Berlin probes ransomware attack as hackers demand 30 BTC
Berlin officials have publicly refused to pay a reported 30 Bitcoin ransom following a cyberattack that targeted two state agencies, escalating concerns about ransomware, data breach risks and the role of cryptocurrency in extortion schemes. Authorities say the investigation into the incident is ongoing, and several key details about the scope of the compromise remain unverified.
What happened: agencies disconnected, investigation launched
The intrusion became public on Aug. 14, when Berlin’s Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Climate Protection and the Environment were taken offline from the state network. Officials isolated the affected systems for roughly a week to contain the incident and to carry out forensic analysis.
Services disruption followed: residents temporarily could not apply for or receive housing benefits through the impacted systems while investigators worked to assess the damage and restore secure access. State and federal cybersecurity teams — including the Berlin State Criminal Police Office and public prosecutors — have been involved in the probe.
Ransom claim and the alleged data haul
Security reports and media coverage say the ransomware syndicate known as Rhysida claimed responsibility and posted evidence on a leak site, asserting it had extracted almost six terabytes of data. The attackers allegedly demanded 30 BTC — roughly €2 million at the time of reporting — and threatened to publish sensitive material if Berlin refused to pay.

Rhysida’s alleged haul reportedly includes administrative offense records, contracts, passwords, login credentials, emergency plans and documents tied to critical infrastructure. Berlin authorities have acknowledged that non-public information was affected, reversing an earlier statement that only public data had been exposed. However, the state government has not independently verified the full list or volume of files the group claims to hold.
Officials stand firm: no payout
Berlin Mayor Kai Wegner, addressing the matter after a special Senate meeting, said the state would not be blackmailed. Interior Senator Iris Spranger joined the briefing, emphasizing that investigators could not disclose operational details for investigative reasons. The Senate Chancellery declined to confirm the ransom sum, the identity of the attackers or the precise categories of data allegedly taken while the investigation remains active.
Authorities are working with federal cybersecurity partners to identify the perpetrators, reconstruct the attack timeline and determine exactly which files were accessed or stolen. Preliminary reporting suggests data may have been exfiltrated between Aug. 7 and Aug. 12, days before detection.
Election infrastructure and public safety
Officials have said the incident did not compromise preparations for Berlin’s Sept. 20 state election, asserting that election systems were secured. Public-safety planners and critical infrastructure operatives are particularly sensitive to ransomware threats because leaks or sabotage can have outsized social consequences.
Why cryptocurrency is central to ransomware
Bitcoin and other cryptocurrencies remain the preferred payment method for many ransomware operators because blockchain addresses let attackers request funds without traditional bank accounts. While cryptocurrencies offer pseudo-anonymity, public blockchains are traceable: forensic analysts can follow transaction flows, identify exchange on-ramps and sometimes link addresses to services or individuals.
Law enforcement has recovered cryptocurrency in prior ransomware cases. Notably, U.S. authorities seized $1.09 million in crypto linked to the BlackSuit group in August 2025. That operation traced payments and infrastructure and recovered assets after longer investigations. Blockchain forensics — combined with subpoenas to exchanges and cooperation from crypto custodians — has become a core investigative tool against extortion groups.
Ransomware groups and patterns: Rhysida and peers
Rhysida emerged in 2023 and has been implicated in attacks on public institutions, healthcare providers and cultural organizations. The group has been associated with operations that combine network intrusion, data exfiltration and double-extortion tactics — demanding ransom payment while threatening to publish stolen files.
Other well-known groups, such as BlackSuit and Scattered Spider, have also relied on cryptocurrency for ransoms and have been the focus of international law enforcement efforts. In a separate case, U.S. prosecutors charged a suspect tied to a Scattered Spider campaign that sought an $8 million crypto ransom. These episodes illustrate recurring infection vectors like phishing, credential theft, and social engineering directed at corporate help desks.
Investigative challenges and next steps
Berlin’s public statements emphasize the investigative sensitivity of ongoing work. The Senate Chancellery insisted it would withhold specifics to avoid jeopardizing efforts to identify the attackers and recover evidence. That stance leaves some widely reported claims unconfirmed, including the 30 BTC demand and the alleged six-terabyte extraction.
Forensic investigators will focus on several key tasks:
- Reconstructing the threat actor’s entry point and lateral movement inside networks.
- Verifying the scope and integrity of stolen files and determining whether data was exfiltrated or merely copied.
- Tracking any cryptocurrency addresses associated with the ransom demand to see if funds move through identifiable exchanges or mixers.
- Coordinating with federal authorities and international partners, since ransomware operations often cross borders.
Public accountability and data protection
Government entities face heightened scrutiny when breaches involve citizen data or services. Public trust hinges on transparent remediation, timely notifications to affected individuals and demonstrable steps to prevent recurrence: patching vulnerabilities, enforcing strong identity and access management, adopting multifactor authentication, and conducting regular security audits.
Legal and regulatory frameworks can also require disclosure and remediation measures. For any confirmed exposures involving personally identifiable information, data protection authorities may investigate compliance with privacy rules and require incident reporting.
Context: recent global ransomware trends
The Berlin incident follows a string of high-profile ransomware cases where attackers leveraged Bitcoin and other cryptocurrencies to demand extortion payments. In July, hackers temporarily took control of the Kenyan president’s official website and demanded 5 BTC, prompting an investigation that found no evidence of sensitive data loss at the time. Earlier seizures, successful recoveries and prosecutions demonstrate that law enforcement can sometimes disrupt criminal revenue streams and infrastructure, though operations are complex and resource-intensive.
Criminal groups adapt quickly, switching tactics when their infrastructure is targeted or when law enforcement pressure rises. As a result, both public and private sectors continue to invest in proactive defenses, threat intelligence sharing and incident response readiness.
What this means for citizens and organizations
For residents and organizations in Berlin and beyond, the attack underscores a few practical points:
- Be alert to phishing and credential-harvesting schemes. Attackers often use stolen credentials as an initial foothold.
- Use strong, unique passwords and enable multifactor authentication on important accounts.
- Organizations should maintain offline backups and rehearse disaster recovery and incident response plans to reduce pressure to pay ransoms.
- Monitor official communications for guidance about potential exposure of personal information and follow recommended steps if notified of a breach.
Final thoughts
The Berlin ransomware episode reinforces the complex relationship between cryptocurrencies and cybercrime: blockchain-based payments facilitate extortion demands, but they also create forensic trails that investigators can exploit. Authorities’ refusal to pay the reported 30 BTC underscores a policy stance increasingly favored by public institutions: prioritize containment, investigation and resilience rather than fueling criminal networks with ransom payments. As the probe continues, stakeholders will watch whether law enforcement can corroborate Rhysida’s claims and whether any crypto-linked funds can be traced or recovered.
Berlin’s case will likely contribute to ongoing debates about public-sector cybersecurity funding, cross-border cooperation on ransomware, and the evolving capabilities of blockchain forensics in attributing and disrupting criminal activity.






Discussion
Leave a Comment
Comments (3)
Seen this in my IT shop, phishing then helpdesk trick, lateral moves happen fast. Berlin isolating systems was smart, but people deserve clearer updates and faster notifications, if that’s real then…
Crypto helps criminals but also leaves trails. refusing to pay is right, hope they can trace the funds and not drag citizens through months of uncertainty
is this even true? 6 TB sounds giant, 30 BTC could be bluffing. govt says no pay but where's the proof, timeline seems fuzzy...