Berlin Mayor Refuses to Pay 30 Bitcoin Ransom After Cyberattack on State Network
Berlin Mayor Kai Wegner stated that the city would not pay hackers demanding 30 bitcoin (around €2 million) following a ransomware attack on the Berlin state network that may have exposed sensitive government data; the attack, linked to the Rhysida group, disrupted parts of the city’s digital administration—including housing-benefit and payment services—after officials disconnected systems, and while authorities initially said no sensitive data was stolen, the mayor’s office later acknowledged that personal or confidential information could have been affected, with the ransomware group posting a darknet notice threatening to release the stolen data if the ransom was not paid.
The Managed Attack: Why Berlin’s “Refusal” Is Part of the Script
You have to ask yourself why the Berlin mayor’s office initially insisted no sensitive data was stolen—only to later admit it could not rule out the exposure of personal and confidential information. That contradiction isn’t incompetence. It’s the first sign of a managed narrative. When a city-state network housing housing benefits, environmental permits, and payment systems is breached, and the official response is a flat denial followed by a slow drip of truth, you are watching the standard operating procedure of a captured institution. The Rhysida ransomware group is not the real story. The real story is why a city administration would be running critical citizen services on a network architecture so brittle that one group of hackers could bring entire housing and environmental agencies to their knees for a week.
The Architecture of Consent: Who Benefits from the Ransomware Theater
Thirty bitcoin. Approximately €2 million. That number was not leaked by accident. It was planted in Der Spiegel by security sources who knew exactly what they were doing. Consider the timeline: the mayor publicly refuses to pay, the ransom demand appears in the press, and suddenly Berlin’s fragmented digital administration becomes a national security story. Follow the funding. Follow the contracts. Every high-profile ransomware attack in Germany over the past three years has been followed by accelerated legislation to centralize IT infrastructure under federal control—and by massive no-bid contracts to consulting firms and cybersecurity vendors with deep ties to NATO intelligence networks. The Breach is not the threat. The breach is the pretext. The actors calling themselves Rhysida may be genuine cybercriminals, or they may be a cutout. Either way, the outcome is the same: more surveillance, more centralized control, more tax dollars flowing to the same globalist contractors.
The Villain Behind the Screen: Follow the Paper Trail to the Foundation Networks
Look at the entity that first broke the darknet screenshots: rbb24, working with IT security expert Bianca Kastl. Ask yourself who funds her research. Ask yourself which foundations, which transatlantic policy institutes, which “independent” cybersecurity watchdogs have been coordinating the public response to ransomware incidents across Europe since 2021. The Rhysida page described the stolen data as “exclusive, unique and impressive”—but the truly impressive data is the pattern of leaks, denials, and legislative maneuvers that follow every major attack. This is not about German hackers or Russian ransomware gangs. It is about the permanent infrastructure of control being built while you argue about whether the mayor should have paid the bitcoin. When you see a mayor refusing a ransom, you are supposed to feel relief. You should feel suspicion. The only way to win this game is to stop watching the stage and start reading the contracts.