Rhysida ransomware group demanded 30 bitcoin—approximately $2.3 million—for 5.7 terabytes of data stolen from Berlin’s state administrative network, but Governing Mayor Kai Wegner flatly refused to negotiate, stating “The state of Berlin is being blackmailed” during a public confirmation of the extortion attempt on August 31. The breach, which occurred between August 7 and August 12 before Berlin disconnected affected networks on August 14, exposed personal information on 12,076 individuals, 16,000+ email addresses, nearly 12,000 phone numbers, financial documents, credentials, and sensitive government files from the Senate Department for Mobility, Transport, Climate Protection and Environment.
Rhysida’s August 28 Tor Leak Site Claim Following Berlin’s August 17 Public Disclosure
Rhysida briefly posted Berlin on its Tor-based leak site on August 28, following the city’s August 17 public disclosure of the breach. Berlin detected the intrusion and shut down affected departments’ networks on August 14 to contain further compromise. The exfiltration window of August 7 through August 12 gave the attackers five days to extract 5.7 to 5.79 terabytes of data before Berlin’s isolation response. The timeline shows Berlin moved quickly after detection—shutting down networks within two days of discovering the intrusion and publicly disclosing the breach three days later—but Rhysida had already completed its data exfiltration during the five-day window before detection.
The Rhysida group’s August 28 posting came 11 days after Berlin’s public disclosure, suggesting the ransomware operators waited to see whether Berlin would negotiate privately before escalating to a public leak site threat. The demand for 30 bitcoin, approximately $2.3 million, represents the extortion price for withholding public release of the 5.7 terabytes of government files. Rhysida’s brief posting indicates the group posted the claim and then removed it, a tactic some ransomware groups use to pressure victims while maintaining some operational security.
12,076 Individuals’ Personal Information, Financial Documents, and Government Administrative Records
The stolen data includes personal information on 12,076 individuals, maps, geodata, and administrative records spanning Berlin’s transport, climate, and environmental departments. The personal information encompasses 16,000+ email addresses and nearly 12,000 phone numbers, creating significant phishing and social engineering risk for affected individuals. Financial documents and credentials were also compromised, though Berlin has not specified which systems’ credentials were stolen or what financial records the attackers accessed.
Senator Iris Spranger joined Wegner in confirming the extortion attempt and the city’s decision not to pay. Berlin emphasized that no sensitive election-related data left the network and airport operations remained unaffected despite the breach’s focus on mobility and transport infrastructure. The clarification about election data suggests Berlin conducted a scope assessment to determine which specific data types were exfiltrated, and the airport operations statement addresses public concern about critical infrastructure impact.
Berlin’s Federal-Supported Forensic Investigation and Refusal to Fund Ransomware Operations
Forensic investigations continue with support from state criminal police, federal security authorities, and the Federal Office for Information Security. Berlin’s decision to refuse the ransom follows the city’s August 17 disclosure, which came three days after the network shutdown and 11 days before Rhysida posted its claim publicly. The federal support for the investigation reflects the seriousness of the breach—a state government administrative network compromise affecting 12,076 individuals and 5.7 terabytes of data warrants coordination across multiple German law enforcement and security agencies.
Governing Mayor Wegner’s Public Refusal Eliminates Negotiation Ambiguity for 12,076 Affected Individuals
Berlin’s public refusal to negotiate removes any ambiguity about whether the city will engage with the threat actors, signaling to both the attackers and affected individuals that the city will not fund ransomware operations regardless of the threatened data release. The 12,076 individuals whose personal information was compromised now face exposure risk as Rhysida decides whether to follow through on its leak site threat. The breach creates long-term risk for affected individuals even if Rhysida does not publicly release the data—the attackers already possess 12,076 individuals’ contact information, financial records, and credentials, which can be sold or used for targeted phishing campaigns without a public leak.
