Berlin's mayor has confirmed that the German capital is being held to ransom by hackers who compromised city systems and stole 5.79 terabytes of data earlier this month. The Rhysida ransomware group — believed to operate from Russia and Eastern Europe — has claimed responsibility and is threatening to begin auctioning the stolen data within seven days if the city refuses to pay. Berlin's response is unambiguous: it will not be blackmailed.
Key Points
- Rhysida ransomware group has claimed responsibility for breaching Berlin's city systems, stealing 5.79 terabytes of data including contracts, personnel files, passwords and thousands of personal contact details
- The group is demanding 30 Bitcoin — approximately €2 million — and has set a countdown after which it says it will begin auctioning the data on the dark web
- Berlin Mayor Kai Wegner has refused to pay, stating: "Berlin will not be blackmailed"
- An initial data leak occurred between August 7 and 12, followed by the shutdown of two department networks on August 14, making housing benefit applications and payments impossible for several days
- Forensic investigations revealed further data leaks within Berlin's transport and environment department
- The attack comes approximately one month before Berlin holds elections, though officials confirmed election infrastructure has not been compromised
- Rhysida previously attacked the British Museum in 2023, stealing approximately 500,000 files and publishing them after the institution refused to pay
What Happened
City officials confirmed that an initial data breach occurred between August 7 and 12, when attackers were able to access and extract data from Berlin's systems. On August 14, two department networks were shut down in response — an action that made it impossible for residents to apply for housing benefits or receive payments for several days, with direct consequences for some of Berlin's most vulnerable residents.
Subsequent forensic investigations revealed additional data leaks within Berlin's transport and environment department, broadening the scope of what had initially been disclosed. Mayor Kai Wegner's office issued a statement on Friday acknowledging that personal or other non-public data may also be affected, though the full extent of what was taken remains under investigation.
State police, prosecutors and federal security services are working to investigate the suspected perpetrators, Wegner said, describing the inquiries as being pursued with the utmost urgency and great intensity.
The Rhysida Group and Its Demands
The Rhysida ransomware group posted a claim of responsibility on its dark web site, where it displayed screenshots purporting to show files taken from Berlin — including contracts, non-disclosure agreements, personnel files, passwords and thousands of personal contact details. The site is running a countdown timer, after which Rhysida says it will begin auctioning the stolen data with a starting bid of 30 Bitcoin — the same amount it is simultaneously demanding directly from the city as a ransom payment.
The dual-track approach — ransom demand to the victim alongside public auction threat to external buyers — is a standard pressure tactic used by modern ransomware operators to maximise the likelihood of payment. The victim faces not only the threat of public data exposure but the prospect of sensitive information being sold to parties with potentially adversarial interests, including criminal organisations or foreign intelligence actors seeking operational data on city contracts, personnel and infrastructure.
Rhysida is believed to operate from Russia and Eastern Europe. The group has claimed hundreds of attacks since emerging in 2023, targeting government institutions and businesses of varying sizes across numerous countries.
The British Museum Precedent
Rhysida's track record with non-paying targets is not speculative — it is documented. In 2023, the group successfully infiltrated the British Museum's computer systems, disrupting services and stealing approximately 500,000 files containing personal data of visitors, subscribers and staff. When the museum refused to pay the ransom, Rhysida published the files on the dark web, making the personal data of hundreds of thousands of people publicly accessible.
That precedent matters for Berlin's decision-making. The group has demonstrated both the willingness and the capability to follow through on publication threats when ransom demands are refused. Berlin's firm public position — that it will not pay — means the city and its residents should prepare for the possibility that the stolen data will be auctioned or published when the countdown expires.
The Election Timing
The attack arrives at a particularly sensitive moment. Berlin is scheduled to hold elections in approximately one month, and the combination of compromised government systems, exposed personnel data and public uncertainty about what else may have been accessed creates a challenging backdrop for the campaign period.
State senator Iris Spranger moved quickly to address the most acute concern, confirming that election infrastructure has not been compromised. That assurance addresses the immediate integrity question but does not resolve the broader damage: personnel files, passwords and contact details for city staff represent a meaningful intelligence asset for any actor seeking to understand Berlin's governmental operations, and the transport and environment department data could include information about infrastructure that goes well beyond administrative records.
The Broader Pattern
Berlin's experience fits a pattern that has become distressingly familiar across European and North American governments. Ransomware groups operating from Russia and Eastern Europe have systematically targeted municipal and regional governments, hospitals and public institutions — organisations that combine meaningful data holdings, operational dependencies that make downtime costly and, in many cases, insufficient cybersecurity investment relative to the threats they face.
Rhysida's targeting of both a major cultural institution — the British Museum — and a major European capital within two years illustrates the group's ambition and operational capacity. The combination of a seven-day countdown, a simultaneous auction threat and a demand denominated in Bitcoin creates a structured pressure campaign designed to maximise the probability of payment before the deadline forces either a payout or a damaging publication.
Berlin has chosen confrontation over capitulation. The consequences of that choice — and whether the stolen data appears on the dark web within the week — will unfold in real time.
Sources
Berlin Mayor Kai Wegner public statement on ransomware attack, Friday August 2026. Berlin city-state officials statement on data breach timeline and affected departments, August 2026. Der Spiegel reporting on Rhysida dark web site and Bitcoin demand, August 2026. Reuters reporting on Rhysida auction threat and 5.79 terabyte data claim, August 2026. State Senator Iris Spranger confirmation that election infrastructure is unaffected, August 2026. British Museum Rhysida attack reference, 2023.