Berlin Refuses to Pay Hackers for Stolen State Network Data

Berlin state government refuses to negotiate with Rhysida ransomware group after massive data breach.

By Central
Berlin's government faces a critical test after hackers stole terabytes of state data.
Highlights
  • Berlin officials refused to pay a ransom after Rhysida hackers stole terabytes of state data.
  • The breach exposed personal information on over 12,000 individuals and 124,823 geodata files.
  • Security experts say the decision sets a precedent but risks public release of sensitive data.

Berlin’s state government has taken a firm stand against cyber extortion, publicly refusing to meet the demands of hackers who breached its administrative network and exfiltrated terabytes of data, including personal information on thousands of individuals. The decision, announced by Governing Mayor Kai Wegner after a special Senate session, marks a critical juncture in how public institutions respond to the growing threat of ransomware-driven data theft, particularly when the attackers have already demonstrated their capacity to steal sensitive information. The Berlin state network compromise, first disclosed in August 2026, has now been linked to the Rhysida ransomware group, a known threat actor that has targeted governments and critical infrastructure globally, and the city’s refusal to pay sets a significant precedent for other public bodies facing similar dilemmas.

Berlin’s State Network Breach: A Timeline of Events

The Berlin Senate Chancellery confirmed that the city’s state administrative network was compromised in August 2026, with forensic analysis revealing that data exfiltration occurred between August 7 and August 12. The Senate Department for Mobility, Transport, Climate Protection and Environment was identified as a primary source of the data outflow, though officials have not ruled out that personal or non-public data from other departments may also have been taken. The department first reported an anomaly on August 7, seven days before it was disconnected from the broader network on August 14 as a containment measure.

Berlin has not disclosed the total volume of data that left the network, but the attackers themselves have claimed responsibility on their darknet leak site, posting on August 28 that they had scanned 5.79 terabytes of data comprising approximately 1.44 million files. The leak-site entry, attributed to Rhysida, states that personal information on 12,076 individuals is among the stolen data. The entry identifies the victim simply as “Berlin, Germany” rather than any specific department, and no ransom figure was publicly posted. The file categories listed include 124,823 maps and geodata files, which together account for about a quarter of the claimed total file count.

Governing Mayor Kai Wegner stated unequivocally that “the state of Berlin is being blackmailed” and that the government would not give in to the extortionists’ demands. Interior Senator Iris Spranger added that, based on current assessments, no data from systems relevant to the conduct of the September 20 Abgeordnetenhaus election had been compromised, and that security officials regard the election environment as secure. The Senate Chancellery’s statement confirmed that the state criminal police, the public prosecutor, and federal security authorities are investigating the suspected perpetrators, though no group has been officially named by Berlin authorities.

Berlin first disclosed the incident on August 17, stating that forensic work had established a compromise of the state network and that affected departments had been isolated since the previous Friday. At a press conference on August 19, Wegner described the incident as serious but emphasized that, based on current knowledge, no sensitive data had left the network. Housing benefit applications and payments were temporarily unavailable while the two affected departments were offline, but all Senate departments were reconnected on August 23. Forensic work and scanning of the state network continue as of late August.

How the Attackers Gained Access: Rhysida’s Known Exploitation Methods

The Rhysida ransomware group, which has been linked to the Berlin attack, has a well-documented operational playbook. A joint advisory issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) in November 2023 outlines the group’s primary methods for initial access. Understanding these techniques is essential for any organization seeking to defend against similar threats.

What is Rhysida and how does it typically breach networks? Rhysida is a ransomware group that operates a double extortion model, encrypting victim data and exfiltrating sensitive information before demanding payment. The group’s primary initial access vectors include compromising valid accounts on external-facing remote services, exploiting the Zerologon vulnerability (CVE-2020-1472) in Microsoft’s Netlogon Remote Protocol, and conducting phishing campaigns. The advisory notes that the group often targets organizations that lack multi-factor authentication (MFA) enabled by default, allowing them to authenticate to internal VPN access points using compromised credentials.

The Zerologon vulnerability, which Microsoft patched on August 11, 2020, allows an attacker to elevate privileges within a domain. Despite being patched for over six years at the time of the Berlin attack, the inclusion of this vector in the advisory underscores the persistent challenge of legacy vulnerabilities in organizational networks. The advisory also records that phishing remains a successful route into victim networks for Rhysida, highlighting the importance of user awareness and email security controls.

The advisory strongly discourages paying ransom, stating that “the FBI and CISA do not encourage paying ransom” because payment does not guarantee data recovery and may embolden adversaries to target further organizations. The agencies recommend prioritizing remediation of known exploited vulnerabilities, enabling multi-factor authentication across all services, and segmenting networks to prevent ransomware from spreading laterally.

Rhysida’s Victimology: A Global Pattern of Targeting Public Institutions

The Berlin attack fits a broader pattern of Rhysida targeting public sector organizations and critical infrastructure. The monitoring service that tracks Rhysida victims listed 280 entries as of August 29, 2026, with nine of those in Germany. Notable German victims include the Stuttgart city administration, which was attacked in May 2026, and the aid organization Welthungerhilfe, which was compromised in June 2025. Internationally, the group’s victims include the Port of Seattle, which operates Seattle-Tacoma International Airport, listed in September 2024.

The advisory also notes open-source reporting of similarities between Rhysida and Vice Society, a group that Microsoft tracks as Storm-0832. Check Point published analysis in 2023 outlining the operational overlap between the two groups, suggesting that Rhysida may have evolved from or be closely related to Vice Society. This connection is significant because Vice Society has historically targeted educational institutions and healthcare organizations, and the technical overlap implies that Rhysida may have access to a broad arsenal of tools and techniques refined over years of operations.

The Berlin Senate Chancellery has stated that the state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed on a continuing basis. However, as of August 29, no statement on the incident had been published by the Berlin Commissioner for Data Protection and Freedom of Information, leaving affected individuals without official guidance on how to protect themselves from potential identity theft or fraud resulting from the data breach.

Why Berlin Refuses to Pay: Strategic Considerations and Risks

Berlin’s decision to refuse payment is consistent with the official guidance from U.S. and international cybersecurity authorities, but it carries significant implications. The attackers have already demonstrated that they possess a substantial volume of data, including personal information on over 12,000 individuals. By refusing to pay, Berlin is betting that the attackers will not follow through on their threat to release the data publicly, or that the damage from any release can be managed.

The decision also reflects a broader strategic calculation: paying ransom does not guarantee that the data will be destroyed or returned, and it may encourage further attacks against the city or other public institutions. The CISA/FBI advisory explicitly warns that payment may embolden adversaries, and Berlin’s public stance may serve as a deterrent to other groups considering similar attacks. However, the city must now contend with the possibility that the attackers will release the data to demonstrate credibility and pressure other victims to pay in the future.

The absence of any official guidance for the 12,076 individuals whose data may be compromised is a notable gap in Berlin’s response. Affected individuals are left without specific instructions on how to monitor for identity theft, place fraud alerts, or protect themselves from phishing attacks that may use the stolen data to appear credible. The Senate Chancellery’s statement that personal or other non-public data cannot be excluded from what was taken adds to the uncertainty, as does the lack of a publicly available list of data categories or systems that were compromised.

Berlin’s Interior Senator Iris Spranger has sought to reassure the public regarding the integrity of the upcoming election, stating that no data left the areas relevant to the conduct of the September 20 Abgeordnetenhaus election. This assurance is critical for maintaining public confidence in the electoral process, but it also raises questions about what other sensitive systems may have been exposed and what data the attackers actually possess.

Parallel Incident: Manchester Airports Group Confirms Customer Data Theft

In a separate but related development, Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports, confirmed on August 27 that an unauthorized third party had obtained customer data relating to car park, lounge, and Fast Track bookings, as well as in-airport WiFi sign-ups. The data obtained includes email addresses, phone numbers, vehicle registrations, and postcodes, but MAG has stated that neither it nor the accessed system holds customers’ bank or payment details.

MAG’s statement emphasizes that “at no point has passenger safety or aviation security been compromised” and that airport operations and customer parking services continue to operate normally. The company describes the affected system as distinct from MAG itself, though the exact nature of the system and the method of access have not been publicly detailed. Access to the online Manage My Booking service has been suspended as a precautionary measure, and customers with bookings due within 72 hours are directed to contact customer services by phone.

A figure of roughly 8.7 million affected customers has circulated widely in press reports, attributed to a company spokesperson, though MAG’s own official materials leave the count unstated. MAG has contacted affected customers directly and directed them to the U.K. National Cyber Security Center’s (NCSC) data breach guidance, advising them to stay alert for suspicious emails, text messages, and phone calls. The incident highlights the ongoing vulnerability of customer-facing systems in the transportation sector, where large volumes of personal data are collected and stored for operational purposes.

The Broader Landscape: Ransomware Threats to Public Infrastructure

The Berlin and MAG incidents, occurring within weeks of each other, underscore the persistent and evolving threat that ransomware and data extortion groups pose to public infrastructure and government operations. The Rhysida group’s focus on German state and municipal governments, combined with its track record of targeting ports, airports, and aid organizations, demonstrates a strategic interest in organizations where disruption can cause significant economic and social impact.

The advisory from CISA, FBI, and MS-ISAC, though dating to November 2023, remains highly relevant. The technical guidance on enabling multi-factor authentication, patching known vulnerabilities, and segmenting networks represents the baseline defensive posture that organizations should maintain. The fact that the Zerologon vulnerability, patched in 2020, remains a viable attack vector for Rhysida suggests that many organizations still struggle with fundamental patch management and network hygiene.

For Berlin, the immediate priority is completing the forensic investigation to determine the full scope of the data exfiltration and to identify the individuals whose data may have been compromised. The city must also communicate clearly with affected residents, providing them with specific steps to protect themselves from potential fraud or identity theft. The longer-term challenge is rebuilding trust in the security of the state network and implementing the systemic changes needed to prevent a recurrence. The decision to refuse payment, while principled and consistent with official guidance, places the city in a precarious position: the attackers still hold the data, and the risk of public release remains.

The incident also raises questions about the adequacy of current cybersecurity frameworks for public sector organizations, particularly in Germany, where state and municipal governments operate with varying levels of security maturity. The Berlin Senate’s disclosure that the state data protection commissioner and the BSI are being kept informed suggests a coordinated response, but the lack of public guidance for affected individuals is a gap that should be addressed urgently. The September 20 election adds a layer of urgency, as any data release in the weeks before the vote could be used to manipulate public opinion or disrupt the electoral process.

Berlin’s refusal to pay the hackers is a statement of principle, but it is also a calculated risk. The outcome of this incident will be closely watched by other governments and public institutions worldwide, as they assess their own vulnerability to ransomware and the consequences of choosing not to comply with extortion demands. The city’s response, from the initial containment to the public stance on payment, offers a case study in how governments can navigate the complex terrain of modern cyber extortion—but the final chapter of this story has yet to be written, and the data in the hands of the Rhysida group remains a potent threat.

Share This Article