Technology

Berlin Refuses to Pay Ransomware Group That Stole City Data

Berlin's state government confirmed Friday that it is the target of an extortion attempt following a cyberattack on the city's administrative network, and said it will not meet the attackers' demands. [1] The ransomware group Rhysida, identified by Der Spiegel and confirmed through leak-site monitoring, posted an entry titled "Berlin, Germany" to its darknet site on August 28, claiming to have scanned 5.79 terabytes of data across roughly 1.44 million files, including personal information on 12,076 individuals. [1]

Governing Mayor Kai Wegner made the confirmation blunt. "The state of Berlin is being blackmailed," he said after a special Senate session at the Rotes Rathaus, in a statement posted to the city's official portal. [2] State criminal police, the public prosecutor, and federal security authorities are investigating; no group has been officially named by Berlin's own Senate Chancellery, though Der Spiegel's attribution to Rhysida has gone unchallenged.

The breach itself dates back further than Friday's confirmation. Berlin first disclosed a compromise of its state network on August 17, isolating two Senate departments — including the Department for Mobility, Transport, Climate Protection and Environment — after forensic work found data leaving the network between August 7 and August 12. [1] All affected departments were reconnected by August 23, but forensic scanning has continued, and the Senate's public statements have offered no itemized account of what left the network. The only specific figure in circulation is the attackers' own claim.

That gap matters because Berlin's state parliament, the Abgeordnetenhaus, holds elections on September 20 — three weeks after Friday's confirmation. Interior Senator Iris Spranger said systems relevant to the election are secure and that no data left that specific infrastructure, but the broader breach touches personal records whose scope Berlin itself has not yet quantified. As of August 29, the Senate had issued no public guidance for the roughly 12,000 individuals whose information the attackers claim to hold. [1] A city government heading into a contested election while unable to tell affected residents whether their data is safe is a story about institutional readiness, not merely a network intrusion.

Rhysida is a known quantity to federal cybersecurity agencies. A joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center, first issued in November 2023, documents the group's typical entry points: compromised VPN credentials at organizations without multi-factor authentication, the Zerologon privilege-escalation flaw Microsoft patched in 2020, and phishing. [3] The advisory explicitly states that federal agencies "do not encourage paying ransom," since payment neither guarantees data recovery nor discourages future attacks. Leak-site tracking lists 280 Rhysida victims to date, nine of them in Germany, including Stuttgart's city administration in May 2026 and the aid organization Welthungerhilfe.

Berlin's posture — refuse to pay, investigate, communicate cautiously — follows that federal guidance to the letter. What it does not yet do is answer the question a voter heading to the polls in three weeks might reasonably ask: whether the institution asking for their ballot has secured the data it already lost.

-- DAVID CHEN, Beijing

Get the New Grok Times in your inbox

A weekly digest of the stories shaping the timeline — delivered every edition.

No spam. Unsubscribe anytime.