Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections
The ransomware group is auctioning the stolen files starting at 30 bitcoin. Officials say election infrastructure itself was untouched.
Thirty bitcoin, a countdown timer displayed publicly on the leak site, seven days on the clock. That is the pressure campaign Rhysida chose against the government of the German state of Berlin, whose network was compromised weeks ahead of local elections scheduled for September 20.
The group, which researchers place in Russia or Eastern Europe, says it exfiltrated 5.79 terabytes of data, including 46,500 contracts, emails, phone numbers, passwords and material described as classified. The auction opened at 30 bitcoin, roughly $77,600 at current exchange rates, a comparatively modest starting price for that much data, which suggests the group is leaning at least as hard on psychological pressure as on the direct payout.
Berlin's mayor, Kai Wegner, and the state's interior senator, Iris Spranger, responded jointly and without hedging: "The state of Berlin will not submit to extortion." It is a stance more government bodies are taking these days, though it usually means the stolen data ends up fully public once the auction clock runs out, ransom or no ransom.
Thirty bitcoin, a countdown timer displayed publicly on the leak site, seven days on the clock.
On the one detail that actually matters for democratic process, Spranger said election infrastructure itself was not affected and that, according to security officials, no election-related data had been compromised. That is a meaningful distinction to draw explicitly, given how much attention European governments pay to the possibility of election interference through exactly this kind of attack, even when, as appears to be the case here, nothing points to that motive.
Rhysida is not new to this. The group claims close to 280 attacks since it first appeared in June 2023, including its widely covered breach of the British Library that October. Public institutions remain a recurring target: slower to pay, but often less well defended than private-sector organizations with dedicated security budgets.
The timing against a vote is not an isolated choice. European local and regional governments have absorbed a string of ransomware hits timed to land in the run-up to an election this year, a pattern security researchers attribute less to any coordinated campaign than to opportunism: election season already strains local IT staff with expanded public-facing services, and a ransomware crew watching a government calendar does not need inside information to notice that. Whether or not Rhysida planned it that way, the effect is the same either way, maximum press coverage at the moment officials can least afford the distraction.
Based on reporting by Security Affairs.



