Berlin’s state government has refused to pay a ransom to the Rhysida ransomware group which claims to hold 5.79 terabytes of data taken from the city-state’s administrative network. Rhysida posted an entry titled simply “Berlin, Germany” on its leak site on 28 August, listing roughly 1.44 million files and personal information on 12,076 individuals. Berlin elects its Abgeordnetenhaus on 20 September.
Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus that the state of Berlin is being blackmailed. In a joint statement with Interior Senator Iris Spranger, reported by Reuters on 28 August, the two said Berlin would not submit to extortion. Spranger added that no data has left the areas relevant to running the September election and that her security officers regard the election environment as secure.
Seven Days Between the First Alert and the Network Cut
The Senate Department for Mobility, Transport, Climate Protection and Environment reported a data outflow internally on 7 August. It was disconnected from the state network on 14 August, seven days later. Forensic work dates the exfiltration to between 7 and 12 August so the attackers were still moving data out during most of that week.
Berlin disclosed the compromise publicly on 17 August saying both affected departments had been isolated since the previous Friday. At a press conference on 19 August, Wegner said that on current knowledge no sensitive data had left the state network. Housing benefit applications and payments were unavailable while the two departments sat off the network. All Senate departments were reconnected on 23rd August.
Everything Itemised So Far Comes From the Attackers
Berlin has published no figure for how much data left the network. The only itemised account in circulation is Rhysida’s own and it doubles as a sales pitch. The leak-site post claims personnel files, payroll records, plaintext credentials, disciplinary proceedings, Bundesrat committee protocols, passports pulled from personnel records and vulnerability analyses of Berlin’s water supply. The largest single category is 124,823 maps and geodata files about a quarter of the claimed file count on its own. Treat the rest of that inventory as unverified until the Senatskanzlei or the BSI confirms it.
The ransom figure is second-hand too. The Hacker News reported that no amount appeared in the leak-site entry at all. Der Spiegel and heise put the demand at 30 bitcoin which German reporting valued at roughly two million euros while other outlets converted the same 30 bitcoin to figures between $77,000 and $2.3 million. When one number moves by a factor of thirty across outlets, none of them is holding the primary document.
The state criminal police, the public prosecutor and federal security authorities are investigating and the Senatskanzlei has not named a group. Der Spiegel named Rhysida on 28 August citing the leak-site entry and security sources involved in the response.
Rhysida’s Way In Has Not Changed Since 2023
CISA, the FBI and the Multi-State Information Sharing and Analysis Center documented Rhysida’s initial access routes in a joint advisory in November 2023. There are three, valid credentials against internet-facing VPN endpoints at organisations without MFA enabled by default, Zerologon (CVE-2020-1472) and phishing. Microsoft patched Zerologon on 11 August 2020.
Nothing on that list is new which is the whole point. The same advisory records that the FBI and CISA do not encourage paying a ransom because payment guarantees no recovery and funds the next campaign. Berlin’s refusal follows that guidance rather than any local calculation.
A leak-site monitoring service listed 280 Rhysida victims as of 29 August, nine of them in Germany including the Stuttgart city administration in May 2026 and the aid organisation Welthungerhilfe in June 2025. The same list carries the Port of Seattle from September 2024 and the group took the British Library offline in 2023. Around half its listed victims sit in the United States, a spread that points to selection by weak controls rather than by geography.
Sweden Votes on 13 September
Berlin votes on 20 September. Sweden votes a week earlier on 13 September, in simultaneous elections to the Riksdag, 21 regional councils and 290 municipal councils. Valmyndigheten puts the Riksdag electorate at 8,046,725 people.
Valmyndigheten runs a permanent national election network alongside Säkerhetspolisen, the police, MSB, the Agency for Psychological Defence, the National Cyber Security Centre, the county administrative boards, PTS and Skatteverket. The government has separately instructed the NCSC to produce a threat assessment for the 2026 elections and to provide operational support to election actors before during and after the vote.
Berlin was not an attack on a vote count, and Swedish exposure does not sit there either. It sits in the municipal administrative systems next to the election machinery and Sweden already has the precedent. When the HR system supplier Miljödata i Karlskrona was breached in August 2025, IMY received more than 500 personal data breach notifications from affected organisations and around 70 complaints from individuals and opened a supervisory investigation into the company.
A year later that investigation is still open and Sweden has no official count of the people affected. Berlin is in the same position working from 12,076, a number supplied by the attackers.
The Number That Matters Is Seven
The most useful disclosure out of Berlin is not the terabyte claim. It is the seven days between an affected department flagging a data outflow and that department being cut from the state network. Establish your own equivalent this week.
- Enforce MFA on every internet-facing remote access point, VPN included. It is the first route in the CISA advisory and it still works in 2026.
- Confirm Zerologon (CVE-2020-1472) is patched on every domain controller. The fix has been available since 11 August 2020.
- Decide now who notifies affected individuals, and when. Berlin published two statements on the incident and neither carried guidance for the 12,076 people named in the leak-site post.
References
- Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
- Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network
- Berlin City Government Says It Won’t Submit to Extortion After Pre-Election Cyberattack
- Wegner and Spranger: Berlin Will Not Give In to Blackmail
- 30 Bitcoin or Leak, Ransomware Gang Extorts Berlin
- StopRansomware: Rhysida Ransomware, AA23-319A
This post is also available in:
