City Confirms Extortion Attempt, Refuses to Pay
Berlin's city administration has confirmed that cybercriminals are attempting to extort the state government after the Rhysida ransomware gang listed it on their dark-web data leak site. The incident was discovered in mid-August, with affected Senate departments disconnected from the state network on August 14, 2026; Rhysida publicized the claim on August 28.
Berlin authorities have confirmed data was stolen and that the government received an extortion demand, but they have not publicly attributed the attack to Rhysida or verified the group's claims about the volume or contents of the stolen data.
Incident Summary
| Field | Details |
|---|---|
| Target | Berlin state administrative network |
| Threat Actor | Rhysida ransomware gang (claimed) |
| Network Disconnect | August 14, 2026 |
| Public Claim | August 28, 2026 |
| Claimed Volume | 5.79 TB / ~1.44 million files |
| Ransom Demand | 30 BTC (~$2.3M), 7-day auction countdown |
| Investigation | State Criminal Police Office, public prosecutor, federal security agencies |
What Rhysida Claims to Have Stolen
Per Rhysida's own listing, the exfiltrated data spans government, legal, financial, contractual, HR, infrastructure, health, and mapping records. Separate reporting has cited 46,500 contracts, along with emails, phone numbers, passwords, and classified material among the claimed haul. None of these specifics have been independently verified by Berlin authorities.
Berlin's Response
Mayor Kai Wegner and Interior Senator Iris Spranger issued a joint statement rejecting the ransom demand: "The state of Berlin will not submit to extortion." Officials say they have found no evidence that election data was compromised, and that the technical environment supporting the upcoming Berlin House of Representatives election on September 20 is considered secure.
The Senate Chancellery says the state's data protection commissioner and Germany's Federal Office for Information Security (BSI) are being kept informed as the investigation continues. Authorities have not ruled out that personal or other non-public data was exposed.
Rhysida's Track Record
Rhysida has operated since at least May 2023, targeting governments, hospitals, schools, manufacturers, and technology companies — typically stealing data and encrypting systems before demanding cryptocurrency payment. Leak-site tracking put Rhysida's total victim count at 280 as of August 29, nine of them in Germany, including the Stuttgart city administration in May 2026 and aid organization Welthungerhilfe in June 2025.
Why It Matters
A ransomware hit on a state capital's administrative network, timed weeks before a state election, raises the stakes beyond a typical data-theft extortion case — even with election systems reportedly unaffected. The case is a reminder that government network segmentation between "administrative" and "electoral" systems needs to hold up under real attacker access, not just on paper.