The German capital has become the latest government to stare down a crypto ransom demand. Berlin authorities are investigating a cyberattack against two state agencies after hackers reportedly demanded 30 Bitcoin, worth roughly 2 million euros, and threatened to publish stolen data if the city refused to pay.
Berlin’s answer, delivered by Mayor Kai Wegner after a special Senate meeting on Friday, was unequivocal: “The state of Berlin will not allow itself to be blackmailed.” Interior Senator Iris Spranger joined Wegner in briefing the public, while authorities continue examining exactly what information left government systems.
## What Happened
The attack affected two Berlin state agencies. City officials initially said only public information had been compromised, but later acknowledged that non-public data had also been affected, a shift that has raised concerns about the scope of the breach.
German magazine Der Spiegel reported that the ransomware group Rhysida claimed responsibility, citing information posted by the group on its dark web leak site. Security sources cited by the publication identified Rhysida as the group behind the extortion attempt. The attackers allegedly demanded 30 BTC and threatened to release the information unless Berlin paid, with the demand worth approximately 2 million euros at current prices.
According to those reports, Rhysida claims to have taken nearly six terabytes of data. The alleged files include information from tens of thousands of administrative offense proceedings, contracts, passwords, login credentials, emergency plans, and documents related to critical infrastructure. Berlin authorities have not independently confirmed the amount of data claimed by the group or the full list of compromised records.
## Officials Stay Tight-Lipped
The Berlin Senate Chancellery has declined to disclose details about the attackers, their demands, or the information potentially taken, citing the ongoing investigation. A Senate spokesperson told German news agency dpa that officials could not comment “for investigative reasons” at this stage.
That caution leaves several core facts unconfirmed by the state government, including the ransom amount itself. What is confirmed is the extortion attempt, the refusal to pay, and the admission that non-public data was affected.
## Why Ransomware Groups Demand Bitcoin
The Berlin case is a textbook example of why Bitcoin remains the preferred settlement rail for extortion schemes despite years of enforcement pressure. Ransom demands denominated in BTC can be set precisely, transferred across borders without intermediaries, and converted through increasingly sophisticated laundering chains.
It also illustrates the other side of the ledger: paying rarely ends the problem. Security researchers consistently advise against payment, both because it funds future attacks and because there is no guarantee data is deleted. Governments across Europe have hardened their stance in recent years, with public refusal becoming the standard playbook for state institutions, even as private companies continue to pay quietly.
Rhysida itself has a track record of high-profile intrusions, and its leak-site strategy relies on publicity pressure to force victims into negotiations. Berlin’s public refusal is a deliberate counter-move, denying the group the leverage of secrecy while accepting the risk that stolen files may be published.
## The Bigger Picture for Crypto Regulation
For the crypto policy world, incidents like this land at a difficult moment. The same properties that make Bitcoin attractive for extortion, borderless transfer and censorship resistance, are the ones advocates cite for financial inclusion and property protection in unstable jurisdictions. Regulators in the European Union have already tightened traceability requirements under transfer-of-funds rules, and every prominent ransomware case involving a European government strengthens arguments for stricter oversight of exchanges and self-custody services.
At the same time, blockchain analysis has become one of law enforcement’s most effective tools. Ransom payments leave permanent onchain footprints, and multiple crews have been identified or disrupted through exactly that trail. The Berlin investigation will likely involve tracing the attackers’ wallets, a process that has produced arrests in comparable European cases.
## What Comes Next
Berlin’s refusal to pay means the standoff now moves to two arenas: the leak site, where Rhysida may publish stolen files as threatened, and the investigation, where German authorities and security services will attempt to trace the attack and attribute individuals.
For now, the city is holding the line. Whether the six terabytes of claimed data surface publicly, and what they contain, may determine whether Berlin’s hard stance becomes a model for other European governments facing the same choice.
Disclaimer: This article is for informational purposes only and does not constitute financial advice.
emergency infrastructure documents and tens of thousands of offense records on one state network reachable with stolen login creds. the 30 BTC demand is the cheap part of this story
the expensive part is rebuilding two agency networks on a flat topology that folded to one stolen login. hope the 2 million euros saved goes to segmentation
flat topology with stolen creds, you can almost picture the shared admin password on a sticky note. segmentation budgets never win until a week like this
30 btc, roughly 2 million euros, and Wegner just says no on principle. honestly the only correct answer, paying Rhysida once means paying forever
pay once and every state agency in germany becomes a subscription for rhysida. wegner saying no on friday was the cheap decision, the expensive one was letting one stolen login reach offense records
the part that worries me is the walk back. first only public data, now non public data too. the scope of what Rhysida grabbed keeps growing
rhysida leaking berlin state data in september, mark it
september leak is basically scheduled at this point. rhysida never deletes anything it can monetize twice
scheduled unless the dutch key trick pans out. investigators grabbed a rhysida master key last year, if that happens again the september deadline turns into a nothingburger overnight
the dutch got that key because a group member got sloppy, not magic. hoping berlin catches the same break is hope, not a recovery plan. offline backups are the actual plan
the initial only public data line aged about 12 hours. classic incident response by press release, expect a third revision before the rhysida timer runs out
the third revision is basically scheduled. first only public data, then oops non public too, incident comms by press release always ends up here
Good on Wegner for refusing. 30 BTC is pocket change for a state government but pay once and every agency becomes a target next month
^ and dutch police grabbed a rhysida key last year. refuse, restore from offline backups, let investigators hunt the keys instead
the dutch key was one sloppy affiliate, you cant budget a recovery around hoping rhysida hires badly twice. agree on the backups, the rest is copium
Rhysida leaked hospital records last year even after getting paid. berlin refusing is the only rational move here
this. paying just funds the next 30 BTC demand against whichever city blinks first. saying no is the cheap part, keeping six terabytes sealed is the hard part
30 BTC is pocket change until you price the cleanup. rebuilding two agencies on segmented networks will blow way past the 2 million euros they refused to pay
rhysida running a countdown for tens of thousands of offense proceedings is the grim part. der spiegel naming them means the leak page is already archived by half of europe
tens of thousands of offense proceedings AND login credentials in the same grab. why were emergency infrastructure docs on that network at all
exactly, and the answer will be some legacy sync share nobody audited since 2019. the ransom is the symptom, flat network design is the disease
because the same shared drive held ten years of case files. flat topology plus one stolen domain admin login and every agency doc since 2019 ends up in the same basket
emergency infrastructure documents sitting on the same domain as offense records, one login away. that part should end careers, not just contracts
wegner saying berlin will not be blackmailed is the easy quote. every state government in europe is watching how the september timer plays out before they answer their own rhysida email
genuine question, would berlin even be allowed to transfer 30 btc to a wallet tied to a sanctioned actor? half of these refusals might be lawyers, not backbone
they would not. transferring to a sanctioned entity is a criminal exposure no mayor can wave through, which is exactly why the no was free. the backbone framing is theater