The municipal government of Berlin has been targeted in a major cyberattack that resulted in the theft of massive volumes of administrative data, leading to a high-stakes extortion attempt by illegal hackers. Mayor Kai Wegner publicly announced that the German capital would strictly refuse to bow to any ransom demands issued by the perpetrators. The extortion attempt was formally delivered on Thursday evening, triggering an emergency response across municipal IT operations and law enforcement channels. Reports indicate that the cybercriminals responsible are demanding a sum of 30 bitcoin, which translates to approximately €2 million or £1.7 million, to prevent the unauthorized release and auction of the stolen records.
Critical Municipal Network Disruptions and Forensic Findings
The cyber intrusion began unfolding earlier in August when unauthorized actors gained access to municipal servers. Official disclosures from the city-state administration confirm that an initial data breach took place between August 7 and August 12. As security teams detected suspicious activities, administrative authorities took immediate preventative measures on August 14 by shutting down network operations across two key city departments. This operational suspension halted crucial public digital tools, rendering local residents temporarily unable to submit applications for housing benefits or process government payments for several consecutive days.
Subsequent forensic investigations conducted by cybersecurity specialists uncovered further evidence of unauthorized data exfiltration targeting Berlin transport and environment department. In an official communication released on Friday, the mayor office stated that personal or other non-public records could potentially be exposed as a result of the compromise. Technical crews and investigators are currently working under intense pressure to ascertain the precise extent of the breach, evaluate the sensitivity of the compromised files, and restore full functionality to all impacted municipal digital infrastructure safely.
Ransom Demands and Dark Web Data Auction Threats
Following the breach, the extortionists escalated their tactics by establishing a countdown timer on a dark web platform, signaling their intent to monetize the stolen files if their ransom demands are ignored. According to details emerging from dark web monitoring and media reports, the hackers claim to have successfully stolen 5.79 terabytes of data from Berlin government servers. The group announced that if the 30 bitcoin ransom is not paid within a seven-day window, they will initiate a public online auction to sell off the confidential cache to the highest bidder.
Screenshots of the group dark web posting reveal an extensive catalog of compromised internal documents. Among the stolen contents are official municipal contracts, non-disclosure agreements, sensitive internal personnel files, administrative login credentials and passwords, alongside thousands of private contact entries belonging to government staff and associated entities. The dark web portal explicitly lists the starting bid for the data auction at 30 bitcoin, identical to the ransom total demanded directly from the city administration.
The Rhysida Cybercrime Syndicate Profile
Although municipal authorities have not formally named the syndicate in official legal proceedings, evidence points toward the notorious ransomware gang known as Rhysida. Cybersecurity researchers believe the group operates predominantly out of Russia and Eastern Europe. Since its emergence in 2023, Rhysida has established a track record of high-profile cyber extortion campaigns targeting public institutions, healthcare organizations, and commercial enterprises of varying sizes across numerous international jurisdictions.
The syndicate gained widespread notoriety in 2023 following a severe cyberattack on the British Museum. During that incident, Rhysida operators infiltrated the institution internal IT networks, causing widespread operational disruption and exfiltrating approximately 500,000 sensitive internal files. Their operational methodology typically involves encrypting target systems, exfiltrating critical databases, and threatening public exposure or commercial auction if extortion demands are not met promptly.
Law Enforcement Investigation and Upcoming Election Security
In response to the unprecedented municipal breach, Mayor Kai Wegner reaffirmed that Berlin leadership maintains a firm stance against paying ransoms to digital extortionists. State police forces, public prosecutors, and federal security agencies have launched a coordinated criminal investigation aimed at identifying and prosecuting the perpetrators with the utmost urgency. Law enforcement personnel and forensic experts are analyzing server logs and network traffic to trace the digital signatures of the intruders.
The cyberattack has generated heightened scrutiny as Berlin approaches municipal elections scheduled to take place in roughly a month. Addressing potential concerns regarding electoral integrity, State Senator Iris Spranger provided public assurances that the city election infrastructure operates on separate, secured systems and has not been compromised by the security breach. Authorities continue to monitor all municipal digital perimeters closely to prevent further unauthorized access while working to fortify systemic vulnerabilities across all administrative networks.


















