Berlin Rejects Ransom Demand After Hackers Steal Data From City’s State Network
Berlin has refused to pay a ransom after the Rhysida group claimed to have stolen data from the city’s state network, including personal and other non-public information, in a breach that could expose thousands of residents and officials.
Berlin’s state government is refusing to pay cyber extortionists after a major breach of its IT systems, setting up a test of how far a large public administration can go in resisting ransom demands.
The Rhysida ransomware group says it has stolen data from the city’s state network and has listed the haul on its leak site. Berlin officials have confirmed that personal or other non-public data may be among what was taken but have not yet specified exactly which records were exposed.
Ransomware gangs typically combine data theft with the encryption of a victim’s systems to pressure organizations into paying. Berlin’s stance follows law-enforcement guidance that warns against paying ransoms, arguing that it encourages further attacks and does not guarantee that stolen information will be deleted.
For public employees and residents whose information is held on the state network, the main risk now is how much data the attackers choose to publish. Depending on what was accessed, that could range from contact details and internal correspondence to potentially sensitive records.
The incident underlines how difficult it is for sprawling public-sector IT environments to defend against sophisticated ransomware operations. Berlin’s state systems support a wide array of services, and a breach in one part of the network can give attackers pathways to others.
The Rhysida case also fits a broader trend of ransomware crews targeting governments and other public bodies, betting that the disruption and political pressure will force them to pay. Hitting the administration of Germany’s capital guarantees attention and raises the stakes if large volumes of data are leaked.
Key signals to watch include whether Rhysida begins releasing significant batches of Berlin’s data, how the city notifies and supports affected individuals once the scope is clearer, and whether Germany’s federal authorities propose new support or rules for municipal cyber defense. Any shift in Berlin’s stance under public pressure, or a wave of copycat attacks on other city networks, would show how sustainable this refusal to pay proves in practice.
Sources
- OSINT