Berlin Refuses to Pay Extortionists as State-Network Breach Widens
Berlin's state government confirmed it is the target of an extortion attempt after the August compromise of its state administrative network, and says it will not meet the extortionists' demands. Forensics also found new data outflows in the mobility and transport department.
BERLIN: The city-state's government has confirmed it is the target of an extortion attempt following the August compromise of its state administrative network, and said it will not meet the extortionists' demands. In the same statement, officials disclosed additional data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with the theft dated between August 7 and August 12.
The confirmation, reported by The Hacker News on August 28 and drawn from the Senate Chancellery's own releases, moves the Berlin incident from a contained IT outage to an active extortion case. Governing Mayor Kai Wegner put it plainly after a special Senate session at the Rotes Rathaus: "The state of Berlin is being blackmailed," he said in the English version published on Berlin's city portal. What that means for the people whose records may sit in those systems is still being worked out.
What Berlin Newly Disclosed
The fresh detail is the mobility and transport department. Forensic work found that data left that portfolio between August 7 and August 12, and the department first reported an outflow on August 7, seven days before it was cut off from the network on August 14. Scope and content are still under examination, and the Senate Chancellery said personal or other non-public data cannot be excluded from what was taken.
The Numbers Berlin Has Not Confirmed
Berlin has published no figure for how much data left the network. The only itemized account in circulation is the attackers' own: a leak-site post indexed on August 28 that claims 5.79 terabytes of data, around 1.44 million files, and personal information on 12,076 individuals. Those are the criminals' claims, not a verified count, and the Senate's releases carried no guidance for people whose records may be among the data. Treat the volume and the victim tally as unconfirmed until Berlin's forensic review says otherwise.
Who Is Behind It, and What Officials Will Not Say
Berlin officials have named no group. The Senate Chancellery said the state criminal police, the public prosecutor, and federal security authorities are investigating and have identified no perpetrator. Attribution so far rests on reporting: Der Spiegel named the Rhysida ransomware group on August 28, citing an entry on the group's darknet leak site and security sources involved in the response, and The Hacker News confirmed through a leak-site monitoring service that an entry titled "Berlin, Germany" appeared on Rhysida's site that day. That is a strong lead, not an official finding. There is also no confirmed link between this breach and any earlier Berlin ministries incident; nothing in the public record establishes one.
On the money, caution applies again. German outlets including Der Spiegel and heise report a demand of 30 bitcoin, worth roughly two million euros, with publication of the data threatened if Berlin refuses. No ransom figure appeared in the leak-site entry itself, and the state has not confirmed an amount. Berlin's position, stated by Wegner and Interior Senator Iris Spranger, is that it will not pay.
What the Rhysida Playbook Looks Like
If Rhysida is responsible, defenders already have a documented profile to work from. A November 2023 joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) records three recurring routes into victim networks: valid accounts on external-facing remote services such as VPNs that lack multi-factor authentication, the Zerologon privilege-escalation flaw (CVE-2020-1472) that Microsoft patched in August 2020, and phishing. The same advisory is blunt about payment: "the FBI and CISA do not encourage paying ransom," because payment does not guarantee recovery and may embolden attackers to hit others.
Rhysida is not a niche actor. A leak-site monitoring service listed 280 claimed victims as of August 29, nine of them in Germany, including the Stuttgart city administration in May 2026. The group drew wide attention when it hit the British Library in 2023, and researchers have documented overlap with the older Vice Society crew, which Microsoft tracks as Storm-0832.
Rhysida typically runs a double-extortion model, stealing data before encrypting systems and threatening to publish the files if a victim declines to pay. That is why the pressure point here is the stolen data itself, not only the days of downtime, and it is what any no-pay decision has to weigh.
Berlin is only the latest European public body to face data theft and extortion. The European Commission confirmed a cloud infrastructure breach after ShinyHunters data-theft claims, and German lawmakers have been targeted directly, with Berlin blaming Russia for Signal phishing aimed at members of parliament. The bloc is also tightening its baseline: the European Commission has referred four member states to the Court of Justice over delays implementing the NIS2 directive, which sets security and incident-reporting duties for public administration and essential services.
Services, Elections, and Recovery
The public account has shifted as forensics caught up. Berlin first reported the compromise on August 17, saying both affected departments had been isolated since the previous Friday, and at an August 19 press conference Wegner said that, on the knowledge available then, no sensitive data had left the state network. The later confirmation of outflows from the mobility and transport portfolio revised that early read, a pattern common in the first weeks of a breach investigation.
The operational disruption has been real but bounded. Housing benefit applications and payments were unavailable while the two departments were off the network, and all Senate departments were reconnected on August 23. Spranger said that, as things stand, no data left the areas relevant to the conduct of the September 20 Abgeordnetenhaus election, and that her security officers regard the election environment as secure. Berlin's state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed as forensic work continues.
My read: The story here is not the theft, it is the policy. By stating a no-pay position early and in public, Berlin converts a live negotiation into a fixed constraint, which removes the attackers' leverage to extract a quiet settlement and shifts the whole incident onto recovery and notification. That only works if the operational groundwork was laid before the breach: segmented networks, restorable offline backups, and a communications plan that does not depend on the attacker's cooperation. The refusal is the visible part. Whether Berlin can restore services and notify affected people without a decryptor is the part that will actually decide how this ends. (This is assessment, not a reported fact.)
● PUBLIC-SECTOR EXTORTION RESPONSE How a prepared administration turns a ransom demand into a recovery process. |
THE EXTORTION DEMAND Attackers exfiltrate data, threaten to publish it, and set a payment deadline. |
| ↓ |
CONTAIN AND SCOPE Isolate affected departments and use forensics to establish what left the network. |
| ↓ |
DECIDE ON POLICY, NOT PANIC A no-pay position set in advance removes the attacker’s leverage. Payment does not guarantee deletion or recovery. |
| ↓ |
RESTORE FROM OFFLINE BACKUPS Recover services from segmented, tested backups instead of an attacker’s decryptor. |
| ↓ |
NOTIFY PEOPLE AND REGULATORS Tell affected residents, the data-protection authority, and security agencies while the review continues. |
Source: CyberSignal analysis of CISA advisory AA23-319A and Berlin Senate Chancellery statements. |
The no-pay path a prepared public-sector defender follows once data theft turns into extortion. Source: CyberSignal analysis of CISA advisory AA23-319A and Berlin Senate Chancellery statements.
What Public-Sector Defenders Should Take From This
For municipal and state security teams, Berlin is a rehearsal for the decision you do not want to make under pressure. Build the answer before an incident, not during one:
- Segment administrative networks so a foothold in one department, here mobility and transport, cannot roam across the rest of the state estate. Segmentation is also what makes a confident "no data left the election systems" statement possible.
- Keep offline, tested backups. A no-pay stance is only credible if you can restore without the attacker's decryptor. Rehearse the restore, do not assume it works.
- Write the no-pay decision and the communications plan in advance. A rehearsed incident response process turns a ransom deadline into a sequence of known steps rather than an improvised crisis.
- Plan to notify affected residents and regulators. When personal data "cannot be excluded," the people whose records were taken need guidance, and data-protection law across the EU expects prompt disclosure.
- Close the routes Rhysida uses. Enforce phishing-resistant MFA on every remote-access service, and prioritize remediation of known-exploited flaws like Zerologon (CVE-2020-1472) rather than treating old CVEs as low risk.
Primary Documents
- Senate Chancellery statement on the extortion attempt and further data outflows
- Berlin city portal: Wegner and Spranger on refusing extortion
- CISA, FBI and MS-ISAC joint advisory on Rhysida ransomware (AA23-319A)
- The Hacker News: Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network