Columbia Bar)
- Beschluss vom 30. März 2022, 1 BvR 2821/16 (Bundesverfassungsgericht)
- 28 U.S.C. § 1291, Final decisions of district courts (Office of the Law Revision Counsel)
- 28 U.S.C. § 1292, Interlocutory decisions (Office of the Law Revision Counsel)
- Rule 8.5: Disciplinary Authority; Choice of Law (American Bar Association)
- D.C. Rule 4.4: Respect for Rights of Third Persons (District of Columbia Bar)
- D.C. Rule 1.15: Safekeeping Property (District of Columbia Bar)
- D.C. Rule 8.5: Disciplinary Authority; Choice of Law (District of Columbia Bar)
Assisted by GAI and LLM technologies
Source: HaystackID published with permission from ComplexDiscovery OÜ
Advisor Note: This incident highlights an evolving challenge at the intersection of cybersecurity, data governance, and legal risk management: determining how organizations should handle potentially sensitive or privileged information that emerges through ransomware leak sites, extortion campaigns, or unauthorized data disclosures. Beyond system recovery and incident containment, organizations must be prepared to make defensible decisions regarding evidence preservation, data review protocols, privilege considerations, regulatory obligations, and cross-border legal exposure when stolen information becomes publicly accessible. The Berlin case also underscores the importance of establishing clear governance around who is authorized to access, assess, and act on leaked data before a crisis occurs.
HaystackID’s Cyber Discovery and Cybersecurity Services help organizations prepare for, investigate, and respond to cyber incidents through digital forensics, ransomware response support, insider threat investigations, incident response, and information governance expertise. By combining advanced cybersecurity capabilities with deep legal data intelligence and eDiscovery experience, HaystackID helps organizations navigate complex cyber events, balance operational resilience with evidentiary and legal requirements, and develop defensible workflows for managing sensitive data throughout the incident lifecycle. Learn more at HaystackID.com.




