Berlin Won’t Pay Extortion Group Claiming Data Theft

Summary: The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

Berlin Refuses to Pay Rhysida After Hackers Claim Theft of 5.7 TB of Government Data

Berlin authorities have confirmed that they will not pay a ransom demanded by cybercriminals following a major intrusion into the German capital’s government infrastructure. The decision comes as the Rhysida ransomware group claims responsibility for the attack and says it stole more than 5.7 terabytes of data, including credentials, financial information, legal documents and personal records.

The incident was discovered on August 14 and affected Berlin’s Senate Department for Mobility, Transport, Climate Protection and Environment. Authorities responded by shutting down the department’s network, while the network belonging to the Senate Department for Urban Development, Construction and Housing was also taken offline as part of containment efforts.

Attackers may have spent days extracting data

Berlin’s investigation indicates that data was exfiltrated between August 7 and August 12, meaning attackers potentially had several days to collect information before the incident was discovered.

Officials have acknowledged that personal and non-public information was likely affected but have released relatively few technical details while the investigation continues. The case is being examined by Berlin’s state criminal police together with federal security authorities and the public prosecutor’s office.

Berlin has not publicly attributed the intrusion to a specific group. Rhysida, however, briefly listed the city on its Tor-based leak site on August 28 and claimed responsibility.

The distinction is important. Ransomware groups regularly publish victims to pressure them into negotiations, but their claims about the amount and sensitivity of stolen information should be treated as allegations until independently confirmed.

Rhysida claims an unusually large collection of government data

According to the attackers, the stolen material includes complaints and legal documents, contracts, financial records, HR files, passwords and confidential government information.

Rhysida also claims to possess personal information belonging to more than 12,000 people, along with over 16,000 email addresses and nearly 12,000 phone numbers. The group says the compromised material contains IBAN banking information, payroll records, passport and identification data, plaintext credentials, lawsuit files and private information concerning government leadership.

If those claims are accurate, the incident could have consequences extending well beyond the initial network intrusion. Credentials could potentially facilitate follow-on attacks, while identity and financial information could support phishing, impersonation and fraud.

Legal and administrative documents present a different problem. Government datasets frequently contain information about citizens who never directly interacted with the compromised IT systems, meaning the impact of a breach can extend to people who had no practical ability to protect the affected information themselves.

Berlin rejects a $2.3 million ransom demand

Rhysida reportedly demanded 30 bitcoin, worth approximately $2.3 million, in exchange for the stolen information. Berlin’s governing mayor Kai Wegner and Senator for the Interior and Sport Iris Spranger confirmed that a ransom demand had been made but said the city would not pay.

That decision removes one of the attackers’ primary sources of leverage but does not eliminate the consequences of the breach. Modern ransomware operations increasingly rely on data theft even when encryption is limited or absent. Once information has been exfiltrated, restoring systems from backups cannot solve the underlying problem.

Attackers can threaten publication indefinitely, sell information to other criminals or use stolen credentials in additional operations.

This is why ransomware has increasingly evolved into data extortion. The valuable asset is no longer simply the victim’s ability to access its computers; it is also the confidentiality of the information the organization was responsible for protecting.

Refusing payment shifts the problem toward containment

Berlin’s position reflects the difficult economics surrounding ransomware. Paying may appear to provide a faster path toward preventing publication, but there is no technical mechanism forcing criminals to delete stolen information after receiving money.

Refusing payment avoids financing the attackers and reduces the incentive for future attacks, but it also means organizations must prepare for the possibility that stolen information will eventually become public.

That makes incident response considerably broader than rebuilding servers. Berlin now needs to determine precisely what was taken, identify potentially compromised credentials, assess whether authentication secrets must be rotated and establish which individuals may require notification.

The scale of that investigation can be substantial when several terabytes of government information are involved.

The breach demonstrates the changing economics of ransomware

The Berlin incident illustrates why ransomware remains effective even as organizations improve backups and recovery capabilities. Attackers have adapted by targeting something backups cannot restore: confidentiality.

For public institutions, that creates an especially difficult problem. Government networks contain administrative records, financial information, employee data, legal documents and correspondence accumulated over many years. A single intrusion can therefore expose multiple categories of sensitive information simultaneously.

Berlin’s refusal to pay sends a clear message that extortion will not automatically produce a financial reward. But the success of that strategy ultimately depends on resilience before and after an attack: segmentation, credential protection, rapid detection and the ability to identify and respond to stolen information.

The most significant question is therefore no longer whether Berlin can restore its affected systems. It is how much information actually left those systems during the five-day exfiltration window and what attackers can still do with it.

⁠Original report at SecurityWeek

Key facts

  • The Rhysida ransomware group claims to have exfiltrated over 5TB of data
  • The stolen data allegedly includes personal information and credentials
  • Berlin has stated it will not pay any ransom to the extortion group

Why it matters

Berlin's refusal to pay a ransom sets a precedent for governmental entities facing cyber extortion. It signals a commitment to not funding criminal enterprises, potentially encouraging other organizations to adopt similar non-payment policies, though this could also lead to the public release of sensitive exfiltrated data.