Berlin Won't Pay Rhysida's Extortion Demand
The city government of Berlin has confirmed it will not pay a ransom demanded by the Rhysida ransomware group, which claims to have exfiltrated over 5.7 terabytes of data from the Berlin Senate Department for Mobility, Transport, Climate Protection, and Environment.
Incident Summary
- Data allegedly exfiltrated between August 7–12, 2026
- Breach discovered by Berlin authorities on August 14, 2026
- Rhysida posted its extortion claim publicly on August 28, 2026
- Both affected departments' networks were taken offline the day the breach was discovered
What Rhysida Claims to Have Stolen
According to the threat actor's claims, the stolen archive includes:
- Personal information belonging to 12,000+ individuals
- Over 16,000 email addresses and nearly 12,000 phone numbers
- Financial documents, contracts, HR files, and payroll data
- Plaintext credentials and lawsuit case files
- Payment information, including IBANs
- Passport and ID document data
Berlin's Response
Governing Mayor Kai Wegner and Senator Iris Spranger confirmed that Rhysida demanded 30 bitcoin — roughly $2.3 million at time of writing — and stated the city would not negotiate or pay.
City officials say the investigation is being handled jointly with state criminal police and federal security agencies. Limited additional detail has been released publicly while the investigation remains active.
Who Is Rhysida
Rhysida is a ransomware-as-a-service operation that has previously targeted healthcare providers, educational institutions, and government bodies, typically combining data exfiltration with encryption and threatening public leaks to pressure victims into paying. The group's decision to target a European capital's government infrastructure underscores the continued willingness of ransomware operators to strike public-sector targets despite the reputational and legal risk.
Why This Matters
- Public-sector targeting continues: government bodies remain attractive targets due to the sensitivity of the data they hold and pressure to restore services quickly.
- Non-payment stance: Berlin's refusal to pay aligns with growing government guidance (including from CISA and European counterparts) discouraging ransom payments, though it raises the likelihood that stolen data will be leaked or sold.
- Scale of exposure: even without encryption, the exfiltration-only extortion model can expose sensitive personal and financial data belonging to thousands of residents and employees.
Recommendations for Organizations
- Segment and monitor sensitive departments handling financial and HR data — these are prime exfiltration targets.
- Maintain offline, tested backups so recovery does not depend on ransom payment.
- Have a pre-approved incident response and communications plan for extortion scenarios, including legal and law-enforcement contacts.
- Assume exfiltration, not just encryption — modern ransomware operators prioritize data theft even when encryption is not deployed.
Source: SecurityWeek