Severity Daily

IT and AI security incidents, checked against the primary source

Berlin confirms it is being extorted, eleven days after announcing a network compromise without mentioning it

BREACH — Berlin confirms it is being extorted, eleven days after announcing a network compromise without mentioning it

Written by

in

The State of Berlin acknowledged a compromise of its administrative network on 17 August without mentioning extortion. On 28 August it confirmed the extortion and rejected the ultimatum — and almost everything published about what was taken comes from the people who took it.

What happened

On 28 August 2026, Berlin’s Senate confirmed that the state administration is the subject of an extortion attempt following a cyberattack, and the Governing Mayor, Kai Wegner, rejected the attackers’ ultimatum. His statement, in full: “Das Land Berlin wird sich nicht erpressen lassen” — the State of Berlin will not allow itself to be extorted.

That is the news. It is worth setting against what the state said eleven days earlier.

On 17 August, the Senatskanzlei published a press release titled IKT-Vorfall im Landesnetz Berlin — ICT incident in the Berlin state network. Its operative sentence: “Im Zuge forensischer Untersuchungen hat sich eine Inkriminierung des Landesnetzes Berlin ergeben” — in the course of forensic investigations, a compromise of the Berlin state network was established. The release named two Senate administrations that had been isolated from the network the preceding Friday: Urban Development, Building and Housing, and Mobility, Transport, Climate Protection and Environment. It gave no dates for any data outflow, no volume, and no attacker. It stated that “aus ermittlungstaktischen Gründen” — for investigative reasons — no further concrete information could be provided.

It did not mention extortion at all.

What the Senatskanzlei has since acknowledged, as reported by German outlets that carried its statements, is that personalized and other non-public data may have been taken from the Mobility, Transport, Climate Protection and Environment administration, and that the full scope is not yet established. Coverage places the data outflow in a window between 7 and 12 August, and reports that all Senate administrations were reconnected to the network on 23 August. Neither of those specifics appears in the 17 August release, and we have not found them in a primary statement.

Everything that follows is claimed by the attackers, labeled as such throughout because Berlin has confirmed none of it.

The claimed inventory includes roughly 80,000 administrative-offense files, more than 46,500 contracts, court documents, details described as relating to critical infrastructure, emergency plans, passwords, and approximately 6,000 files of login credentials. The claimed ransom is 30 bitcoin, characterized in reporting by Der Spiegel as around €2 million, with an initial ultimatum set for Friday afternoon and a deadline a week out.

The claimed volume does not agree with itself across sources. One figure circulating is 5.79 terabytes; German reporting gives 5.7 terabytes copied from the environment and transport administration. On people affected, one account reports a claim of personal information on 12,076 individuals, while German coverage describes 100,000 to 200,000 individual data records. Those last two are not necessarily contradictory — records are not people — but they are not reconcilable from anything published either, and no official figure exists for any of it.

On attribution: the ransomware group Rhysida has been named by Der Spiegel and by security sources, and a leak-site entry appeared on 28 August. Berlin has not publicly attributed the attack, and neither do we. A leak-site listing establishes that someone claims the data; it does not establish who took it, and it is not evidence of the inventory it advertises. Reporting also describes the initial access as a phishing email opened by an employee. That has not been confirmed by the Senatskanzlei and is carried here as reporting.

Why it matters

The eleven days between the two statements are the part worth studying, and not because anyone did anything improper.

The 17 August release is a model of a certain genre: accurate, prompt by public-sector standards, and almost entirely uninformative. Every sentence in it is defensible. It confirms a compromise, names the isolated departments, and declines further detail on investigative grounds — a real constraint, not an excuse, when a criminal investigation is running. What it does not do is tell anyone whose data sits in those systems that a party with a financial motive is holding it.

Eleven days later the extortion is public, and it is public on the attackers’ schedule. The ultimatum, the leak-site entry and the ransom figure all surfaced together, and the state’s confirmation followed them. That is the structural problem with staged disclosure: an organization that holds back the extortion element for legitimate investigative reasons has ceded the timing of that disclosure to the criminal, who has every incentive to choose the moment that maximizes pressure. Berlin ended up confirming the extortion in response to an ultimatum rather than announcing it on its own terms, and the sequence reads as reactive even though the underlying decisions may each have been sound.

A related sequencing detail, stated without insinuation: all Senate administrations were reportedly reconnected on 23 August, five days before the extortion was publicly confirmed. Reconnection turns on forensic confidence about persistence and access, which is a different question from whether stolen data is being used as leverage, and both can be handled correctly at once. But the public timeline shows restoration completed before the public learned an extortion demand was involved.

Wegner’s refusal is the right call and deserves to be said without hedging. Paying funds the next operation, guarantees no deletion, and buys a promise from a party whose business model is breaking promises. But it is not costless: if the claimed material is genuine, it gets published, and the remediation burden falls entirely on the state. Refusal absorbs that cost deliberately rather than gambling on avoiding it, and calling it free does the decision a disservice.

For everyone else, the operationally important claim in that inventory is not the terabyte count. It is the roughly 6,000 credential files and the emergency plans. If credentials were genuinely taken at that scale from a state administration, the exposure does not stop at the two isolated departments — it extends to every system, supplier portal and federated service those credentials could reach, and isolating a network segment does nothing about a valid password used somewhere else. Credential rotation across an organization the size of a city-state administration is measured in months, and it is the work that outlasts the headline. We stress again that this is the attackers’ claim. It is also the claim that, if true, matters most, which is precisely why it should not be repeated as fact.

What to do

  • If you are a supplier, contractor or federated partner of the Berlin administration — particularly the Senate administration for Mobility, Transport, Climate Protection and Environment — treat any credential, API key or shared account you have exchanged with those systems as potentially exposed and rotate it. Do this on the claim, not on confirmation; rotation is cheap and confirmation may take months.
  • Do not build a response around the leak-site inventory. Volumes and file counts published by an extortion group are promotional material. Use them to scope what to check, never as an assessment of what was lost.
  • Decide your own disclosure triggers now, in writing. Berlin’s sequence — incident notice first, extortion confirmation eleven days later under an ultimatum — is the default outcome when nobody has predetermined whether “we are being extorted” is disclosed with the incident or held. Make that call before you need it, and record the reasoning.
  • Check that you could isolate an administrative unit the way Berlin did. Whatever else is unresolved here, segmenting two departments off the state network was possible and was done quickly. If your equivalent action would require an all-or-nothing shutdown, that is a design finding you can act on today.
  • Treat “emergency plans” as a data class. Continuity documentation usually sits outside the classification schemes applied to personal data, and it describes exactly how an organization behaves under stress. Find out where yours lives and who can read it.

Sourcing note

Checked: the Senatskanzlei’s press release of 17 August 2026, IKT-Vorfall im Landesnetz Berlin, on berlin.de, which supplied the quoted German text, the two named Senate administrations, the isolation action, and the investigative-reasons caveat — and which contains no reference to extortion. That is the primary source for the state’s initial position.

The 28 August confirmation and Wegner’s quoted statement come from Tagesspiegel’s report of that date, published 18:37 and updated 20:37, which is where we read them. We could not locate a Senatskanzlei press release carrying the same language, so the confirmation reaches us at one remove from a German outlet that carried the Senate’s statements, not from a government page.

All figures for volume, file counts, individuals affected, ransom amount and the contents of the stolen material originate with the attackers and are reported as claims. The conflicting volume figures (5.79 versus 5.7 terabytes) and the two different measures of scope (12,076 individuals versus 100,000 to 200,000 records) are shown as they stand; we have not chosen between them, and no official figure has been published. The ransom of 30 bitcoin, described as approximately €2 million, is Der Spiegel’s reporting.

Attribution to Rhysida is reporting by Der Spiegel and unnamed security sources, plus a leak-site entry dated 28 August. It is not confirmed by Berlin and is not stated as fact here. The phishing-email account of initial access is likewise reporting and is unconfirmed by the Senatskanzlei.

Unresolved: the actual volume and nature of data taken; whether credentials were among it; the dates of the data outflow, which appear in coverage as 7 to 12 August but not in any primary statement we located; and whether Berlin will make an attribution of its own.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *