Berlin鈥檚 city administration has confirmed that it is facing an extortion attempt after the Rhysida ransomware gang added the city to its data leak site. The city discovered the attack in mid-August, and the criminal group made its claim public on August 28. Mayor Kai Wergner said Berlin will not pay the attackers, and the State Criminal Police Office, the public prosecutor鈥檚 office, and federal security agencies are now investigating.
The Rhysida group says it pulled 5.79 TB of data from Berlin鈥檚 administrative network, which it describes as roughly 1.44 million files. The stolen material reportedly includes a range of unspecified information types, and the attackers are using potential GDPR violations as leverage. They have given the city four days, as of the original report, to pay before releasing the files publicly.
Forensic investigators have also found that the attacker took data from the Senate Department for Mobility, Transport, Climate Protection and the Environment, likely between August 7 and 12. That department, along with other affected Senate offices, was cut off from the state network on August 14. The city notes that the investigation is ongoing and that the full scope of the data theft has not yet been determined.
Senator Iris Spranger said officials have found no evidence that election data was compromised, and the technical setup supporting the upcoming Berlin House of Representatives election is considered safe. The method Rhysida used to break in has not been disclosed. In a previous campaign disrupted by Microsoft, the same ransomware operators used malicious Teams installers to gain access to targets.
Rhysida has been active since mid-2023, with a track record of hitting healthcare organizations, state governments, education institutions, and critical infrastructure. Berlin鈥檚 case adds another government target to that list, and the city鈥檚 refusal to pay aligns with the stance taken by many U.S. municipal and state agencies facing similar ransomware demands. The Blue Report 2026, which measures defenses across 338 million simulations in customer production environments, notes that prevention scores can hide what happens after attackers gain valid credentials, at which point prevention drops sharply.
More cybersecurity news from TechManNews.








