Berlin Confirms Extortion Attempt After Administrative Network Attack, Data Leak Scope Under Investigation

Following a cyber incident in the state administrative network, Berlin confirmed an extortion attempt. The city will not comply with the demands, while the investigation has uncovered another data leak.

Berlin confirmed an extortion attempt following a cyberattack on the city’s administrative network. On August 28, the state Senate said it would not comply with the extortionists’ demands. The incident is being investigated by the state criminal police, the public prosecutor’s office and federal security authorities.

Forensic examination also uncovered another data leak involving the Senatsverwaltung für Mobilität, Verkehr, Klimaschutz und Umwelt, or the authority for mobility, transport, climate protection and the environment. Authorities are not yet able to determine the scope or contents of the leaked data. They do not rule out that personal or other non-public information may be among it.

Berlin Confirms Extortion Attempt and Refuses to Pay

The Senate announced that it would not meet the ransom demand. However, it has not publicly confirmed the amount requested, the attackers’ identities or the specific volume of stolen data.

Authorities affected by the incident disconnected from the state network as early as August 14. The forensic investigation, network scanning and work by the ICT crisis team are continuing.

Another Data Leak Is Still Under Investigation

Berlin officially confirmed another data leak from the aforementioned Senate authority, but did not state which records were affected or how many people the incident may concern. The scope and contents of the data are not yet known.

Personal or other non-public information may therefore potentially be at risk, but the exact impact remains under investigation.

Attackers and Method of Intrusion Not Confirmed

Media outlets and services tracking data leaks have linked the incident to the Rhysida group. Berlin, however, has not officially confirmed this attribution. The attackers’ claims about the amount of stolen data or the number of potentially affected people have likewise not been independently verified.

The method of the initial network intrusion is also not publicly known. Authorities have not confirmed a specific exploited vulnerability, compromised account or other entry point.

What Happens Next

The results of the forensic investigation will be crucial: the scope and nature of the leaked data, any notifications to affected individuals and findings concerning the intrusion vector. Confirmation or rejection of the reported connection to the Rhysida group will also be important.

Berlin’s case is a confirmed incident in public administration involving a data leak followed by an extortion attempt. The exact impact on systems, services and individuals whose data may have been affected remains under investigation.

Sources

Verified and updated: 08/30/2026 13:28

Sharing