News

Berlin Refused to Pay Rhysida’s $2.3 Million Ransom. Here’s Everything That Happened.

Wireframe illustration of a government building with data files streaming out through a crack, labelled 5.79 TB across 1,440,000 files stolen in the Berlin Rhysida ransomware attack.

A ransomware group broke into Berlin’s government network, sat inside for five days pulling files, and then put 5.79 terabytes of stolen data up for auction on the dark web, timed to go live less than a month before Germany’s capital holds its state elections.

Berlin’s response was public and unambiguous. Governing Mayor Kai Wegner stood in front of cameras and said the state was being blackmailed, and that it would not pay. “The state of Berlin is being blackmailed,” he said. “We will not comply with the attackers’ demands.”

That’s the clean version of the headline. But the story behind it is messier, more detailed, and more worrying than the wire reports suggest.

Quick answer: Rhysida, a Russian-linked ransomware-as-a-service group, breached Berlin’s government network between August 7 and 12, 2026, stealing an estimated 5.79TB of data including contracts, emails, phone numbers, passwords, and personal records of over 12,000 people.

The group claimed responsibility on August 28 and listed the data for auction starting at 30 bitcoin, roughly $2.3 million. Berlin confirmed the breach on August 31 and publicly refused to pay. Election systems were separately confirmed as unaffected ahead of Berlin’s September 20 state elections.

How the Attack Unfolded

The breach didn’t start with an explosion. It started with a quiet five-day window that investigators only pieced together afterward.

Forensic analysis shows the attackers were inside Berlin’s network and actively pulling files between August 7 and August 12, 2026. The affected department was the Senate Department for Mobility, Transport, Climate Protection and Environment, one of two Berlin ministries that share IT infrastructure and run their section of Berlin’s state backbone network, the Landesnetz, independently of the city’s main IT provider.

Berlin’s government first detected suspicious data movement around August 7. The two compromised departments weren’t disconnected from the wider Landesnetz until August 14, seven days later. That gap matters. It’s not a detail buried in a technical report; it’s the reason the breach became as large as it did. Seven days of uninterrupted access to a government network connected to around 600 sites across Berlin โ€” covering government offices, police, fire services, and hospitals, is a long time for an attacker moving data outward. The disconnection on August 14 stopped the bleeding, but the window had already closed.

The second affected ministry, the Senate Department for Urban Development, Building and Housing, was also cut off as a precaution. Both remained operational, but employees lost access to their normal IT systems overnight. Staff resorted to telephone, text messages, and fax to keep working.

What Got Stolen

Berlin’s state government confirmed data was stolen on August 31, 2026, moving the story from a criminal group’s claims to an official acknowledgment. They’ve confirmed the theft without fully verifying every number Rhysida put out.

What Rhysida claims it took across 1.44 million files includes personal data on 12,076 individuals, 16,389 email addresses, 11,963 phone numbers, 148 IBAN bank account numbers, 46,500 contracts, classified documents, passwords, and records covering government, legal, financial, HR, infrastructure, health, and mapping categories.

One technical report from TechTimes also identified what appears to be water-supply vulnerability assessments in the dataset, the kind of operational infrastructure detail that moves this breach beyond a simple data theft into territory that security agencies treat very differently.

Berlin authorities are still investigating the full scope. They haven’t publicly confirmed whether every category Rhysida listed is accurate or verified. What they have confirmed: data left the network, the exfiltration window was real, and the personal information of Berliners may have been compromised.

The ITDZ Berlin, the city-state’s main IT provider, was not affected. The two ministries operated their own segment of the state network separately, which is both why the breach was contained and why it wasn’t caught faster, independent infrastructure means independent monitoring, which doesn’t always mean better monitoring.

The Auction: 30 Bitcoin, Seven-Day Countdown

On August 28, Rhysida posted Berlin’s data to their dark web leak site, listing it under the entry “Berlin, Germany.” The format is the same one they use for all their victims: a description of the data, a screenshot or sample as proof, and a countdown timer.

The opening auction price was 30 bitcoin, worth roughly $2.3 million at current rates. The clock was set to run for approximately seven days.

This is Rhysida’s preferred approach, and it’s worth understanding why. Traditional ransomware encrypts a victim’s systems and demands payment to restore access. That’s immediately obvious, systems go dark, employees can’t work, the disruption is instant and visible. Rhysida uses double extortion, which is different. They steal the data first, then post it publicly and demand money to prevent publication. The victim’s systems may keep running. The threat is a leak, not an outage.

For a government body, that distinction matters enormously. Encrypted systems are a crisis that can be managed with backups. A public release of 46,500 contracts, government passwords, and the personal data of thousands of citizens is a political crisis with a completely different shape, one that lands directly on elected officials and affects real people’s trust in their government. Rhysida understands this, which is why they specifically target public institutions.

The way Rhysida’s auction model works connects directly to the broader ransomware economy we’ve covered in detail, the same financial infrastructure, mixers, and underground markets that the AudiA6 takedown this June exposed. Groups like Rhysida rely on that infrastructure to turn stolen data and ransom payments into usable cash without a traceable trail.

Berlin Said No. Why That Actually Matters.

Refusing to pay isn’t just a political statement. It’s an argument about deterrence with real economic logic behind it.

Every ransom payment funds the next attack. When Rhysida gets paid, it pays its affiliates, improves its tools, and recruits more people under its ransomware-as-a-service model. The return on investment for hitting a government target goes up every time a government pays. When Berlin publicly says no and says it loudly, it changes the math slightly for every future criminal group sizing up a European city as a target.

It also demonstrates something practically important: you can survive a ransomware attack without paying. The two affected ministries kept functioning, employees adapted, and the election timeline was not disrupted. That won’t always be true, the British Library’s recovery took over a year and cost an estimated $7.5 to $8.7 million even after refusing to pay, but Berlin’s ability to keep the lights on undermines the core threat Rhysida was selling.

Interior Senator Iris Spranger confirmed that Berlin’s election systems, which operate separately from the affected departments, were protected and showed no sign of compromise. “According to our security officials, the election environment is secure,” she said. Berlin’s September 20 state elections proceeded on schedule.

Who Is Rhysida?

Rhysida is a ransomware-as-a-service operation that first appeared publicly in May 2023. Under the RaaS model, the same basic structure as Ransom Cartel, which we covered when its creator received a 16-year sentence earlier this year, the core group builds and maintains the ransomware infrastructure, then leases it to criminal affiliates who run individual attacks and split the ransom proceeds with the operators.

As of late August 2026, Rhysida had listed around 280 confirmed victims across 39 countries. Nine of those are German organisations. Among them: the Stuttgart city administration, attacked in May 2026 (just three months before Berlin), and the humanitarian aid organisation Welthungerhilfe, hit in June 2025.

Their wider track record includes some high-profile names. The British Library was hit in October 2023. The library refused to pay, Rhysida published the data, and the recovery took the institution well over a year, prompting the library to publish one of the most detailed and candid post-incident reviews any public sector organisation has ever released. Insomniac Games, the Sony-owned studio, was hit in December 2023.

Rhysida leaked 1.3 million files, including employee passports, internal Slack messages, and full development details for the then-unannounced Marvel’s Wolverine game. The Chilean Army, the Port of Seattle (which runs Seattle-Tacoma International Airport), and the Kuwait Ministry of Health are also on the list.

CISA and the FBI issued a joint cybersecurity advisory on Rhysida in November 2023, designated AA23-319A, specifically warning about the group’s tactics and indicators of compromise. The advisory documents how Rhysida affiliates have used fake Microsoft Teams installers to gain initial access, and how the group uses legitimate built-in system tools (known as Living off the Land Binaries, or LoLBins) once inside a network, making detection harder because the malicious activity blends with normal system operations.

Cybersecurity researchers have linked Rhysida to Vice Society, a previous ransomware group that heavily targeted the education sector. Shared tools, similar techniques, and overlapping infrastructure are the basis for that link, though Rhysida has operated as a distinct brand. Researchers broadly assess the group is Russian-speaking or operates from the broader Russia and Eastern Europe region, though specific identities and precise location remain unverified publicly.

The Seven-Day Gap Is the Real Lesson

Every major news outlet covering this story reported that Berlin refused to pay. Most left the story there.

The more important detail is the seven days between when Berlin first detected suspicious data movement on August 7 and when it finally disconnected the compromised departments from the Landesnetz on August 14. That window is why 1.44 million files left the building.

This is the pattern we see consistently in government ransomware incidents. Detection is rarely the problem โ€” most breaches get noticed. The problem is what happens in the gap between detection and containment. Networks are interconnected. Cutting off a department means disrupting services. Someone has to make a call about whether to pull the plug on systems that citizens depend on, and that decision takes time.

In Berlin’s case, the Landesnetz connects roughly 600 sites. The two affected ministries plugged into that backbone carried their own section of it. The decision to disconnect them had consequences for every service that depended on their systems, including district offices that couldn’t process housing benefit applications or education assistance because those systems sat in the affected ministry’s infrastructure. The disruption was real and immediate. That’s exactly why the disconnection took a week instead of a day.

It’s the same tension we see in supply chain attacks more broadly: the most damaging breaches exploit the hesitation that comes with interconnected, critical systems. The cost of disconnecting feels too high in the moment. Seven days later, it turns out the cost of not disconnecting was higher.

What Happens Next

The State Criminal Police Office, Berlin’s public prosecutor, and federal security agencies are all investigating. The Federal Office for Information Security (BSI) and Berlin’s data protection commissioner are being kept informed on an ongoing basis.

Rhysida’s auction countdown has since expired. The outcome, whether the data was sold, retained, or dumped publicly, has not been officially confirmed at the time of writing. The pattern from previous Rhysida cases is that if no buyer pays the auction price, the group either publishes the data to demonstrate they follow through on threats, or quietly holds it for future leverage.

For the 12,076 individuals whose personal records are potentially in that dataset, the practical advice applies regardless of what Rhysida ultimately does with the files. Assume your information may be circulating. Watch for unexpected contacts that reference personal details you’ve only given to government services.

Be suspicious of any communication claiming to be from Berlin government departments, especially ones asking you to confirm identity or click a link. And check our guide on what to do when your data is on the dark web, not because the situation is identical, but because the practical steps for protecting yourself after an unwanted exposure follow the same logic regardless of the source.

Frequently Asked Questions

Who attacked Berlin’s government?

The Rhysida ransomware group claimed responsibility on August 28, 2026. Rhysida is a ransomware-as-a-service operation that has been active since May 2023, with researchers assessing it likely operates from Russia or Eastern Europe.

How much data was stolen?

Rhysida claims 5.79TB across 1.44 million files, including personal data on 12,076 individuals, 46,500 contracts, email addresses, phone numbers, IBAN numbers, passwords, and classified documents. Berlin confirmed data was stolen but has not independently verified every figure in Rhysida’s claim.

Did Berlin pay the ransom?

No. Governing Mayor Kai Wegner publicly refused to comply with the extortion demand.

Were Berlin’s election systems affected?

No. Interior Senator Iris Spranger confirmed election infrastructure was protected and showed no signs of compromise. Berlin’s September 20 state elections proceeded on schedule.

How long did the attackers have access before being stopped?

Data exfiltration occurred between August 7 and 12. The affected departments weren’t disconnected from Berlin’s central network until August 14, a seven-day gap that security researchers say was the primary reason such a large volume of data could be removed.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

๐Ÿ“‹ Latest Articles

View all →
Cracked magnifying glass made of blue circuit lines powering down while data fragments drift away, illustrating the shutdown of Google's Dark Web Report
Monitoring

Google Killed Its Dark Web Report – What to Use Instead

Starting from the 16th of February 2026, Google dark web report shut down its operation completely. This comes…

Sep 5, 2026
13 min read
Glowing wireframe file icon labelled wp-config.php.bak alone in a dark server corridor, illustrating the WordPress backup files allegedly left publicly accessible on Sonora government portals.
News

Sonora Government Portals Allegedly Left Live Database Passwords Sitting in Plain Sight

A threat actor has posted what they claim are publicly accessible WordPress configuration backup files from municipal government…

Sep 5, 2026
5 min read
153 Million Driver's Licenses Showed Up on the Dark Web
News

153 Million Driver’s Licenses Showed Up on the Dark Web. Here’s the Full Story.

You handed your driver’s license to a Hertz agent, a hotel front desk, or a dispensary door scanner.…

Sep 4, 2026
9 min read
PNLD breach
News

PNLD Breach: The UK Police Data Leak, the ExfilSquad Campaign, and What Nobody Is Telling You

On July 26, 2026, a group nobody had heard of before posted to a dark web leak site…

Sep 3, 2026
11 min read
Ransom Cartel's Creator Gets 16 Years
News

Ransom Cartel’s Creator Gets 16 Years โ€” And He Helped Invent the Whole Ransomware Business Model

The man who walked out of cybercrime forums in 2021 with a fresh ransomware operation he called Ransom…

Sep 3, 2026
8 min read
Can My Data Be Removed From the Dark Web
Monitoring

Can My Data Be Removed From the Dark Web? The Honest Answer

Are you wondering if your data can be removed from the dark web? No. Once something you own,…

Sep 3, 2026
7 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted