
Berlin authorities have refused to meet an alleged 30 Bitcoin ransom demand worth approximately €2 million after a cyberattack hit two state agencies. According to latest reports from Germany's DIE ZEIT and ME News, the Berlin administrative data network has been under cyberattack for over two weeks, with the hacker group Rhysida threatening to release vast amounts of stolen sensitive data unless Berlin pays the ransom. Berlin Mayor Kai Wegner confirmed after a special Senate meeting that the state was facing an extortion attempt, stating 'The state of Berlin will not allow itself to be blackmailed'. The attack became public on August 14 and affected Berlin's Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Climate Protection and the Environment. Rhysida has now announced plans to initiate an auction for the stolen data within seven days, according to Reuters, with the group displaying a countdown on their dark web portal and an initial bid of 30 bitcoin.
The attack affected both agencies for approximately one week while officials worked to contain the incident. As reported by DIE ZEIT, the stolen data allegedly includes around 46,000 contracts, over 11,000 confidential documents, nearly 6,000 passwords, 16,000 emails, and 148 IBAN accounts. The compromised information reportedly includes documents such as contracts, non-disclosure agreements, personnel files, passwords, and personal contact details. Rhysida allegedly claimed to have taken almost six terabytes of data including information from tens of thousands of administrative offense proceedings, contracts, passwords, login credentials, emergency plans and documents related to critical infrastructure. Berlin initially said only public information was compromised but later acknowledged that non-public data had been affected. The separation lasted for about a week and disrupted some administrative services, including residents being temporarily unable to apply for or receive housing benefits and payment systems. According to ME News, the primary affected departments were transportation and construction, with these systems being temporarily isolated from the state network following the incident.
The Berlin State Criminal Police Office, prosecutors, and federal security services are investigating the breach, with officials continuing to examine which files had been accessed or removed. According to reports, investigators are still determining when the intrusion began and how much information left the network, with data potentially extracted between August 7 and August 12. Interior Senator Iris Spranger said the attack had not compromised preparations for Berlin's September 20 state election, describing the election infrastructure as fully secured. The timing of the attack raises particular concern as it occurred less than a month before the municipal elections in Berlin. The attack was initially discovered on August 14, after which two Senate departments were disconnected from the state network. Some public services, including housing benefit applications and payments, were temporarily affected. The departments were later reconnected while forensic investigations continued. The Berlin state government has refused to disclose details of the ransom demand or the data breach, citing 'reasons related to investigative strategy' for its silence. The Senate Chancellery has not disclosed details about the attackers, their demands or the information potentially taken while the investigation remains active.
German magazine Der Spiegel reported that Rhysida was behind the attack, citing information posted by the ransomware group on its dark web leak site. Security sources cited by the publication reportedly identified Rhysida as the group responsible for the extortion attempt. Reuters reports that Rhysida, linked to operations in Russia and Eastern Europe, has asserted responsibility for the breach. The group has previously claimed responsibility for hundreds of attacks since 2023, targeting government agencies and private entities globally. Rhysida has been linked to attacks against government bodies, healthcare organizations and other institutions in several countries, with operations generally combining network intrusion with demands for payment while threatening to publish stolen information. The group has previously targeted organizations including the British Library and the Chilean Army, with the British Museum experiencing a similar breach in 2023 that resulted in the theft of 500,000 files. After refusing to pay the ransom, the institution had visitor data publicly released by the attackers.
The Berlin case follows another government cyberattack involving a Bitcoin demand reported in July, when hackers took control of Kenyan President William Ruto's official website and demanded 5 BTC. Bitcoin and other cryptocurrencies have repeatedly featured in ransomware cases because attackers can direct payments to blockchain addresses without using conventional bank accounts. Law enforcement agencies have recovered cryptocurrency from ransomware operations in previous cases, with U.S. authorities seizing $1.09 million in cryptocurrency linked to the BlackSuit ransomware group in August 2025. The breach highlights ongoing challenges in securing municipal infrastructure, with threat actors increasingly leveraging data exfiltration as a tool for coercion. Cybersecurity experts have urged organizations to enhance protective measures, including regular system audits and incident response planning.