Berlin Refuses €2 Million Ransom After Rhysida Breach Exposes State Data
Governing Mayor Kai Wegner rejects demands from the Rhysida ransomware group following the theft of nearly 6 TB of administrative data.
Berlin's state administrative network was compromised in a massive cyberattack in August 2026, leading to the theft of several terabytes of sensitive government data. The city has since formally rejected a multimillion-euro ransom demand from the attackers.
The ransomware group Rhysida claimed responsibility for the breach, which occurred between August 7 and August 12, 2026. According to reports, the hackers exfiltrated between 5.79 TB and nearly 6 TB of data from the BeLa (Berlin state administrative) network. The stolen archives include login credentials, government contracts, and records related to administrative fine proceedings. In exchange for the return or deletion of the data, Rhysida demanded a ransom of 30 bitcoin, valued at approximately 2 million euros ($2.3 million).
A Hardline Stance on Blackmail
Governing Mayor Kai Wegner responded to the crisis with a definitive refusal to negotiate with the cybercriminals. Wegner explicitly stated that Berlin would not pay the ransom, asserting that "Berlin will not allow itself to be blackmailed." This decision follows a growing trend among European governments to avoid paying ransoms, as such payments are often seen as incentives for future attacks and provide no guarantee that stolen data will actually be deleted.
Implications for State Security
The scale of the exfiltration highlights a significant vulnerability in the city's administrative infrastructure. The loss of nearly 6 TB of data—including internal contracts and credentials—creates a long-term security risk, as this information can be used for further targeted phishing attacks or to expose sensitive state operations. By refusing to pay, Berlin is prioritizing the principle of non-compliance over the immediate recovery of data, shifting the focus toward damage control and the hardening of its digital defenses.
The Path Forward
While the city has taken a firm public stance, the full extent of the leaked data's impact remains to be seen. Authorities are now tasked with auditing the BeLa network to close the entry points used by Rhysida and notifying individuals whose data may have been compromised in the fine proceedings. Observers are watching to see if the hackers will release the stolen archives publicly as retaliation for the city's refusal to pay.