Berlin is being blackmailed by hackers, mayor says

The German capital of Berlin is facing a high-stakes standoff with international cybercriminals after a significant data breach that compromised multiple city government networks, Mayor Kai Wegner has confirmed. The attack, which first saw unauthorized access to city systems between August 7 and 12, has prompted a full-scale emergency response from local, state and federal security agencies, with officials drawing a hard line against meeting the hackers’ extortion demands.

Wegner announced on Friday that the city would not cave to the ransom demand delivered to officials Thursday evening. While the mayor declined to disclose the exact sum being demanded, reporting from German outlet Der Spiegel puts the demand at 30 bitcoin, equivalent to roughly €2 million ($2.15 million) as of recent market valuations.

In the wake of the initial breach, city authorities shut down two departmental networks on August 14 as a protective measure. This outage disrupted critical public services for several days, leaving residents unable to submit applications for housing benefits or process routine government payments. Subsequent forensic investigations have uncovered additional unauthorized access within the city’s transport and environment departments, raising concerns about the full scale of compromised information.

“It cannot be ruled out that personal or other non-public data may also be affected,” the mayor’s office said in an official statement Friday.

Responsibility for the attack has been claimed by the Rhysida hacking group, a prolific ransomware operation that researchers believe operates from Russia and Eastern Europe. The group, which first emerged in 2023, has already carried out hundreds of attacks on government agencies and private businesses across dozens of countries, building a reputation for aggressive extortion tactics. Most notably, Rhysida breached the British Museum’s digital systems in 2023, stealing roughly 500,000 files containing personal data of visitors, subscribers and staff. When the museum refused to pay the demanded ransom, the group published all stolen data on the dark web.

Per the group’s dark web posting cited by Reuters, Rhysida is now in possession of 5.79 terabytes of stolen data from Berlin city systems. Der Spiegel has published a screenshot of the group’s dark web page showing the stolen assets include internal contracts, non-disclosure agreements, personnel records, user passwords, and thousands of personal contact details. The page also features an active seven-day countdown, after which the group says it will begin auctioning off the entire stolen dataset with a starting bid set to match its 30 bitcoin ransom demand.

Wegner reaffirmed the city’s stance in clear terms Friday: “Berlin will not be blackmailed.” He added that state police, public prosecutors, and federal German security services are working “with the utmost urgency” to identify the attackers and map the full extent of the breach. “Inquiries into the content and scope of the compromised data are being pursued with great intensity,” he said.

Notably, the attack comes roughly one month ahead of scheduled municipal elections in Berlin. However, State Senator Iris Spranger has moved quickly to reassure voters that all election-related digital infrastructure remains fully secure and was not compromised in the breach.

Cybersecurity researchers warn that Rhysida’s ongoing targeting of public sector institutions reflects a growing trend of ransomware actors targeting government entities, which often face greater pressure to resolve service disruptions quickly but also face widespread public backlash if they agree to pay ransoms that fund further criminal activity.