Palantir was not in the letter
Facts are theirs. Interpretation is mine.
A German district refused an American cybersecurity firm access to its network in the middle of a breach investigation. A specialist security account reported that one of the district's reasons was the vendor's ties to Palantir. The letter, as the outlet holding it reported the letter, does not name that company.
What was published
On 6 September 2026, the X account International Cyber Digest posted that Berlin's Lichtenberg district was refusing to let CrowdStrike's Falcon agent onto its network because of its US ties. The post listed the district's reasons as visibility into staff devices and personal data, US legal disclosure duties, and the vendor's Palantir ties. A separate line stated that ICD had confirmed documents in the Rhysida leak contained cleartext credentials. The post carried a CrowdStrike logo and a stock image of the Brandenburg Gate. It named neither RBB nor Tagesspiegel.

What the letter says
RBB reported the refusal first. Its broadcast went out on 5 September 2026 at 18:40, and its written article, published 6 September at 12:32, states that the internal document is held exclusively by RBB.
What RBB reports from Lichtenberg's letter:
- Falcon Agent would gain what the district calls virtually unlimited access to all data in the district, including personal data.
- The district states the agent would likely prove impossible to remove.
- The software is capable of monitoring all work equipment, and therefore administrative staff, with official data collected and derived.
- Quoting the letter directly: "According to feedback from other districts, it also leads to sometimes serious disruptions in the functionality of specialized procedures, services, and programs, and poses a significant risk to the operational capacity of the district office."
- Lichtenberg has already checked its own systems and found no evidence the attackers were active there. It uses a competitor's product for protection.
- CrowdStrike gets access only if the Senate assumes full responsibility, including all costs.
Palantir does not appear in that account. Neither does US disclosure law. RBB describes CrowdStrike as a US company in its own voice, as a plain description of the vendor. It does not report that as a ground the district gave.
That is the correction. Not a scoop dispute. A company name entered a specialist feed that is not in the letter as the outlet holding it reported the letter.
What is actually being argued
Strip out what the reported letter does not say and there is still a real fight underneath.
The Senate Chancellery commissioned CrowdStrike to examine state IT systems for damage, traces and remnants of Rhysida following the mid-August intrusion. RBB reports that the Chancellery told the district on Saturday evening that the software was the only option available and that the Senate would assume responsibility for its use. Lichtenberg still refused.
That is a district declining to put an agent it cannot contract, cannot document and believes it cannot remove onto servers holding personal data, from a vendor already commissioned above it. The Senate's answer is to absorb the legal and financial risk so the deployment proceeds anyway. A sovereignty argument settled by a liability transfer, not a security argument.
RBB adds its own context that in 2024 a faulty Falcon update caused worldwide IT outages, with Berlin Brandenburg Airport among those affected. RBB presents this as background, not as a reason stated in the letter.
The number
Rhysida demanded 30 bitcoin. According to the Senate Chancellery, that is approximately two million euros. Berlin refused to pay, an ultimatum expired, and the group published the data for download on Friday afternoon.
What stands
The credentials claim ICD made is true. It is not true that ICD confirmed it. Palantir is not in the letter as reported. Both of those things can be established without access to a single paywalled page.

One district asked who controls an agent after the vendor is already inside. That question is worth reporting accurately, which means reporting what the letter says rather than what the vendor's corporate associations suggest it might have said.
Sourcing note
This piece is built on rbb24's reporting and on a screenshot of the ICD post. I do not hold Lichtenberg's letter. Every claim about its contents is RBB's account of a document they hold exclusively, and is attributed to them as such throughout rather than quoted as though I had read it myself.
Tagesspiegel's coverage of the same letter sits behind a paywall requiring bank details at signup. It is not cited here. Where German-language phrasing from the original letter would strengthen a quotation, I have used RBB's reporting in translation rather than reconstruct German I have not seen.
Sources
- 5 September 2026, 18:40 • rbb|24 • Broadcast, audio by Sebastian Schöbel
- 6 September 2026, 12:32 • rbb24 • "Lichtenberg district rejects Berlin Senate's anti-hacking software" • Tier A for RBB's account of the letter
- 6 September 2026 • @IntCyberDigest • Post on X • Screenshot on file • Tier A as a record of ICD's own words
- 2024 Falcon update outage • tagesschau.de, cited by rbb24 as its own added context
Clayton Bax
Published under ONYX Digital Intelligence Following the #OnyxAudit methodology.
- X: @onyxaudit
- Email: onyxdigitalintelligence85@protonmail.com
- https://github.com/Baximus855
- @Onyx_Digital@mastodon.social
"Adjacent to true is not true."
Truth has no flag nor favour, only a standard. And it's heavy