Berlin mayor rejects ransom demands as hackers put government data up for auction
The city administration of the German capital is being blackmailed by hackers who were able to compromise the state network and steal data earlier this month.
The worrisome development was revealed by Berlin Mayor Kai Wegner, who said the blackmail demand was received on the evening of August 27. Wegner and Berlin's Interior Senator Iris Spranger spoke on August 28 during a press conference, ensuring that Berlin would not give in to the demands.
While the exact amount demanded has not been publicly confirmed by the Berlin authorities, German media have reported that the hackers are demanding 30 bitcoin, which accumulates to an approx. €2 million.
Some of the German capital's online systems were forced offline following the attack, while investigators continued working to establish what information had been taken. Berlin authorities said the forensic investigation is still under way and that personal or other non-public information cannot be ruled out among the compromised data.
German investigative outlet Der Spiegel reported that it had found an entry on the dark web apparently linked to the attack and extortion attempt. According to these reports, the entry was attributed to the ransomware group Rhysida, which has previously targeted the German city of Stuttgart.
The hackers described the stolen material as “exclusive, unique and impressive” and put it up for auction for seven days. Reuters reported that Rhysida claimed to have stolen 5.79 terabytes of data, including about 46,500 contracts, emails, phone numbers, passwords and classified information.
Speaking at a special Senate session at the Rotes Rathaus on August 28, Wegner and Spranger assured the public that the Berlin government would not submit to the blackmailers. The State Criminal Police Office, the public prosecutor's office and federal security agencies are investigating the suspected perpetrators.
“Regardless of the amount and regardless of how the extortion takes place, we will not allow this extortion to take place in the federal capital and in Berlin,” Spranger said.
Other reports citing the hackers' claims said the stolen material could include thousands of contracts, confidential documents, passwords and bank account information, as well as documents concerning senior officials and disciplinary proceedings. The hackers also allegedly claimed to possess analyses concerning the “vulnerability of Berlin's water supply.” The authorities have not independently confirmed the full scope or contents of the stolen data.
Political earthquake
The attack has also raised concerns because it occurred less than a month before Berlin's September 20 elections. However, Spranger said the election environment is technically protected and that, according to the information currently available, no election-related data had been compromised.
Earlier this week, Berlin's Senate Chancellery disclosed that the hackers had gained access to the state network earlier than initially known. According to Chief Digital Officer Florian Hauer, data had been extracted between August 7 and 12, several days before the breach was detected. On August 14, the Senate departments responsible for mobility, transport and climate protection and for urban development and housing were disconnected from the rest of the state network as a precaution.
The affected Senate departments have since been reconnected to the network and are generally operational again, while forensic investigations and network checks continue. Berlin's ICT emergency response team remains active.
Rhysida’s international record
Rhysida has claimed responsibility for hundreds of cyberattacks since emerging in 2023, according to cybersecurity research. The ransomware group has targeted government institutions as well as businesses of various sizes across numerous countries.
Among its high-profile victims was the British Museum, whose computer systems Rhysida infiltrated in 2023, disrupting services and allegedly stealing around 500,000 files.
After the British institution refused to pay the ransom, the group published the stolen material on the dark web. The files reportedly included personal information belonging to visitors, subscribers and museum staff.
By Nazrin Sadigova







