Berlin’s state government refused to pay a 30 BTC ransom demanded by Rhysida, and the ransomware gang answered by claiming to leak 5.79 TB of stolen data on the dark web. Same old extortion script, ugly ending. Hold the line, and criminals try to make the refusal sting anyway.
- Berlin said it would not “submit to blackmail.”
- Rhysida claimed to leak 5.79 TB of stolen files after nonpayment.
- Officials say residents’ personal information may be among the data exposed.
- The incident disrupted services and is now under state and federal investigation.
The ransom demand was not small change. Berlin’s Senate Chancellery valued it at about €2 million, or roughly $2.4 million, based on the 30 Bitcoin demand. At the time, Bitcoin was trading near $79, 902, which is a very expensive way for a gang to say, “nice administration you have there, shame if something happened to it.”
Florian Hauer, Berlin’s chief digital officer, said the city “would not submit to blackmail” and that “protecting state employees and residents remained the priority.” That is the right public answer. Paying extortionists is a terrible business model, and governments should stop pretending otherwise.
But refusing to pay does not make ransomware painless.
It just changes the damage.
Rhysida is a ransomware group active since 2023, and this case follows the now-standard double extortion model. That means the attackers do not just steal or lock data. They also threaten to publish it unless the victim pays. If the victim refuses, the leak site becomes the pressure point.
Berlin first detected the compromise in August and disconnected two Senate departments from the state network. The affected areas covered urban development and housing, plus mobility, transport and environmental affairs. Services tied to those departments were disrupted, including housing benefit payments and family support, before the systems were reconnected on August 23.
That sequence matters. When ransomware hits a government network, the damage is not just technical. It shows up as delayed payments, backlogged paperwork, and public trust taking a hit while officials scramble to figure out what was taken and what can still be protected.
Rhysida’s post-release claims are the part that raise the most concern. According to reporting on the leak, the gang claimed to have stolen 5.79 TB of data and roughly 1.44 million files. The material is said to include personal data for 12, 076 individuals, 16, 389 email addresses, 11, 963 phone numbers, 148 IBANs, and a mix of passwords, credentials, passports, ID cards, HR files, and internal legal records.
Those are attacker claims, not independently verified facts. Still, even partial exposure of that kind can turn into a long, ugly mess for people whose names, contact details, banking information, or identity documents are now floating around criminal channels.
Officials are reviewing the leaked dataset with forensic cybersecurity specialists, while Berlin’s State Criminal Police Office and Germany’s federal cybersecurity agency are investigating. Residents who suspect fraud or identity theft tied to the breach have been told to contact police.
That is the real cost of ransomware once data has already been exfiltrated. Even when the ransom is refused, the aftermath can still include phishing, identity theft, account abuse, and months of cleanup. The criminals lose a payday, but the victims still eat the bill for containment and recovery.
The broader trend is interesting, too. Chainalysis says ransomware payments have trended downward even as data-leak-site-claimed attacks rose sharply, with claimed incidents up 50% year over year. In plain English: more gangs are shouting louder, but victims are resisting more often. Good. The market for cyber-blackmail deserves to be less liquid.
Bitcoin remains the preferred payment rail for these crews because it moves across borders quickly and without a bank clerk asking questions. At the same time, the “crypto is invisible” fantasy is getting thinner every year. Blockchain analytics, exchange compliance, and law-enforcement tracing have made laundering harder than it used to be. Harder is not the same as impossible, though. Plenty of gangs still use mixers, peel chains, and other tricks to muddy the trail.
There is also a more uncomfortable truth here: refusing to pay is the right call, but it is not a shield. Once the data is out of the building, there is no magic button that un-leaks it. A principled stand can still end with public exposure, angry residents, and a pile of incident-response costs. Noble? Yes. Clean? Not even close.
That is the ransomware bargain in 2025. Criminals try to turn stolen data into leverage. Victims try to avoid funding the racket without making the fallout worse. And when governments are the target, the stakes go beyond one agency’s IT budget. They reach into resident privacy, public services, and trust in the institutions meant to keep the lights on.
Key takeaways
-
Why did Berlin refuse to pay the ransom?
Berlin said it would not “submit to blackmail” and made protecting employees and residents the priority. The government chose not to fund the criminals, even knowing that refusal could trigger a public leak. -
Was the data leak confirmed?
Rhysida claimed to have leaked 5.79 TB of stolen data, but the contents are not fully independently verified. Investigators are still reviewing what was actually taken and how much of the gang’s claims hold up. -
Could residents be affected?
Yes. Officials said residents’ personal information may be among the leaked files, and the reported material includes data types that can fuel fraud, identity theft, and phishing. -
Why does this matter beyond Berlin?
It shows the tradeoff at the heart of ransomware response: refusing to pay can avoid funding extortion, but once data is stolen it does not stop the fallout. Public-sector targets are especially exposed because the disruption affects real services, not just servers. -
What does this say about ransomware and Bitcoin?
Bitcoin is still a common ransom rail because it is easy to transfer across borders, but it is not a free pass for criminals. Tracing tools and exchange scrutiny make laundering harder, even if they do not eliminate the threat.
Further reading
A few related reports for anyone keeping an eye on ransomware, extortion, and the bits of crypto that criminals still love to abuse.
- Ransomware group Rhysida extorts Berlin with government data
- Rhysida ransomware group targets Berlin government ahead of vote
- Ransomware trends and tactics: a 2025 analysis
- Berlin confirms data theft after Rhysida ransomware attack
- Cybercriminals target Kansas ATMs with jackpotting
- Rhysida claims Berlin hack: 5.79 TB, 30 BTC demand
- CrowdStrike warns of AI-driven ransomware surge in Europe
- FBI shuts down RAMP: dark web cybercrime hub linked to Bitcoin ransomware
- US credit downgrade to AA-: fiat falters, Bitcoin’s appeal surges