Berlin Tells Cyber Extortionists: “We’re Not Paying!”
Berlin’s state government has confirmed it is facing an extortion attempt following the compromise of its administrative network, and officials have made one part of their response very clear.
They’re not paying.
Investigators discovered additional data had been removed from systems belonging to Berlin’s Senate Department for Mobility, Transport, Climate Protection and Environment between 7 and 12 August 2026.
Authorities are still determining exactly what was taken and have warned that personal or otherwise confidential information may be included.
Attackers Claim Nearly Six Terabytes
A ransomware leak site associated with Rhysida reportedly listed Berlin on 28 August.
The attackers claim to have obtained approximately 5.79TB of data, comprising around 1.44 million files and information relating to 12,076 people.
Those figures come from the attackers themselves rather than Berlin authorities, so they should be treated accordingly.
German law enforcement, prosecutors and federal security authorities are investigating the incident. Berlin officials have not formally identified the group responsible.
The attack had practical consequences too.
Affected government departments were temporarily disconnected from the network, disrupting services including housing-benefit applications and payments. Departments were reconnected by 23 August while forensic investigations continued.
Officials have said they have found no evidence that data relating to Berlin’s September election systems was removed.
Why Refusing Payment Matters
Rhysida has previously been associated with so-called double-extortion attacks, where criminals steal data before demanding payment to prevent its publication.
Security authorities have repeatedly warned organisations that paying criminals provides no guarantee that stolen information will be deleted or restored.
The incident is another reminder of the value of multi-factor authentication, rapid vulnerability patching and network segmentation.
For organisations everywhere, including here in the UK, the lesson is fairly simple.
Stopping attackers getting in is preferable to negotiating with them once they’ve packed several terabytes of your data into their digital suitcase.