Berlin blackmailed by hackers, mayor says city will not give in to ransom demand

Cyberattack cripples city systems, 5.7 terabytes of data stolen, gang threatens to auction files

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
Berlin is being blackmailed by hackers who breached city systems and stole data earlier this month, Mayor Kai Wegner said on Friday, vowing the German capital will not cave to the ransom demand.

Wegner said officials received a ransom demand on Thursday evening. He did not disclose the amount, though Der Spiegel reports the hackers are demanding 30 bitcoin, worth around €2 million (£1.7 million).

The attack forced some of the city's online systems offline, disrupting services including housing benefit applications and payments for several days.

Investigators are working to determine the full extent of the breach. Officials said the initial data leak occurred between 7 and 12 August, and two department networks were shut down on 14 August. Subsequent forensic investigations revealed further data leaks within Berlin's transport and environment department.

"It cannot be ruled out that personal or other non-public data may also be affected," the mayor's office said in a statement.

The Rhysida group, which is thought to operate from Russia and eastern Europe, has reportedly taken responsibility. The group was also behind a previous attack on the British Museum, according to news reports.

Rhysida has said on its website that it intends to begin auctioning the 5.79 terabytes of data it was able to steal from Berlin in seven days' time, according to Reuters.

"Berlin will not be blackmailed," Wegner said. He said state police, prosecutors and federal security services were investigating the suspected perpetrators "with the utmost urgency," and that inquiries into the "content and scope of the compromised data are being pursued with great intensity."

Authorities have not officially named the suspected cyberattackers, though Der Spiegel is carrying a screenshot of the Rhysida group's dark web site claiming to possess files.

§

Analysis

Why This Matters

  • A major European capital city has been crippled by ransomware, disrupting public services and threatening to leak terabytes of sensitive government and personal data.
  • The attack signals a growing willingness by cybercriminal groups to target public sector institutions, which are often under-resourced in cybersecurity but hold vast amounts of citizen data.
  • The auction of stolen data represents an escalation in ransomware tactics, moving beyond encryption and extortion to direct data sales on the dark web.

Background

Ransomware attacks on municipal governments have become increasingly common worldwide. The Rhysida group, a relatively new ransomware strain first identified in mid-2023, has quickly gained notoriety for targeting high-value institutions including the British Museum and hospitals. The group typically uses a double-extortion model: encrypting files and threatening to leak stolen data unless a ransom is paid. Public sector systems are often particularly vulnerable due to aging infrastructure and limited cybersecurity budgets.

Key Perspectives

City of Berlin: Maintaining that paying ransoms only emboldens attackers and funds further criminal activity. Officials are prioritizing incident response, system recovery, and investigation, while warning citizens their personal data may have been compromised.

Cybersecurity experts and privacy advocates: The 5.79 TB data haul likely includes sensitive citizen information such as addresses, bank details, and welfare applications. Even if the ransom is not paid, the data may already be in the hands of criminals who could use it for identity theft or fraud.

Rhysida Group (via dark web communications): The group appears motivated by both financial gain (the bitcoin ransom) and reputational damage (the threat to auction data publicly). Their targeting of a major capital city suggests operational confidence and a willingness to take extreme risks.

What to Watch

  • The seven-day deadline for the data auction: whether Rhysida follows through on its threat
  • Official updates on which specific systems and data types were compromised, and whether citizen notification becomes necessary under EU GDPR rules
  • Broader implications for German and European cybersecurity policy, including potential calls for mandatory ransomware reporting and stronger public sector defences

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.