Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2604+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Berlin Refuses to Pay Rhysida Ransom Over Alleged Senate Data Theft
Berlin Refuses to Pay Rhysida Ransom Over Alleged Senate Data Theft
NEWS

Berlin Refuses to Pay Rhysida Ransom Over Alleged Senate Data Theft

Rhysida ransomware claims 5.7TB stolen from a Berlin Senate department; city officials say they will not pay the 30 BTC ransom demand.

Dylan H.

News Desk

August 31, 2026
3 min read

Berlin Won't Pay Rhysida's Extortion Demand

The city government of Berlin has confirmed it will not pay a ransom demanded by the Rhysida ransomware group, which claims to have exfiltrated over 5.7 terabytes of data from the Berlin Senate Department for Mobility, Transport, Climate Protection, and Environment.

Incident Summary

  • Data allegedly exfiltrated between August 7–12, 2026
  • Breach discovered by Berlin authorities on August 14, 2026
  • Rhysida posted its extortion claim publicly on August 28, 2026
  • Both affected departments' networks were taken offline the day the breach was discovered

What Rhysida Claims to Have Stolen

According to the threat actor's claims, the stolen archive includes:

  • Personal information belonging to 12,000+ individuals
  • Over 16,000 email addresses and nearly 12,000 phone numbers
  • Financial documents, contracts, HR files, and payroll data
  • Plaintext credentials and lawsuit case files
  • Payment information, including IBANs
  • Passport and ID document data

Berlin's Response

Governing Mayor Kai Wegner and Senator Iris Spranger confirmed that Rhysida demanded 30 bitcoin — roughly $2.3 million at time of writing — and stated the city would not negotiate or pay.

City officials say the investigation is being handled jointly with state criminal police and federal security agencies. Limited additional detail has been released publicly while the investigation remains active.

Who Is Rhysida

Rhysida is a ransomware-as-a-service operation that has previously targeted healthcare providers, educational institutions, and government bodies, typically combining data exfiltration with encryption and threatening public leaks to pressure victims into paying. The group's decision to target a European capital's government infrastructure underscores the continued willingness of ransomware operators to strike public-sector targets despite the reputational and legal risk.

Why This Matters

  • Public-sector targeting continues: government bodies remain attractive targets due to the sensitivity of the data they hold and pressure to restore services quickly.
  • Non-payment stance: Berlin's refusal to pay aligns with growing government guidance (including from CISA and European counterparts) discouraging ransom payments, though it raises the likelihood that stolen data will be leaked or sold.
  • Scale of exposure: even without encryption, the exfiltration-only extortion model can expose sensitive personal and financial data belonging to thousands of residents and employees.

Recommendations for Organizations

  1. Segment and monitor sensitive departments handling financial and HR data — these are prime exfiltration targets.
  2. Maintain offline, tested backups so recovery does not depend on ransom payment.
  3. Have a pre-approved incident response and communications plan for extortion scenarios, including legal and law-enforcement contacts.
  4. Assume exfiltration, not just encryption — modern ransomware operators prioritize data theft even when encryption is not deployed.

Source: SecurityWeek

#Ransomware#Cybercrime#Rhysida#Germany#Extortion#Government

Related Articles

Swiss Rail Giant Stadler Refuses $12.3M Ransom Demand from Everest Group

Stadler Rail has publicly rejected a CHF 10 million (~$12.3M USD) ransom demand from the Everest extortion group following a breach of a supplier...

4 min read

Swiss Rail Giant Stadler Rejects $12.3M Ransom Demand After Cyberattack

Swiss rail vehicle manufacturer Stadler Rail has publicly refused to pay a CHF 10 million (~$12.3M USD) ransom demanded by the Everest ransomware group...

5 min read

ATF Breach Hit System Holding Investigation-Target Data, Officials Say

ATF says the Qilin-linked breach hit a standalone system holding data on investigation targets, not gun-owner records, amid a 'major incident' probe.

3 min read
Back to all News