Berlin Won't Pay Extortion Group Claiming Data Theft
Rhysida ransomware group claimed responsibility for a major cyberattack on Berlin's municipal government networks, stealing over 5.7 terabytes of sensitive data The attack targeted the Senate Department for Mobility, Transport, Climate Protection, and Environment, as well as the Senate Department for Urban Development, Construction, and Housing Berlin's leadership, including Governing Mayor Kai Wegner, confirmed the city will not pay the 30 Bitcoin (~$2.3 million) ransom demand Data exfiltrated
Analysis
TL;DR
- Rhysida ransomware group claimed responsibility for a major cyberattack on Berlin's municipal government networks, stealing over 5.7 terabytes of sensitive data
- The attack targeted the Senate Department for Mobility, Transport, Climate Protection, and Environment, as well as the Senate Department for Urban Development, Construction, and Housing
- Berlin's leadership, including Governing Mayor Kai Wegner, confirmed the city will not pay the 30 Bitcoin (~$2.3 million) ransom demand
- Data exfiltrated included personal information of over 12,000 individuals, 16,000 email addresses, payroll data, passwords, IBANs, and confidential government documents
- The breach occurred between August 7-12, 2025, with the attack discovered on August 14, prompting immediate network shutdowns
Why It Matters
This incident highlights the escalating threat of ransomware targeting critical municipal infrastructure and government entities, demonstrating how cyberattacks on local governments can compromise vast amounts of citizen data. It underscores the growing trend of ransomware groups like Rhysida specifically targeting public sector organizations with large data holdings, and the difficult policy decisions governments face when deciding whether to negotiate with threat actors.
Technical Details
- Attack vector and scope: The Rhysida ransomware group infiltrated Berlin's government networks, exfiltrating 5.7 TB of data spanning multiple departments before encrypting systems
- Data compromised: Over 12,000 individuals' personal information, 16,000 email addresses, ~12,000 phone numbers, plaintext credentials, IBANs, payroll information, passport/ID data, legal documents, contracts, and HR files
- Ransom demand: 30 Bitcoin (approximately $2.3 million at the time), demanded via the group's Tor-based leak site where Berlin was briefly listed on August 28
- Containment measures: Both affected department networks were shut down on August 14; investigation involves state criminal police, federal security agencies, and the public prosecutor's office
- Timeline: Data theft occurred August 7-12; incident discovered August 14; Rhysida claimed responsibility on August 28
Industry Insight
- Government entities should treat ransom payment as a last resort; Berlin's stance reinforces the growing institutional resistance to funding criminal operations, though this also means accepting the reputational and legal consequences of breached data
- The scale of data exfiltration (5.7 TB) from municipal networks demonstrates that even local government organizations are prime targets due to often-lax cybersecurity postures compared to federal agencies
- Organizations should prioritize data classification, encryption at rest and in transit, and zero-trust architectures to limit the blast radius of potential breaches, especially for departments handling sensitive citizen information
Disclaimer: The above content is generated by AI and is for reference only.