Berlin Refuses €2 Million Ransom as Rhysida Hackers Leak State Data
The German capital's refusal to yield to ransomware demands led to the public release of sensitive administrative data on the dark web.
The Berlin state administration has fallen victim to a major cyberattack by the Rhysida ransomware group, resulting in the leak of sensitive government data. The breach underscores the ongoing struggle between municipal governments and sophisticated extortionists targeting public infrastructure.
Rhysida targeted two specific agencies: the Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and the Environment. The hackers demanded a ransom of 30 Bitcoin, valued at approximately €2 million ($2.3 million), in exchange for the stolen information. Berlin officials, led by Mayor Kai Wegner and Interior Senator Iris Spranger, refused to pay the demand. Following this refusal, the hackers published the exfiltrated data on the dark web.
Timeline of the Breach
Investigation into the incident reveals that data exfiltration likely occurred between August 7 and August 12, 2026. The breach was detected around August 14, when the affected agencies were temporarily disconnected from the state network for approximately one week. This emergency shutdown disrupted essential public services, including the processing of housing benefit applications. Rhysida, a ransomware operation active since 2023, has a documented history of targeting healthcare and government institutions on a global scale.
Strategic Implications
This incident serves as a high-profile test of the German government's strict "no-pay" policy regarding cyber-extortion. By refusing the demand, Berlin aims to discourage future attacks by demonstrating that ransomware payments are not a guaranteed outcome. Mayor Kai Wegner emphasized this stance, stating, "The state of Berlin will not allow itself to be blackmailed."
However, the decision to refuse payment carries significant risks. The leak of administrative data potentially exposes critical infrastructure plans, including details regarding Berlin's water supply and thousands of private administrative proceedings. This creates a lasting security and privacy vulnerability for both the city's strategic operations and its citizens.
Future Outlook
Berlin authorities continue to probe the extent of the damage and the specific nature of the leaked files. While the immediate network crisis has been managed, the long-term impact of the data exposure remains a primary concern for security analysts. The incident highlights a systemic vulnerability in municipal administrative networks, suggesting that further hardening of state digital infrastructure is required to prevent similar exfiltrations in the future.