Berlin Ransomware Attack: State Refuses to Pay

Berlin ransomware attack 2026 — Rhysida extortion of German state government network

A Berlin ransomware attack has put Germany’s capital in the position every public-sector CISO dreads: a confirmed data breach, a seven-figure ransom demand, and an election three weeks away. The ransomware group Rhysida claims it stole 5.79 terabytes from Berlin’s state administrative network and is demanding 30 Bitcoin, roughly €2.05 million, with a seven-day auction countdown. Berlin’s government has publicly refused to pay.

What Happened

This Berlin ransomware attack began with data exfiltration between August 7 and 12, 2026. As a precaution, Berlin disconnected two Senate departments from the state network (Landesnetz) on August 14: the Senate Department for Urban Development, Building and Housing, and the Senate Department for Mobility, Transport, Climate Protection and Environment. Berlin’s Senate Chancellery received an indication of the specific data leak around August 25, with the affected department confirming it on August 26. Rhysida claimed responsibility publicly on its leak site on August 28, posting an entry titled simply “Berlin, Germany.”

Reporting on the stolen data varies by outlet but is broadly consistent: English-language coverage cites roughly 1.44 million files affecting 12,076 individuals, including 16,389 email addresses, 11,963 phone numbers, 148 IBANs, more than 5,000 personnel files and payroll data. German coverage additionally cites close to 80,000 administrative fine (Ordnungswidrigkeit) case files, more than 46,500 contracts, information tied to critical infrastructure facilities, sensitive judicial records, emergency response plans, and roughly 6,000 files containing login credentials. Berlin has not published an official figure for the total volume exfiltrated.

Rhysida has operated since mid-2023 and claims roughly 280 victims globally, including nine in Germany, with past high-profile targets including the British Library and Chile’s army.

Why It Matters

Berlin’s Abgeordnetenhaus state election is scheduled for September 20, 2026, less than a month after the breach became public. Interior Senator Iris Spranger has stated that election-relevant systems were not affected and that no data left the areas relevant to the vote — a separate, unrelated outage on Berlin’s postal-vote application portal was explicitly confirmed by the Senate as not connected to this attack. Even with that reassurance, a confirmed breach of government systems with a live extortion countdown running into an election period is precisely the kind of scenario NIS2-regulated public bodies and their private-sector suppliers need a rehearsed response for, not an improvised one. The credential files among the stolen data (roughly 6,000 login-data files per German reporting) also raise a lateral-movement risk into connected systems well beyond the two disconnected departments.

What You Should Do Now

  1. If your organization exchanges data or systems access with Berlin state agencies (contractors, suppliers, connected authorities), assume credentials and contract data tied to that relationship may be exposed and rotate shared secrets now.
  2. Review and rehearse your own extortion-response decision process today, before an incident, not during one — who has authority to say no, and how is that communicated internally and externally within hours.
  3. If you hold personal data on Berlin residents through a public-sector contract, check whether you have a notification obligation once official confirmation of affected individuals is published.
  4. Treat any unsolicited contact referencing this breach (phishing framed as “official Berlin notification”) with suspicion until Berlin publishes its own confirmed communication channel.

DIESEC Perspective

We covered a similar pay-or-not decision in May 2026, when Grafana refused a data-extortion demand in the same week Instructure paid one — Berlin’s public, joint statement from its mayor and interior senator follows the Grafana model: refuse publicly, absorb the leak risk, and lean on the well-documented guidance that paying does not reliably prevent a leak or a repeat attack. What is different here is the audience: a state government making that call in public, three weeks before its own election, is also a message to every other extortion group about how this administration intends to respond.

Not sure whether your organization’s incident response plan actually holds up under a live extortion deadline, rather than just on paper? Contact DIESEC for a rapid incident-response and extortion-decision readiness review.

Sources: The Hacker News | Security Affairs | Berlin.de (official)
Published: 2026-08-31 | Category: Ransomware & Extortion | ~4 min read