A City Government Says No to Extortion
Berlin's government has confirmed that attackers stole data from its state network and that it will not pay the ransom demanded to keep that data private. The ransomware group behind the attack, known as Rhysida, claims it exfiltrated 5.79 terabytes of information before the city could respond. Officials have acknowledged the theft but have not verified the full contents or scope of what Rhysida says it took.
This distinction matters. A ransomware group's claim about the size and sensitivity of stolen data is not the same as an independently confirmed inventory. Ransomware crews routinely inflate figures to pressure victims into paying and to generate media attention that increases leverage. Until Berlin or independent investigators publish a verified accounting, the 5.79TB figure should be treated as an unconfirmed claim from the attackers themselves, not an established fact about the breach's true scope.
Why Refusing to Pay Is the Harder, Smarter Path
Paris, London, and now Berlin have all faced a similar calculus in recent years: pay criminals to (maybe) delete stolen data, or refuse and accept the risk that private information ends up published or auctioned online. Berlin chose the latter. Refusing payment denies the attackers a direct financial reward and avoids funding further criminal operations, but it does not undo the theft itself. If Rhysida's claims hold up even partially, residents, employees, or businesses connected to Berlin's state systems could still see their information exposed regardless of the city's decision not to pay.
Government ransomware incidents are rarely isolated criminal events anymore. Cyberattacks against German public institutions have grown more complex, and it's worth noting that state-linked actors, not just financially motivated criminal gangs, are playing a larger role in the country's threat landscape. According to reporting on foreign spies now driving over a third of Germany's cyberattacks, the line between opportunistic ransomware crews and state-backed intrusions has blurred considerably. That context is useful here: even when a ransomware gang like Rhysida claims sole responsibility, the broader environment in which German public infrastructure operates is one where attribution and motive are increasingly murky.
The Trouble With Unverified Ransomware Claims
One of the most consistent challenges in ransomware reporting is separating verified facts from marketing designed to scare victims into paying. Rhysida's public claim of 5.79TB is exactly the kind of number that spreads quickly online because it sounds precise and alarming, even though the group's own dark web postings are not subject to any independent audit. Berlin's confirmation covers two things only: that data was stolen, and that the city refused the ransom demand. It does not confirm the volume, the categories of data involved, or whether residents' personal information is among what was taken.
This pattern repeats across nearly every major ransomware incident. Attackers announce a headline figure to maximize pressure, victims confirm a breach occurred without validating specifics, and the true scope often takes weeks or months to emerge through forensic investigation, if it emerges publicly at all.
What This Means For You
If you live in Berlin, work for a city agency, or interact with municipal services that rely on the affected state network, this incident is worth monitoring even though nothing is fully confirmed yet. Ransomware groups that steal government data often target records tied to employment, permits, tax filings, or municipal services, information that can be used for identity theft or targeted phishing if it surfaces online.
The practical response for residents is the same regardless of how much data Rhysida actually has: assume some exposure is possible and take basic precautions. Watch for unusual communications claiming to be from city agencies, avoid clicking links in unsolicited emails referencing municipal services, and monitor financial and identity accounts for unfamiliar activity in the coming months.
Takeaways for Staying Ahead of This Story
This Berlin ransomware data theft case is still developing, and the gap between Rhysida's claims and verified reality is likely to narrow only gradually. In the meantime:
- Treat the 5.79TB figure as an attacker's claim, not a confirmed fact, until independent verification emerges.
- If you have any connection to Berlin's city government services, monitor official communications for updates on what data may have been affected.
- Be alert to phishing attempts that may exploit public awareness of this breach, especially messages posing as city officials or agencies.
- Follow credible reporting rather than dark web postings for updates, since ransomware groups have a direct incentive to exaggerate.
Berlin's refusal to pay sends a clear signal that the city is not willing to reward extortion, but it does not close the book on this incident. Residents and observers alike should expect more clarity, and possibly more revelations, in the weeks ahead.




