Onyx Digital Intelligence.

Palantir was not in the letter

Facts are theirs. Interpretation is mine.

A German district refused an American cybersecurity firm access to its network in the middle of a breach investigation. A specialist security account reported that one of the district's reasons was the vendor's ties to Palantir. The letter, as the outlet holding it reported the letter, does not name that company.

What was published

On 6 September 2026, the X account International Cyber Digest posted that Berlin's Lichtenberg district was refusing to let CrowdStrike's Falcon agent onto its network because of its US ties. The post listed the district's reasons as visibility into staff devices and personal data, US legal disclosure duties, and the vendor's Palantir ties. A separate line stated that ICD had confirmed documents in the Rhysida leak contained cleartext credentials. The post carried a CrowdStrike logo and a stock image of the Brandenburg Gate. It named neither RBB nor Tagesspiegel.

Screenshot_20260907_185027_Chrome

What the letter says

RBB reported the refusal first. Its broadcast went out on 5 September 2026 at 18:40, and its written article, published 6 September at 12:32, states that the internal document is held exclusively by RBB.

What RBB reports from Lichtenberg's letter:

Palantir does not appear in that account. Neither does US disclosure law. RBB describes CrowdStrike as a US company in its own voice, as a plain description of the vendor. It does not report that as a ground the district gave.

That is the correction. Not a scoop dispute. A company name entered a specialist feed that is not in the letter as the outlet holding it reported the letter.

What is actually being argued

Strip out what the reported letter does not say and there is still a real fight underneath.

The Senate Chancellery commissioned CrowdStrike to examine state IT systems for damage, traces and remnants of Rhysida following the mid-August intrusion. RBB reports that the Chancellery told the district on Saturday evening that the software was the only option available and that the Senate would assume responsibility for its use. Lichtenberg still refused.

That is a district declining to put an agent it cannot contract, cannot document and believes it cannot remove onto servers holding personal data, from a vendor already commissioned above it. The Senate's answer is to absorb the legal and financial risk so the deployment proceeds anyway. A sovereignty argument settled by a liability transfer, not a security argument.

RBB adds its own context that in 2024 a faulty Falcon update caused worldwide IT outages, with Berlin Brandenburg Airport among those affected. RBB presents this as background, not as a reason stated in the letter.

The number

Rhysida demanded 30 bitcoin. According to the Senate Chancellery, that is approximately two million euros. Berlin refused to pay, an ultimatum expired, and the group published the data for download on Friday afternoon.

What stands

The credentials claim ICD made is true. It is not true that ICD confirmed it. Palantir is not in the letter as reported. Both of those things can be established without access to a single paywalled page.

Screenshot_20260907_202853_X

One district asked who controls an agent after the vendor is already inside. That question is worth reporting accurately, which means reporting what the letter says rather than what the vendor's corporate associations suggest it might have said.

Sourcing note

This piece is built on rbb24's reporting and on a screenshot of the ICD post. I do not hold Lichtenberg's letter. Every claim about its contents is RBB's account of a document they hold exclusively, and is attributed to them as such throughout rather than quoted as though I had read it myself.

Tagesspiegel's coverage of the same letter sits behind a paywall requiring bank details at signup. It is not cited here. Where German-language phrasing from the original letter would strengthen a quotation, I have used RBB's reporting in translation rather than reconstruct German I have not seen.

Sources


Clayton Bax

Published under ONYX Digital Intelligence Following the #OnyxAudit methodology.

"Adjacent to true is not true."

Truth has no flag nor favour, only a standard. And it's heavy

#CrowdStrike #Germany #OnyxAudit #Rhysida #sourcing