Berlin Refuses Ransom as Rhysida Leaks 5.79TB of State Network Data
Berlin's state government has confirmed it is the target of an extortion attempt following an August compromise of the city's administrative network and will not meet the attackers' demands. Governing Mayor Kai Wegner stated after a special Senate session at the Rotes Rathaus that "the state of Berlin is being blackmailed," though the Senate Chancellery confirmed no specific ransom figure was communicated by the perpetrators. The Berlin state criminal police, the public prosecutor's office, and federal security authorities are jointly investigating the incident, with no group formally identified by officials as of late August.
The attack is attributed to the Rhysida ransomware group, which added an entry titled "Berlin, Germany" to its darknet leak site on August 28. The post claims to have exfiltrated 5.79 terabytes of data and approximately 1.44 million files, including personal information on 12,076 individuals. The largest of the eleven file categories is reportedly 124,823 maps and geodata files, though together they account for only about a quarter of the claimed total file count. Berlin officials have not confirmed any of these figures. Notably, Rhysida used compromised valid credentials on external-facing VPN endpoints lacking multi-factor authentication as an initial access vector, a tactic documented in a joint advisory from CISA, the FBI, and MS-ISAC that also references exploitation of Zerologon (CVE-2020-1472), a privilege escalation flaw in Microsoft's Netlogon Remote Protocol. Officials noted that further data outflows were detected in the Senate Department for Mobility, Transport, Climate Protection and Environment, with exfiltration dated between August 7 and August 12. The department first reported an outflow on August 7, seven days before it was disconnected from the network on August 14.
The Senate Chancellery has warned that personal or other non-public data cannot be excluded from the stolen materials, yet as of August 29 the two official statements carried no guidance for potentially affected individuals. Organizations and citizens concerned about credential exposure can use our email breach checker to see if their accounts appear in known leaks, and security teams should audit remote access endpoints with our port scanner to identify exposed services that could be targeted using the same Rhysida tradecraft. The incident underscores the critical importance of enforcing multi-factor authentication on all VPN access points and patching legacy Windows infrastructure against vulnerabilities like Zerologon to prevent similar breaches. Berlin's refusal to negotiate sets a precedent aligned with broader law enforcement guidance discouraging ransom payments that fuel further ransomware operations.