Berlin Declines Ransom Payment After Data Breach of State Network

Following a significant data breach, Berlin's state government has confirmed it will not pay the hackers behind the attack, which compromised the city's administrative network.

Berlin’s state government has publicly stated that it will not comply with the ransom demands of hackers who breached the city’s administrative network in August 2026. This decision comes after forensic investigations revealed that sensitive data may have been exfiltrated from the network.

Details of the Breach

The breach occurred between August 7 and August 12, 2026, with the Senate Department for Mobility, Transport, Climate Protection and Environment reporting the initial data outflow on August 7. The network was subsequently isolated on August 14. The exact scope of the data taken is still under investigation, but officials have indicated that personal or non-public data could be involved.

Extent of Data Compromised

While the Berlin government has not disclosed the volume of data that was compromised, a post on a leak site claims that approximately 5.79 terabytes of data, including personal information of 12,076 individuals, were stolen. The attackers have categorized this data into eleven different types, with a significant portion consisting of maps and geodata files.

Investigation and Attribution

The investigation into the breach involves the state criminal police, the public prosecutor, and federal security authorities. As of now, no specific group has been officially identified as responsible for the attack. However, reports from Der Spiegel have linked the incident to a group named Rhysida, which has been associated with similar attacks in the past.

Security Recommendations and Future Steps

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have previously issued advisories regarding Rhysida’s tactics, including exploiting valid accounts on external-facing services and utilizing known vulnerabilities such as Zerologon (CVE-2020-1472). They recommend organizations prioritize remediation of known vulnerabilities and implement multi-factor authentication to enhance security. The Berlin government has stated that it is keeping its data protection commissioner and the Federal Office for Information Security informed about the ongoing situation.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 366