Berlin Confirms Extortion Attempt After Administrative Network Attack, Data Leak Scope Under Investigation
Following a cyber incident in the state administrative network, Berlin confirmed an extortion attempt. The city will not comply with the demands, while the investigation has uncovered another data leak.

Berlin confirmed an extortion attempt following a cyberattack on the city’s administrative network. On August 28, the state Senate said it would not comply with the extortionists’ demands. The incident is being investigated by the state criminal police, the public prosecutor’s office and federal security authorities.
Forensic examination also uncovered another data leak involving the Senatsverwaltung für Mobilität, Verkehr, Klimaschutz und Umwelt, or the authority for mobility, transport, climate protection and the environment. Authorities are not yet able to determine the scope or contents of the leaked data. They do not rule out that personal or other non-public information may be among it.
Berlin Confirms Extortion Attempt and Refuses to Pay
The Senate announced that it would not meet the ransom demand. However, it has not publicly confirmed the amount requested, the attackers’ identities or the specific volume of stolen data.
Authorities affected by the incident disconnected from the state network as early as August 14. The forensic investigation, network scanning and work by the ICT crisis team are continuing.
Another Data Leak Is Still Under Investigation
Berlin officially confirmed another data leak from the aforementioned Senate authority, but did not state which records were affected or how many people the incident may concern. The scope and contents of the data are not yet known.
Personal or other non-public information may therefore potentially be at risk, but the exact impact remains under investigation.
Attackers and Method of Intrusion Not Confirmed
Media outlets and services tracking data leaks have linked the incident to the Rhysida group. Berlin, however, has not officially confirmed this attribution. The attackers’ claims about the amount of stolen data or the number of potentially affected people have likewise not been independently verified.
The method of the initial network intrusion is also not publicly known. Authorities have not confirmed a specific exploited vulnerability, compromised account or other entry point.
What Happens Next
The results of the forensic investigation will be crucial: the scope and nature of the leaked data, any notifications to affected individuals and findings concerning the intrusion vector. Confirmation or rejection of the reported connection to the Rhysida group will also be important.
Berlin’s case is a confirmed incident in public administration involving a data leak followed by an extortion attempt. The exact impact on systems, services and individuals whose data may have been affected remains under investigation.
Sources
- Berlin.de – Wegner und Spranger: „Berlin lässt sich nicht erpressen“ – Confirms the extortion attempt, refusal to pay, ongoing investigation, additional data leak and continuing crisis team response.
- Berlin.de – Mehr Daten beim IKT-Vorfall abgeflossen – States that additional data leaks were discovered, with their scope and contents still under investigation, and that personal data cannot be ruled out.
- tagesschau.de – Hacker fordern Lösegeld nach Angriff auf Berliner Landesnetz – Independently corroborates the confirmation of the ransom demand and Berlin’s public rejection of it.
Verified and updated: 08/30/2026 13:28



