Berlin's state government has confirmed that hackers linked to the Rhysida ransomware group stole 5.79 terabytes of data from state agency networks, then demanded 30 bitcoin to prevent its release. City officials refused to pay, a decision that came just weeks before Berlin's state election. The data has reportedly since been put up for auction on Rhysida's leak site, raising fresh questions about what happens to citizens' information once a government says no to extortion.
What Happened in the Berlin Ransomware Attack
According to reporting on the incident, attackers associated with Rhysida breached at least two Berlin state agencies and exfiltrated 5.79TB of data before demanding payment. Berlin's government publicly stated it would not negotiate with the hackers, a stance that held even as the timeline moved from private threat to public auction listing. This isn't the first time Berlin has faced this exact standoff. City officials had already refused the ransomware demand once extortion was confirmed, and the government's refusal to pay reportedly came before Rhysida's auction even opened, a sequence that differs from how most ransomware cases typically unfold, where public acknowledgment usually follows the leak site listing rather than preceding it.
The timing has drawn particular attention because the breach and the state election were separated by only a few weeks. Ransomware groups sometimes time or amplify their disclosures around politically sensitive moments, knowing that public institutions face added pressure to either pay quietly or manage the fallout in the public eye. Berlin's decision to hold firm, even under that pressure, is consistent with the position it took when it refused the 30 bitcoin ransom after the theft was first disclosed.
Why Refusing to Pay Doesn't Undo the Privacy Damage
Refusing to pay a ransom is generally the right call from a policy standpoint. Paying criminal groups funds further attacks, offers no guarantee that stolen data is actually deleted, and can mark an organization as a repeat target. But the decision not to pay doesn't reverse what already happened: the data left the network, and once it's in Rhysida's hands, it's effectively out of Berlin's control.
With 5.79TB reportedly stolen from state agencies, the scope of what's exposed likely includes internal government records, and depending on which agencies were affected, potentially personal information tied to residents who interact with those state systems. Ransomware groups that run leak site auctions often use the threat of exposure as leverage first, then follow through with partial or full releases when demands aren't met. For anyone whose data may have passed through Berlin's state agency networks, the practical risk isn't the ransom negotiation itself, it's whatever ends up published or sold as a result of it.
The Broader Pattern in Government Ransomware Incidents
Berlin's case fits a pattern that's become familiar across public sector breaches: attackers steal data, threaten publication, and governments increasingly choose public refusal over quiet settlement. That shift reflects both stronger no-negotiation policies among public institutions and a recognition that payment rarely resolves the underlying exposure. Still, each new incident underscores a persistent gap between what governments can promise (institutional integrity, no funding of criminal groups) and what they can actually guarantee to affected residents (that stolen personal data won't circulate).
What This Means For You
If you live in Berlin or have interacted with the affected state agencies, treat this as a reason to be more cautious rather than a reason to panic. Ransomware leaks involving government data can include identifying information such as names, addresses, or records tied to public services, even when the primary target was internal administrative systems rather than a citizen-facing database.
Practical steps worth taking:
- Watch official Berlin state communications for confirmation of exactly which data categories were affected, rather than relying on secondhand summaries.
- Be alert to phishing attempts that reference the breach, since leaked government data is sometimes used to make follow-up scams look more credible.
- Consider monitoring for unusual account activity if you've used services tied to the named agencies, particularly in the weeks following a leak site auction.
- Avoid assuming that a refusal to pay means the situation is resolved. The data's exposure risk continues independent of the ransom decision.
The Bottom Line
Berlin's refusal to pay Rhysida's 30 bitcoin demand is a defensible institutional stance, but it doesn't change the fact that 5.79TB of state data was stolen and may now be circulating publicly. For residents, the real takeaway isn't about the ransom negotiation itself. It's about staying alert to how leaked government data can resurface in scams or identity theft attempts long after the headlines fade. As this Berlin ransomware attack continues to develop, keeping an eye on official updates remains the most reliable way to know if your own information was part of what Rhysida took.




