Berlin Says It Will Not Pay Extortionists After State Network Breach

Berlin’s state government has confirmed that attackers are attempting to extort money after compromising the city’s administrative network, but officials say no ransom will be paid.Additional forensic...

Berlin’s state government has confirmed that attackers are attempting to extort money after compromising the city’s administrative network, but officials say no ransom will be paid.

Additional forensic analysis found that data was transferred from systems operated by the Senate Department for Mobility, Transport, Climate Protection and the Environment between August 7 and August 12. Investigators are still determining what information was taken, and authorities have warned that personal or otherwise confidential data may be involved.

The department reported the suspected data loss on August 7 and was disconnected from the wider state network on August 14. Berlin has not released an official estimate of the volume of information removed. However, a post published on the Rhysida ransomware group’s leak site reportedly claims access to approximately 5.79 terabytes of data, representing about 1.44 million files and information linked to more than 12,000 people. Those claims have not been independently verified.

Berlin’s governing mayor, Kai Wegner, described the incident as blackmail following a special Senate meeting. The state criminal police, public prosecutors and federal security authorities are investigating, although officials have not formally attributed the attack to a particular group. German media have linked it to Rhysida based on the group’s leak-site listing and sources familiar with the response.

Investigation and recovery continue

Berlin’s data protection commissioner and Germany’s Federal Office for Information Security have been informed. Authorities said they are continuing forensic work and network checks. Officials have also said that, based on current findings, systems relevant to the September 20 state election were not affected by data loss and that the election environment remains secure.

The network disruption temporarily affected services including housing benefit applications and payments. Senate departments were reconnected on August 23, although investigations remain underway.

U.S. and international cybersecurity agencies have previously described Rhysida activity involving compromised accounts, phishing and exploitation of vulnerabilities such as Zerologon. Their guidance discourages ransom payments, noting that payment does not ensure data recovery and can encourage further attacks. Recommended defenses include multifactor authentication, prompt vulnerability remediation and network segmentation.