Berlin's state government refused a ransom demand of 30 Bitcoin from the Rhysida ransomware group, allowing the deadline to expire on Friday, September 4. The hackers subsequently published 5.7 terabytes of stolen data on the dark web.
Rhysida, active since 2023, opened bidding on the stolen files at 30 BTC, which equated to approximately $2.4 million at the time. Berlin's Senate Chancellery valued the demand at roughly two million euros. Florian Hauer, the city's chief digital officer, rejected any payment, stating: "The State of Berlin will not give in to blackmail. The safety of the State of Berlin's staff and the people of Berlin is our top priority."
Impact and Response
The attack surfaced on August 14, prompting Berlin to disconnect two Senate departments from the state network: one handling urban development and housing, the other managing mobility, transport, and the environment. Housing benefit payments and family support were suspended until both departments returned to service on August 23.
Officials warned residents that personal data could be included in the leaked files. A central crisis unit has begun reviewing the published material, with forensic specialists examining the files around the clock. The State Criminal Police Office and Germany's federal cybersecurity agency are leading the investigation. Residents have been advised to report any fraud or identity theft to police.
Broader Context
Berlin's refusal aligns with a wider trend: on-chain ransomware payments fell approximately 8 percent in 2025, even as claimed attacks rose 50 percent. The state has not disclosed a damage estimate, and the review of released files continues.


