

A city network, then a public archive
Attackers exfiltrated about 5.79 terabytes—roughly 1.44 million files—from Berliner Landesnetz between August 7 and 12. BeLa connects around 600 public-sector sites. Germany’s BSI attributed the entry to a ClickFix variant, a social-engineering technique that persuades users to run malicious instructions. Rhysida, active since 2023 and linked by researchers to Eastern Europe, demanded 30 Bitcoin through a seven-day auction. Mayor Kai Wegner confirmed the extortion on August 28 and refused to pay.
Why this matters
The full dataset was published in early September, followed by a second package containing access credentials. The reported material included more than 5,000 personnel files, passports, IBANs, Bundestag committee protocols, civil-protection and CBRN plans, PAYONE database credentials and vulnerability assessments involving Berlin’s water supply. The danger is not one headline breach. It is years of secondary fraud, coercion and targeting built from information that cannot be “unpublished.”
The no-pay decision was right—and incomplete
Governments generally discourage ransom payments because money funds criminal operations and does not guarantee deletion. Berlin’s refusal avoided rewarding Rhysida, but it did not protect people whose records were already stolen. Double extortion makes the old backup strategy insufficient: an organization may restore systems yet still face disclosure. The real decision occurs before an attack, in segmentation, identity controls, data minimization and rehearsed support for victims.
The economics of 30 Bitcoin
The reported ransom was 30 Bitcoin, described as about €2 million in the extortion demand. Even if that amount were accurate at the deadline, it is a poor measure of the loss. Incident response, system rebuilding, legal review, credit monitoring, operational delay and security upgrades can cost multiples of the demand. Criminals exploit that gap. A “small” ransom becomes credible when the defender’s cleanup bill is enormous.
Election-eve pressure
Berlin’s state election is September 20, two days after this report. That timing makes every technical failure political. Incumbents must defend preparedness and transparency; opponents can frame the leak as administrative negligence. Rhysida gains reputation from refusing to blink after the mayor’s public stance. But speculation about Kremlin direction should not outrun evidence: geographic attribution and political usefulness do not by themselves prove state control.
The British Library parallel
Rhysida previously hit the British Library, where the damage demonstrated how a public institution can be forced into prolonged reconstruction even when its mission is not commercial. Berlin is larger and more interconnected. Both cases show that legacy systems, broad permissions and irreplaceable public data create recovery challenges that private-sector uptime metrics miss. A library loses access to knowledge; a city risks services and trust.
What European cities should do next
The immediate priorities are credential rotation, independent validation of what was exposed, direct notification and protection for affected people, and isolation of operational technology from administrative networks. Longer term, cities need phishing-resistant authentication, least-privilege access, offline recovery, procurement standards and public exercises that assume data publication. The success measure is not whether a ransom was refused. It is whether essential services continue and exposed residents receive practical help after refusal.
The long tail of a public-data leak
Passwords can be reset, but passports, personnel histories, financial identifiers and sensitive planning records create different timelines. Criminal groups can combine leaked data with later breaches, impersonate officials, target relatives or craft messages that reference authentic workplace details. Even information that seems stale may reveal organizational charts and naming conventions. Civil-protection documents create an additional dilemma: transparency is important in democratic government, yet operational detail can help a hostile actor identify dependencies. Berlin’s recovery should therefore include a data-by-data harm assessment rather than one generic notice. People at higher risk may need document replacement, account monitoring, specialized support or protective changes that last longer than the news cycle.
Accountability without scapegoating one employee
ClickFix begins with human manipulation, but blaming the person who clicked hides the system’s role. A resilient network assumes someone will eventually follow a convincing instruction. Application controls can block unauthorized interpreters; phishing-resistant authentication can limit token theft; segmentation can prevent one user context from reaching unrelated records; egress monitoring can detect terabytes leaving. Training still matters, especially against rapidly changing lures, but it is the least reliable layer when treated alone. Political accountability should ask whether leaders funded those controls, tested response plans and reduced retained data. The goal is not to excuse mistakes. It is to avoid designing a city network whose safety depends on every one of thousands of users making the correct decision every time.
Sources: Reuters crisis response; TechRadar breach report; Moneycontrol report via TradingView. Facts and figures are a fixed September 18, 2026 reporting snapshot and do not update live.