Berlin faces multi-million-euro ransom demand following cyberattack

August 28, 2026

Berlin is facing a ransom demand following the cyberattack on several of the German capital’s Senate administrations. Governing Mayor Kai Wegner has ruled out paying the attackers, while state and federal security authorities continue to investigate the extent to which sensitive government data may have been compromised.

The incident, which became known on 14 August, affected IT systems at Berlin’s Senate administrations responsible for urban development and mobility, among other areas. The affected administrations were temporarily disconnected from the city-state’s network as a security measure.

The disruption also had consequences for public services. For several days, residents were unable to apply for or receive housing benefit payments, illustrating how cyberattacks against public-sector IT can rapidly affect essential administrative processes.

According to German media reports, the ransomware group Rhysida has claimed responsibility for the attack. On a Dark Web leak site, the group is reportedly demanding 30 Bitcoin, worth around €2 million, and threatening to publish stolen information if Berlin refuses to pay.

The attackers claim to have obtained almost six terabytes of data. The alleged material reportedly includes information relating to around 80,000 administrative offence proceedings, more than 46,500 contracts, as well as documents concerning critical infrastructure, judicial matters and emergency plans. Passwords and thousands of files containing login credentials are also claimed to be among the compromised material.

The scale and contents of the alleged data theft have not been independently verified. It therefore remains unclear whether all of the information claimed by the group was actually exfiltrated and whether the material presented by the attackers is authentic.

Berlin refuses to pay

Berlin’s Governing Mayor Kai Wegner described the attack as a serious criminal offence and made clear that the city-state would not give in to the ransom demand.

Security authorities at both state and federal level are continuing their investigation into the perpetrators and the possible loss of confidential information. Berlin authorities had initially said that sensitive data had not been compromised, but subsequently acknowledged that personal or other non-public information could have been affected.

The potential exposure of information concerning critical infrastructure, emergency planning and government access credentials gives the incident significance beyond the immediate disruption to administrative services. If the attackers’ claims are confirmed, the breach could create longer-term security risks even after affected IT systems have been restored.

The incident also comes only weeks before Berlin’s House of Representatives election on 20 September. Interior Senator Iris Spranger has said that the election is fully secured and will not be affected by the cyberattack.

The case once again highlights the growing operational consequences of ransomware attacks against public administrations: the immediate challenge is no longer limited to restoring encrypted or disconnected systems. Authorities must increasingly manage the simultaneous risks of service disruption, data exposure and subsequent extortion.

Related Articles

Share This