Berlin authorities have refused to meet an alleged 30 Bitcoin ransom demand after a cyberattack hit two state agencies, while officials have yet to confirm the amount of data claimed to have been stolen.
Summary
- Hackers reportedly demanded 30 Bitcoin, worth roughly €2 million, after a cyberattack affected two Berlin state agencies.
- The attackers threatened to publish stolen information, while Berlin officials have refused to pay and have not confirmed the reported ransom amount.
- Berlin initially said only public information was compromised but later acknowledged that non-public data had been affected.
- Rhysida reportedly claimed responsibility for the attack and said it obtained sensitive files, though Berlin authorities have not verified the full extent of the alleged theft.
The Berlin Senate Chancellery said it would not disclose details about the attackers, their demands or the information potentially taken from government systems while the investigation remains active. A Senate spokesperson told German news agency dpa that officials could not comment “for investigative reasons” at this stage.
The position leaves several details of the attack unconfirmed by the state government, including reports that the ransomware group Rhysida obtained sensitive files and threatened to publish them unless Berlin paid roughly 2 million euros in Bitcoin.
Berlin has refused the reported 30 Bitcoin demand
Berlin Mayor Kai Wegner confirmed after a special Senate meeting on Friday that the state was facing an extortion attempt following the cyberattack.
“The state of Berlin will not allow itself to be blackmailed,” Wegner said.
He did not publicly identify the attackers or disclose the amount demanded. Interior Senator Iris Spranger joined Wegner in briefing the public following the meeting, while authorities continued examining what information had left government systems.
German magazine Der Spiegel reported that Rhysida was behind the attack, citing information posted by the ransomware group on its dark web leak site. Security sources cited by the publication reportedly identified Rhysida as the group responsible for the extortion attempt.
The attackers demanded 30 BTC and threatened to release the information if Berlin did not pay, according to the report. At current prices, the demand was worth roughly 2 million euros.
Rhysida reportedly claimed to have taken almost six terabytes of data. The alleged files include information from tens of thousands of administrative offense proceedings, contracts, passwords, login credentials, emergency plans and documents related to critical infrastructure.
Berlin authorities have not independently confirmed the amount of data claimed by the group or the full list of compromised records.
The distinction has become important to the official account of the incident because the government’s assessment changed after the attack was discovered. Officials initially said only publicly accessible information had been taken before the Senate Chancellery acknowledged last Wednesday that non-public data was affected.
Cyberattack forced two Berlin agencies off the state network
The attack became public on Aug. 14 and affected Berlin’s Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Climate Protection and the Environment.
Both agencies were temporarily disconnected from Berlin’s state network as officials worked to contain the incident.
The separation lasted for about a week and disrupted some administrative services. German reports said residents were temporarily unable to apply for or receive housing benefits while the affected systems remained isolated.
Investigators are still determining when the intrusion began and how much information left the network. Reports citing the investigation said data may have been extracted between Aug. 7 and Aug. 12, several days before officials detected the attack.
The Berlin State Criminal Police Office and prosecutors are investigating the breach. Wegner said state and federal security authorities were working to identify the perpetrators while officials continued checking which files had been accessed or removed.
Spranger said the attack had not compromised preparations for Berlin’s Sept. 20 state election, describing the election infrastructure as fully secured.
The ransomware case follows another government cyberattack involving a Bitcoin demand reported by crypto.news in July. Hackers took control of Kenyan President William Ruto’s official website and demanded 5 BTC while threatening to disclose unspecified information.
Kenyan authorities temporarily restricted access to the website and opened an investigation. The country’s ICT Authority said at the time that investigators had found no evidence that sensitive information had been accessed, stolen or lost.
Rhysida has operated as a ransomware group since 2023
Rhysida emerged in 2023 and has been linked to attacks against government bodies, healthcare organizations and other institutions in several countries.
The group has previously targeted organizations including the British Library and the Chilean Army. Its operations generally combine network intrusion with demands for payment, while the threat of publishing stolen information can be used to pressure victims.
Bitcoin and other cryptocurrencies have repeatedly featured in ransomware cases because attackers can direct payments to blockchain addresses without using conventional bank accounts.
Public blockchain transactions can still be followed. A crypto.news report on blockchain forensics detailed how investigators can trace cryptocurrency movements between addresses and use transaction patterns and other information to connect funds with services or individuals.
Law enforcement agencies have recovered cryptocurrency from ransomware operations in previous cases. In August 2025, U.S. authorities seized $1.09 million in cryptocurrency linked to the BlackSuit ransomware group alongside four servers and nine domains.
BlackSuit had been linked to more than 450 known U.S. victims and over $370 million in ransom demands since 2022. One victim paid 49.3 BTC in 2023 after an attack, with investigators later recovering part of the payment, according to the Justice Department.
A separate U.S. case in July involved a suspected member of the Scattered Spider hacking group. Federal prosecutors charged 19-year-old Peter Stokes over an alleged corporate intrusion and an unsuccessful $8 million cryptocurrency ransom demand.
Berlin has not confirmed Rhysida’s data claims
Berlin’s investigation remains focused on establishing the extent of the breach while the government withholds details that officials say could affect the inquiry.
Rhysida’s claims about the stolen material originate from the group’s dark web communications and have not been fully verified by the Berlin government. Officials have confirmed that non-public information was affected, reversing the initial assessment that the compromised material was limited to publicly accessible data.
The Senate Chancellery has not disclosed whether investigators have verified the reported 30 BTC demand, the nearly six terabytes allegedly taken or the individual categories of information Rhysida claims to possess.
Wegner said authorities at the state and federal levels were working to identify the group responsible, while the Berlin State Criminal Police Office and prosecutors continued their investigation into the attack.






