Berlin Rejects Blackmail: State Refuses to Pay Hackers After Major Data Breach

Berlin confirmed this week that after its state administrative network was breached in August, it is refusing to comply with ransom demands from the attackers. A forensic investigation uncovered that data theft took place at the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and August 12, 2026.

While the scope of the breach is still under investigation, it may include personal or confidential information. The intrusion led to the isolation of affected departments on August 14, and service disruptions including unavailability of housing benefits and payments. All affected state departments were restored to the network by August 23.

The attackers, allegedly Rhysida, claim to have stolen around 5.79 terabytes of data spanning more than 1.44 million files. Their own leak site lists 124,823 maps and geodata files among the most significant category, but no official figure has been confirmed by authorities. Around 12,076 individuals are reported to have had personal data compromised, though the full remit remains unverified.

The Berlin Senate says it will not pay any ransom. City leadership, including the Governing Mayor, characterize the situation as blackmail. Legal proceedings are underway, with investigations being led by the state criminal police, federal security agencies, and the public prosecutor’s office. No definitive attribution has been confirmed despite reports that Rhysida posted about Berlin on its darknet leak site.

Who’s Behind It & Advice From Experts

The suspected group, Rhysida, has ties to previous double extortion attacks. According to a joint advisory by U.S. cybersecurity agencies, their typical access methods include exploiting weak access credentials, abusing external-facing remote accounts, exploiting vulnerabilities like Zerologon (a known privilege elevation flaw in Microsoft’s Netlogon protocol), and phishing. These methods have been documented since late 2023.

Authorities advise organizations to close known vulnerabilities, enforce multi-factor authentication (especially on remote/external-facing systems), segment critical network infrastructure, and maintain constant forensic readiness. Performing regular audits and updates is strongly encouraged to avoid exposure to similar attacks.

Impact, Timing & Risks Ahead

Berlin’s breach comes just ahead of a key election scheduled for September 20. Officials have clarified that no data affecting the forthcoming state election appears to have been compromised. Nonetheless, residents whose records are implicated have yet to receive formal guidance.

To date, authorities involved include the Senate Chancellery, Berlin’s data protection watchdog, and national cybersecurity entities. Transparency so far has focused on the investigation’s progress, root causes, and infection vectors—rather than disclosing exact numbers or specific identities of individuals impacted.

Berlin’s stance echoes growing international consensus that paying ransom can undermine long-term security by incentivizing attackers. While recovery of stolen data is never guaranteed by complying, refusing to yield poses immediate risks for victims whose sensitive data may be exposed. The city’s refusal sets a precedent for how public institutions might confront extortion without legitimizing demands.