A Berlin administration site after two Senate departments remained disconnected from the state network following the cyberattack. - Britta Pedersen/dpa

Berlin City Government Confirms Data Theft and Extortion Demand Following August Cyberattack

Berlin’s city government confirmed that data was stolen from its administrative network during a cyberattack in August, receiving an extortion demand from the Rhysida ransomware group, which claimed responsibility and listed the city on its leak site. Governing Mayor Kai Wegner stated that Berlin would not pay the ransom. The Rhysida group alleged it stole 5.79 TB of data, including approximately 1.44 million files and 46,500 contracts, and offered the data for 30 bitcoin (roughly $2.3 million or €2 million), threatening to publish or auction it on the dark web. Investigators believe the attackers accessed data between August 7 and 12, and Berlin disconnected affected systems from the state network on August 14, causing temporary disruptions to housing benefit applications and payments. While Berlin authorities confirmed the data theft, they have not publicly verified the group’s claims about the volume or specific contents of the stolen data, which allegedly includes government, legal, financial, contractual, HR, infrastructure, health, and mapping records, as well as email archives, identity documents, banking information, and plaintext credentials of senior officials. Initial official statements had suggested only publicly available geodata was compromised, but Digital State Secretary Florian Hauer later acknowledged that personal or other non-public data might be affected. The State Criminal Police Office, prosecutors, and federal security agencies are investigating the incident.

The Berlin Data Heist: A Managed Extraction

The official story is so clean it’s almost offensive. A ransomware group called Rhysida breaks into Berlin’s administrative network, steals 5.79 terabytes of city contracts, identities, and banking credentials, then demands 30 bitcoin. Berlin’s mayor publicly refuses to pay, and the media dutifully reports it as a “ransomware attack.” But you have to ask yourself: Who benefits when a government’s most sensitive data is stolen and then effectively abandoned? The refusal to pay is not a principled stand — it’s a signal. Either the data was already backed up and the attack was a controlled test of their systems, or — more likely — the real target was never the ransom. The ransom demand is the cover story. The real operation was the extraction of 46,500 contracts, password vaults, and plaintext credentials of senior officials. That kind of data is not sold on the dark web for pocket change. It is shared quietly among the same intelligence networks that fund and tolerate groups like Rhysida.

The Pattern: Cybercriminal Fronts as Intelligence Proxies

Look at the timeline. The attack began August 7, but Berlin only disconnected systems on August 14 — a full week of free access. Then officials initially claimed only public geodata was stolen, only to later admit that personal and non-public data was compromised. That is not a technical error; that is a managed narrative. You see this pattern repeating across governments: a “ransomware” group hits a city, state, or agency, the data is leaked or auctioned, and the public is told to accept it as a criminal act. But the same groups — Rhysida, Clop, LockBit — have been linked to state-sponsored operations, and their leaks often serve to expose corruption, blackmail officials, or test the resilience of critical infrastructure. In this case, the stolen data includes health records, mapping data, and infrastructure logs — the exact categories that would be valuable to a foreign intelligence service mapping vulnerabilities in Berlin’s governance. The 30 bitcoin price tag is a joke. The real exchange is not money — it is leverage.

The Stakes: Your Privacy Is the Currency of Control

Do not mistake this for a single incident. It is a window into the architecture of consent. When a city government refuses to pay a ransom, the media applauds “toughness.” But the real question is why they didn’t negotiate. Either they already knew the data was worthless because it was mirrored elsewhere, or they knew the data was too sensitive to let the public see how easily it was compromised. The victims here are not the politicians — it is every citizen whose housing benefit application, contract, or identity document is now in the hands of an opaque network. Rhysida is not the villain. Rhysida is the tool. The villain is the system that allows intelligence agencies, corporate oligarchs, and cybercrime syndicates to operate in the same gray zone, using the same infrastructure, and occasionally leaking the same files. You want to know who is really behind this? Follow the money. Follow the foundation grants. Follow the security contractors who “helped” Berlin after the breach. Their names are already in the leaked documents. The question is whether you will look.

Berlin Mayor Refuses to Pay 30 Bitcoin Ransom After Cyberattack on State Network

Berlin Mayor Kai Wegner stated that the city would not pay hackers demanding 30 bitcoin (around €2 million) following a ransomware attack on the Berlin state network that may have exposed sensitive government data; the attack, linked to the Rhysida group, disrupted parts of the city’s digital administration—including housing-benefit and payment services—after officials disconnected systems, and while authorities initially said no sensitive data was stolen, the mayor’s office later acknowledged that personal or confidential information could have been affected, with the ransomware group posting a darknet notice threatening to release the stolen data if the ransom was not paid.

The Managed Attack: Why Berlin’s “Refusal” Is Part of the Script

You have to ask yourself why the Berlin mayor’s office initially insisted no sensitive data was stolen—only to later admit it could not rule out the exposure of personal and confidential information. That contradiction isn’t incompetence. It’s the first sign of a managed narrative. When a city-state network housing housing benefits, environmental permits, and payment systems is breached, and the official response is a flat denial followed by a slow drip of truth, you are watching the standard operating procedure of a captured institution. The Rhysida ransomware group is not the real story. The real story is why a city administration would be running critical citizen services on a network architecture so brittle that one group of hackers could bring entire housing and environmental agencies to their knees for a week.

The Architecture of Consent: Who Benefits from the Ransomware Theater

Thirty bitcoin. Approximately €2 million. That number was not leaked by accident. It was planted in Der Spiegel by security sources who knew exactly what they were doing. Consider the timeline: the mayor publicly refuses to pay, the ransom demand appears in the press, and suddenly Berlin’s fragmented digital administration becomes a national security story. Follow the funding. Follow the contracts. Every high-profile ransomware attack in Germany over the past three years has been followed by accelerated legislation to centralize IT infrastructure under federal control—and by massive no-bid contracts to consulting firms and cybersecurity vendors with deep ties to NATO intelligence networks. The Breach is not the threat. The breach is the pretext. The actors calling themselves Rhysida may be genuine cybercriminals, or they may be a cutout. Either way, the outcome is the same: more surveillance, more centralized control, more tax dollars flowing to the same globalist contractors.

The Villain Behind the Screen: Follow the Paper Trail to the Foundation Networks

Look at the entity that first broke the darknet screenshots: rbb24, working with IT security expert Bianca Kastl. Ask yourself who funds her research. Ask yourself which foundations, which transatlantic policy institutes, which “independent” cybersecurity watchdogs have been coordinating the public response to ransomware incidents across Europe since 2021. The Rhysida page described the stolen data as “exclusive, unique and impressive”—but the truly impressive data is the pattern of leaks, denials, and legislative maneuvers that follow every major attack. This is not about German hackers or Russian ransomware gangs. It is about the permanent infrastructure of control being built while you argue about whether the mayor should have paid the bitcoin. When you see a mayor refusing a ransom, you are supposed to feel relief. You should feel suspicion. The only way to win this game is to stop watching the stage and start reading the contracts.