Logo of the ransomware group Rhysida. (Photo via X/@IntCyberDigest)
August 31, 2026 10:36 AM GMT+03:00
A ransomware group calling itself Rhysida has demanded 30 bitcoin, roughly €2 million ($2.3 million), from Berlin’s government after breaching its IT network, threatening to release nearly six terabytes of stolen data if its demand is not met, German media reported Saturday, citing the weekly magazine Der Spiegel.
The group warned it would publish the stolen data if the ransom was not paid, setting a countdown that left Berlin one week to meet the demand.
City officials vow not to pay
Berlin’s city-state administration held an emergency meeting on Friday to discuss the incident, according to public broadcaster RBB. “The State of Berlin has fallen victim to a serious crime,” Governing Mayor Kai Wegner said after the meeting. “Berlin will not allow itself to be blackmailed,” he added.
According to media reports, the ransomware group claims it seized materials including records from nearly 80,000 administrative fine proceedings, more than 46,500 contracts, information on critical infrastructure facilities, judicial documents, emergency plans, passwords, and nearly 6,000 files containing login credentials.
Authorities determined that the hackers had been inside the network earlier than initially believed, with data exfiltration occurring “at least since Aug. 7.”
The leak was first detected on Aug. 14, and, as a precaution, several ministries were temporarily disconnected from the network in mid-August while officials worked to contain the breach.
The compromised system, known as BeLa, is a high-speed fiber-optic network that links hundreds of offices across Berlin’s city-state administration. It is operated by the state IT service provider ITDZ Berlin.
