Berlin refuses ransom after network breach
Berlin's state government has refused to pay extortionists following a data breach of its administrative network in August 2026.

Berlin's state government has confirmed it is the target of an extortion attempt and will not pay a ransom. The incident stems from a compromise of the city's state administrative network in August 2026, as reported by The Hacker News.
Forensic work identified further data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment. This exfiltration occurred between August 7 and August 12, 2026. The scope and content are still being examined, but the Senate Chancellery stated that personal or other non-public data cannot be ruled out.
The department first reported an outflow on August 7. It was cut off from the network on August 14. Berlin has not provided its own figure for the amount of data stolen.
Attackers' Claims and Attribution
The only itemized account in circulation is from the attackers themselves. A leak-site post indexed on August 28 claims the theft of 5.79 terabytes of data and personal information on 12,076 individuals. Der Spiegel named the Rhysida ransomware group as responsible for the attack, citing an entry on the group's darknet leak site and security sources. The Hacker News confirmed via a monitoring service that an entry titled "Berlin, Germany" was added to Rhysida's site on August 28.
The Rhysida post claims to have scanned 5.79 terabytes of data and around 1.44 million files. It identifies the victim only as Berlin, Germany. No ransom figure appeared in the entry. Its eleven file categories account for about a quarter of the claimed total file count.
Rhysida's Known Tradecraft
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) detailed Rhysida's methods in a joint advisory. The group's routes for initial access include valid accounts on external-facing remote services, exploitation of the Zerologon vulnerability (CVE-2020-1472), and phishing.
The advisory, dating to November 2023, states that the FBI and CISA do not encourage paying ransoms. Payment does not guarantee data recovery and may embolden adversaries. The agencies recommend prioritizing remediation of known exploited vulnerabilities, enabling multi-factor authentication, and segmenting networks.
The same document notes open-source reporting of similarities between Rhysida and the Vice Society ransomware group, which Microsoft tracks as Storm-0832.
Incident Response and Broader Impact
"The state of Berlin is being blackmailed," said Governing Mayor Kai Wegner after a special Senate session. The Senate Chancellery stated that the state criminal police, the public prosecutor, and federal security authorities are investigating. Berlin's state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed.
A leak-site monitoring service listed 280 Rhysida victims as of August 29, nine of them in Germany. Previous German victims include the Stuttgart city administration in May 2026 and the aid organization Welthungerhilfe in June 2025.
Interior Senator Iris Spranger said that, based on current knowledge, no data left areas relevant to the conduct of the September 20 Abgeordnetenhaus election. Her security officers regard the election environment as secure.
Berlin first disclosed the incident on August 17. At an August 19 press conference, Wegner emphasized the incident was serious but stated that, based on current knowledge, no sensitive data had left the state network. Housing benefit applications and payments were unavailable while two departments were offline. All Senate departments were reconnected on August 23, and forensic work continues.





