GBAF Logo
Global Banking & Finance Awards® 2026 Nominations open, free to enter Nominate now →
Ransomware group says it stole Berlin data, offers it for auction - Headlines news and analysis from Global Banking & Finance Review
Headlines

Ransomware group says it stole Berlin data, offers it for auction

Published by Global Banking & Finance Review

Posted on August 28, 2026

2 min read

· Last updated: August 28, 2026

Add as preferred source on Google

Ransomware Group Auctions Berlin Data After City Refuses Ransom Payment

Berlin Faces Ransomware Attack and Data Auction

By Maria Martinez and AJ Vicens

BERLIN, Aug 28 (Reuters) - A ransomware group said on Friday it was putting up for auction a trove of data it stole from Berlin state agencies, and city officials refused to pay.

Details of the Data Breach

The Rhysida group, which researchers say operates from Russia or Eastern Europe, said on its website it took 5.79 terabytes of data including 46,500 contracts as well as emails, phone numbers, passwords and classified information.

The group said it was auctioning the data at a starting price of 30 bitcoin ($77,622) in just under seven days, showing a countdown timer on its website.

The cyberattack on Berlin's network comes less than a month before the city-state holds elections on September 20.

City's Response to Ransom Demands

'BERLIN WILL NOT SUBMIT TO EXTORTION'

Broadcaster RBB reported on Thursday evening that Berlin had received ransom demands for an unspecified amount following the attack.

Official Statements and Ongoing Investigation

"The state of Berlin will not submit to extortion," Berlin Mayor Kai Wegner and Berlin's interior senator, Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack on their website.

Officials could not provide details on the content or scope of the affected data because the extent of the breach was still being examined, Wegner said at a press conference.

Spranger said the city's election infrastructure had not been affected and that, according to security officials, no data related to the election had been compromised.

Rhysida Ransomware Group Background

History of Attacks

RANSOMWARE GROUP TARGETS GOVERNMENTS

Rhysida has claimed nearly 280 attacks since it emerged in June 2023, according to cybercrime research platform eCrime.ch.

Roughly half of its victims have been in the U.S., followed by the U.K., Canada and Italy, as well as other nations, according to Ransom-DB, a ransomware analysis and tracking service.

Targeted Sectors and Notable Incidents

The group has repeatedly targeted government institutions, such as the October 2023 hack of the British Library. The group has also claimed attacks on the Chilean army, schools, healthcare facilities and businesses of all sizes.

(Reporting by Cian Muenster, Miranda Murray, Maria Martinez;Editing by Friederike Heine and Cynthia Osterman)

Key Takeaways

  • The Rhysida ransomware group, likely tied to Russia or CIS-based actors, is auctioning 5.79 TB of exfiltrated Berlin state data at an opening bid of 30 BTC (~$77,600), with a countdown of under seven days. Berlin has formally rejected paying the ransom. (ertnews.gr)
  • Rhysida employs ‘double extortion’ tactics—encrypting data and threatening public release if ransoms aren’t paid—and has targeted institutions globally since emerging in May 2023, including the British Library, healthcare providers, the Maryland Department of Transportation, and the Chilean army. (en.wikipedia.org)
  • Cybersecurity researchers link Rhysida to precursor groups like Vice Society and Gold Victor, noting shared tools and techniques. Its operations span Europe and North America, and its tactics reflect a sophisticated ransomware‑as‑a‑service model. (sophos.com)

References

Frequently Asked Questions

What data was stolen in the Berlin ransomware attack?
The Rhysida group claims to have stolen 5.79 terabytes of data including 46,500 contracts, emails, phone numbers, passwords, and classified information from Berlin state agencies.
Did Berlin pay the ransom demanded by the ransomware group?
No, Berlin officials refused to pay the ransom and stated publicly that the city would not submit to extortion.
Who is believed to be behind the Berlin cyberattack?
The attack was claimed by the Rhysida ransomware group, which is believed to operate from Russia or Eastern Europe.
What is the Rhysida group known for?
Rhysida is known for targeting government institutions worldwide, with nearly 280 attacks since June 2023, including high-profile incidents in the U.S., U.K., and Chile.

Tags

Related Articles

More from Headlines

Explore more articles in the Headlines category