Berlin Refuses Ransom After Rhysida Ransomware Steals 5.79TB of Government Data
Berlin's Governing Mayor Kai Wegner confirmed on Friday that the state government will not comply with an extortion demand from the Rhysida ransomware group, which claimed responsibility for a cyberattack that compromised the city's administrative network. The attack, discovered in mid-August, resulted in the theft of approximately 5.79 terabytes of data between August 7 and 12, according to Rhysida's dark-web leak site. The group advertised the dataset for auction at a starting price of 30 bitcoin (roughly $2.3 million), claiming it included 46,500 contracts along with emails, telephone numbers, passwords, and classified government information.
Following the discovery on August 14, Berlin disconnected two affected ministries from the wider state network: the Ministry for Urban Development, Construction and Housing, and the Ministry overseeing Mobility, Transport, Climate Protection and the Environment. Both ministries remained operational but lost access to standard IT systems, including email and internet services, forcing staff to rely on telephones, text messages, and fax machines. The outage cascaded into other public services, with several district offices temporarily unable to process housing benefit and education assistance applications that depend on the urban development ministry's systems. Berlin's central IT provider, ITDZ Berlin, was not impacted; the two ministries operate their segment of the state network independently.
Authorities have confirmed that data was exfiltrated and that an extortion demand was received, though they have not publicly attributed the attack to Rhysida or verified the group's specific claims about the dataset's contents. Interior Senator Iris Spranger stated that election infrastructure remains protected ahead of Berlin's September 20 House of Representatives elections, noting that no data had been exfiltrated from those systems. Officials have warned that personal data may be among the compromised material and continue to investigate the full scope. With incidents like this highlighting the scale of exposed credentials, security professionals can use an email breach checker to verify whether government or employee accounts have appeared in known leaks, while individuals can audit password hygiene with a password checker to reduce the risk of credential reuse enabling lateral movement.
The Rhysida group, active since mid-2023, has increasingly targeted public-sector and healthcare organizations across Europe and North America, typically gaining initial access through phishing or exploiting internet-facing services before deploying ransomware payloads. Berlin's refusal to pay aligns with broader German policy against engaging with ransomware operators, though it leaves open the possibility that Rhysida will publish or sell the stolen data once its auction countdown expires. The incident underscores the critical importance of network segmentation, timely detection, and offline backups—principles that can mean the difference between a manageable breach and a prolonged operational shutdown.