# Hackers Demand Millions in Bitcoin After Infiltrating Berlin Government Systems as Mayor Refuses Extortion

> Cybercriminals have compromised official networks in Berlin and demanded 30 bitcoin in ransom, but Mayor Kai Wegner insists the city will not yield to extortion as law enforcement investigates the leak of 5.79 terabytes of data.

**Type:** article · **Category:** Europe · **Published:** 2026-08-28 · **Source:** TrendKia
**Canonical:** https://trendkia.com/en/europe/berlin-ke-sarakari-sistama-men-sendha-lagakara-haikarsa-ne-mangi-karoron-ki-rngadari-meyara-kai-wegner-ne-blaikamela-hone-se-kiya--23917 · **Language:** English
**Tags:** Berlin, Cyberattack, Hackers, Kai Wegner, Ransomware, Rhysida, Germany

The municipal government of Berlin has been targeted in a major cyberattack that resulted in the theft of massive volumes of administrative data, leading to a high-stakes extortion attempt by illegal hackers. Mayor Kai Wegner publicly announced that the German capital would strictly refuse to bow to any ransom demands issued by the perpetrators. The extortion attempt was formally delivered on Thursday evening, triggering an emergency response across municipal IT operations and law enforcement channels. Reports indicate that the cybercriminals responsible are demanding a sum of 30 bitcoin, which translates to approximately €2 million or £1.7 million, to prevent the unauthorized release and auction of the stolen records.

## Critical Municipal Network Disruptions and Forensic Findings
The cyber intrusion began unfolding earlier in August when unauthorized actors gained access to municipal servers. Official disclosures from the city-state administration confirm that an initial data breach took place between August 7 and August 12. As security teams detected suspicious activities, administrative authorities took immediate preventative measures on August 14 by shutting down network operations across two key city departments. This operational suspension halted crucial public digital tools, rendering local residents temporarily unable to submit applications for housing benefits or process government payments for several consecutive days.

Subsequent forensic investigations conducted by cybersecurity specialists uncovered further evidence of unauthorized data exfiltration targeting Berlin transport and environment department. In an official communication released on Friday, the mayor office stated that personal or other non-public records could potentially be exposed as a result of the compromise. Technical crews and investigators are currently working under intense pressure to ascertain the precise extent of the breach, evaluate the sensitivity of the compromised files, and restore full functionality to all impacted municipal digital infrastructure safely.

## Ransom Demands and Dark Web Data Auction Threats
Following the breach, the extortionists escalated their tactics by establishing a countdown timer on a dark web platform, signaling their intent to monetize the stolen files if their ransom demands are ignored. According to details emerging from dark web monitoring and media reports, the hackers claim to have successfully stolen 5.79 terabytes of data from Berlin government servers. The group announced that if the 30 bitcoin ransom is not paid within a seven-day window, they will initiate a public online auction to sell off the confidential cache to the highest bidder.

Screenshots of the group dark web posting reveal an extensive catalog of compromised internal documents. Among the stolen contents are official municipal contracts, non-disclosure agreements, sensitive internal personnel files, administrative login credentials and passwords, alongside thousands of private contact entries belonging to government staff and associated entities. The dark web portal explicitly lists the starting bid for the data auction at 30 bitcoin, identical to the ransom total demanded directly from the city administration.

## The Rhysida Cybercrime Syndicate Profile
Although municipal authorities have not formally named the syndicate in official legal proceedings, evidence points toward the notorious ransomware gang known as Rhysida. Cybersecurity researchers believe the group operates predominantly out of Russia and Eastern Europe. Since its emergence in 2023, Rhysida has established a track record of high-profile cyber extortion campaigns targeting public institutions, healthcare organizations, and commercial enterprises of varying sizes across numerous international jurisdictions.

The syndicate gained widespread notoriety in 2023 following a severe cyberattack on the British Museum. During that incident, Rhysida operators infiltrated the institution internal IT networks, causing widespread operational disruption and exfiltrating approximately 500,000 sensitive internal files. Their operational methodology typically involves encrypting target systems, exfiltrating critical databases, and threatening public exposure or commercial auction if extortion demands are not met promptly.

## Law Enforcement Investigation and Upcoming Election Security
In response to the unprecedented municipal breach, Mayor Kai Wegner reaffirmed that Berlin leadership maintains a firm stance against paying ransoms to digital extortionists. State police forces, public prosecutors, and federal security agencies have launched a coordinated criminal investigation aimed at identifying and prosecuting the perpetrators with the utmost urgency. Law enforcement personnel and forensic experts are analyzing server logs and network traffic to trace the digital signatures of the intruders.

The cyberattack has generated heightened scrutiny as Berlin approaches municipal elections scheduled to take place in roughly a month. Addressing potential concerns regarding electoral integrity, State Senator Iris Spranger provided public assurances that the city election infrastructure operates on separate, secured systems and has not been compromised by the security breach. Authorities continue to monitor all municipal digital perimeters closely to prevent further unauthorized access while working to fortify systemic vulnerabilities across all administrative networks.

## What this means for you
The cyberattack on Berlin municipal networks directly impacts citizen data privacy and temporarily disrupts digital public service delivery.

- **In Berlin and Germany:** Local residents face temporary service outages for housing benefit processing and public payments. Affected government employees and citizens face potential exposure of sensitive personal information.
- **Across India and Globally:** The breach highlights how public sector infrastructure remains vulnerable to organized ransomware groups. Organizations worldwide must audit and strengthen their perimeter defenses.
- **Data Privacy Risks:** The compromise of administrative login credentials and personal files underlines the necessity of strict access controls and multi-factor authentication.
- **Ransomware Response Strategy:** Refusing extortion sets a strong precedent against cybercrime, though it increases the short term risk of unauthorized data leaks on dark web markets.

## Questions & Answers

### 1. What happened in the Berlin cyberattack?
Hackers breached Berlin municipal government networks, stole 5.79 terabytes of data, and demanded a cryptocurrency ransom.

### 2. How much ransom are the cybercriminals demanding?
The attackers demanded 30 bitcoin, which is valued at approximately €2 million or £1.7 million.

### 3. What is the official response from Berlin Mayor Kai Wegner?
Mayor Kai Wegner stated firmly that Berlin will not be blackmailed and will refuse to pay any ransom demands.

### 4. Which hacker group is suspected of carrying out the attack?
The attack is attributed to the Rhysida ransomware gang, which is believed to operate from Russia and Eastern Europe.

### 5. Has the upcoming Berlin election infrastructure been compromised?
No, State Senator Iris Spranger confirmed that election infrastructure operates on separate systems and remains secure.

---
_TrendKia — Har trend, sabse pehle.. Machine-readable view; canonical HTML at the URL above._