Berlin's Ransom Standoff Tests State Resilience
Berlin refuses to pay Rhysida after data theft from its state network, saying it won't yield to blackmail.
Berlin's state government has publicly acknowledged it is the target of an extortion attempt after hackers breached its administrative network in August — and it is drawing a hard line, saying it will not pay. The confirmation came as forensic investigators uncovered additional data exfiltration from a city department, complicating an already sensitive situation for the German capital.
Extortion Confirmed, Payment Refused
Governing Mayor Kai Wegner confirmed the extortion attempt after a special Senate session, declaring, "The state of Berlin is being blackmailed." The city's official portal carried the statement in its machine-translated English version. The Senate Chancellery's official response makes clear that Berlin will not meet the attackers' demands, although it did not specify what those demands were.
No group had been officially identified by authorities at the time of the statement. The investigation involves the state criminal police, the public prosecutor, and federal security authorities, according to the Senate Chancellery.
Additional Data Loss Revealed
The same statement disclosed that forensic work had uncovered further data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment. The exfiltration is dated between August 7 and August 12, 2026. The exact scope and content of the stolen data are still being examined, and the Senate Chancellery said it cannot be ruled out that personal or other non-public data was among the files taken.
The department first reported an outflow on August 7, seven days before it was disconnected from the network on August 14. Berlin has not published any official figure for the volume of data exfiltrated.
The Attacker's Claims
The only itemized account of the theft comes from the attackers themselves. A leak-site post, indexed on August 28, claims 5.79 terabytes of data and personal information on 12,076 individuals. The entry is titled "Berlin, Germany" and does not name a specific department. The post also claims to have scanned around 1.44 million files, though no ransom figure is listed. The largest of eleven file categories is maps and geodata, comprising 124,823 files.
As of August 29, the Senate's two public releases on the incident contained no guidance for individuals whose data might be among the stolen records.
Attribution to Rhysida
German magazine Der Spiegel first named Rhysida as the group behind the attack on August 28, based on the darknet leak site entry and security sources. The Hacker News independently confirmed via a leak-site monitoring service that an entry matching the description was added to Rhysida's site on August 28.
Rhysida is a known ransomware operation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) published a joint advisory on Rhysida, dated November 2023, documenting its tradecraft.
How Rhysida Operates
The advisory details three common routes into victim networks. First, valid accounts on external-facing remote services, where attackers use compromised credentials to access internal VPNs — a particular risk at organizations that do not have multi-factor authentication (MFA) enabled by default. Second, exploitation of Zerologon (CVE-2020-1472), a privilege escalation vulnerability in Microsoft's Netlogon Remote Protocol, patched by Microsoft on August 11, 2020. Third, phishing campaigns, which the agencies record as a successful entry method.
The advisory's guidance urges organizations to prioritize patching known exploited vulnerabilities, enable multi-factor authentication, and segment networks to limit ransomware spread. Importantly, it states that the "FBI and CISA do not encourage paying ransom" because payment does not guarantee recovery and may embolden adversaries to target further organizations.
Berlin's Response So Far
Berlin first disclosed the incident on August 17, saying forensic work had established a compromise of the state network. Both affected departments had been isolated since the previous Friday. At an August 19 press conference, Wegner described the incident as serious but said that, based on current knowledge, no sensitive data had left the network — a statement now in tension with the newly disclosed outflows.
Service disruptions followed: housing benefit applications and payments were unavailable while the two departments were offline. All Senate departments were reconnected on August 23, though forensic work and network scanning continue.
Interior Senator Iris Spranger said that, as things stand, no data left areas relevant to the conduct of the September 20 Abgeordnetenhaus election, and that her security officers regard the election environment as secure.
Wider Rhysida Activity
The leak-site monitoring service listed 280 Rhysida victims as of August 29, including nine in Germany. Notable prior victims include the Stuttgart city administration in May 2026 and the aid organization Welthungerhilfe in June 2025. The Port of Seattle, which runs Seattle-Tacoma International Airport, was also listed, indexed in September 2024.
Open-source reporting has noted similarities between Rhysida and Vice Society, a group Microsoft tracks as Storm-0832, with Check Point documenting the overlap in 2023.
Why It Matters
Berlin's refusal to pay sets a precedent for other public-sector entities facing similar extortion. The attack also underscores the reality that even with swift response, data can still be exfiltrated over days before detection, and that attributing attacks takes time — time that victims may not have when holding ransoms are already public. With the election approaching, the city's ability to secure its networks while managing a major data breach will be closely watched.
Sources
- The Hacker News Original source
Continue Reading
AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
TeamPCP arrests expose supply chain risk
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.
CRPx0's big claims and where they lead
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.