A breach affecting city departments has exposed almost 5.8 terabytes of data, prompting renewed concern over the resilience of Germany’s digital infrastructure.
Hackers linked to Russia have penetrated Berlin’s municipal digital systems, stolen data and demanded a ransom of about 30 bitcoin, worth approximately €2m, according to the BBC. The attack, reported on 28 August 2026, temporarily disconnected the networks of several city departments and exposed information held by transport and environmental authorities.
The group Rhysida, which is linked to Russia, has claimed responsibility and threatened to begin auctioning the stolen material in seven days. The 5.79 terabytes of data could include contracts, personnel files and sensitive personal information. Berlin’s mayor, Kai Wegner, said the authorities would not pay the attackers, while law enforcement and security services were working on the investigation.
Departments forced offline
The breach has already disrupted the city’s administration. Networks in individual departments were temporarily shut down, including systems dealing with housing benefits. The interruption has highlighted how an attack on municipal infrastructure can affect routine public services even when the wider administration remains operational.
Authorities have also identified leaks involving the transport and environmental departments. The potential exposure of contracts and personnel records raises the prospect of consequences beyond the immediate loss of access to computer networks. Sensitive personal information, if published, could affect employees and members of the public whose details are held by the city.
Berlin’s authorities have said that the infrastructure for future municipal elections was not compromised. That assurance separates the reported breach from the systems responsible for organising the vote, although the attack has placed wider questions about the city’s digital security in sharper focus.
Extortion and the threat of publication
Rhysida’s demand is accompanied by a threat to release or sell the stolen information if Berlin does not comply. The proposed auction would turn the data breach into a continuing pressure campaign, giving the attackers an incentive to prolong the crisis and maximise the damage caused by any disclosure.
The scale of the alleged theft is significant: almost 5.8 terabytes represents a large body of municipal information, although the authorities have not said that every category of data named by the attackers is confirmed to have been taken. The threat itself is intended to force a decision on the city while the investigation continues and the affected systems are assessed.
Wegner’s refusal to pay leaves Berlin facing the more difficult task of containing the breach, restoring departmental networks and determining what information was accessed. The materials identified in the attack show why public bodies are attractive targets: their systems combine administrative records, commercial contracts and personal data in one interconnected digital environment.
A wider test of Germany’s digital defences
The attack is presented as part of the Kremlin’s continuing hybrid aggression against Germany and Europe. In this assessment, cyberattacks complement sabotage, information operations and other disruptive measures intended to create instability and inflict economic damage. A strike on Berlin’s municipal infrastructure is therefore significant not only because of the ransom demand, but also because it demonstrates how a city can be pressured through the systems used to deliver ordinary public services.
The alleged operation also serves a propagandistic purpose by seeking to expose weaknesses in cyber defences and undermine confidence in public institutions. Even without the threatened auction taking place, the disruption and uncertainty created by the breach can impose costs on the city and its residents.
Berlin’s immediate response will depend on how much data investigators establish was taken and whether the stolen material is published after the seven-day deadline. More broadly, the incident has made the need to modernise and strengthen Germany’s municipal digital protection impossible to ignore. The central unresolved issue is whether existing safeguards can prevent a similar breach from reaching other public services.
Should Berlin prioritise restoring vulnerable municipal systems quickly, or undertake a wider security overhaul even if it causes longer disruption?