# Berlin Refused to Pay the Ransom: Inside the Four Task Forces Now Managing the Fallout

When the Rhysida ransomware group demanded a 30-bitcoin payment from the State of Berlin, the German capital made a calculated decision: refuse. The data went public on Friday, September 4th, and now Berlin operates two police task forces, a joint departmental unit, a crisis management team, and has retained external legal counsel. This is what a coordinated incident response looks like when a government entity stares down a cyber extortion attempt—and the aftermath is a masterclass in transparency, resilience, and the harsh realities of modern cybersecurity.

The State of Berlin set out its entire response machinery in a press release from its Senate Chancellery on September 3rd, the day before the criminals' publication deadline. Berlin's state government confirmed on Saturday that it was reviewing the leaked material "with the highest intensity," as Miranda Murray reported for Reuters. A central crisis unit has been tasked with verifying the contents and notifying affected individuals. The attack specifically targeted two Senate departments: one covering Mobility, Transport, Climate Protection and Environment, and the other handling Urban Development, Construction and Housing. It's crucial to state this plainly because some coverage has erroneously placed national defense material in the dump—Berlin is a city-state, and its Senate departments run buses, building permits, and housing benefit programs. German national defense belongs to the federal government and the Bundeswehr, not to a city administration.

The Anatomy of a Refusal: What Berlin's Response Actually Looks Like

Berlin's own account of what may be in the stolen files is narrower and more mundane than speculative reports suggest. The city says the data may include personal information on state employees, residents, and businesses. Der Spiegel published a screenshot of Rhysida's dark web listing in August, which the BBC subsequently reported. On that listing, the group claimed contracts, non-disclosure agreements, personnel files, passwords, and thousands of personal contact details. However, that inventory is the criminals' own claim, and nobody outside the investigation has independently verified it. What makes this incident unusually well documented is that Berlin published its own response, providing a rare transparent look at how a major government entity handles a ransomware crisis.

The operational response is substantial. The State Criminal Police Office and the transport department each established a special task force. The two affected departments then formed a joint task force to coordinate their efforts. The housing department runs its own crisis management team and has opened a dedicated contact point for staff. It also hired an external legal adviser to handle confidential or legally sensitive matters. An ICT emergency task force meets until further notice to manage technical containment and recovery. Berlin is working closely with the state prosecutor, the Federal Office for Information Security (BSI), and other federal agencies. Critically, the city sees no current evidence that the attackers still hold the state network, though forensic work continues to determine whether the threat actors exfiltrated more data than anyone yet knows.

The Human Cost of a Data Breach

One line in the press release is easy to skim past, but it speaks volumes about the real-world impact of this cybersecurity incident. Berlin has told police officers that counselling and support services exist for people who come in to report their data in the dump. A city has budgeted for residents needing psychological support after a data breach. Berlin asks anyone who finds their own data in the leak to file a criminal complaint, either online or at a police station. The Senate departments will contact identified individuals directly, on a risk-based approach, in compliance with the GDPR and the Berlin Data Protection Act. This human-centric approach to breach response is something many private sector organizations could learn from.

Decoding the Numbers: What We Actually Know

Every number in this story belongs to the attackers, and that's a critical distinction. The size of the theft is Rhysida's claim rather than an independent measurement. Berlin says the group asserts it holds 5.7 terabytes of data. Reuters and the BBC both report 5.79 terabytes, but nobody outside the group selling the files has confirmed either figure. The price, however, is firmer. The auction opened at a minimum bid of 30 bitcoin, which Berlin puts at roughly €2 million. One published conversion deserves careful scrutiny: Reuters gives the 30-bitcoin minimum as $77,622, which would value a single bitcoin at about $2,587. Multiply $77,622 by thirty and the answer is $2.33 million, which matches Berlin's own euro figure. The bracket appears to hold the price of one coin rather than the total—a minor but telling detail in the confusing world of ransomware economics.

Rhysida: A Familiar Pattern of Cyber Extortion

The pattern here is Rhysida's business model rather than a reaction to Berlin specifically. This ransomware group hit the British Museum in 2023, taking around 500,000 files. The museum refused to pay, and the group published them as promised. Rhysida has claimed hundreds of attacks since emerging in 2023, targeting governments and companies across many countries. Security researchers place the group's operations in Russia and Eastern Europe. Their approach is consistent: breach, exfiltrate, threaten, publish. The group's willingness to follow through on publication threats makes them particularly dangerous to organizations that refuse to negotiate.

Refusal is now common enough to have a recognizable shape in the cybersecurity landscape. Grafana Labs turned down a ransom demand in May after attackers stole code that was already open source. Kenya investigated a bitcoin demand over its president's website in July. Coca-Cola halted US production at a subsidiary after an attack in the same month. These cases, along with Berlin's, suggest a growing consensus that paying ransoms is both ethically problematic and practically ineffective—a stance supported by many cybersecurity professionals who argue that payment only funds further criminal activity.

The Political and Operational Timeline

The timing of this attack adds another layer of complexity. Berlin votes on September 20th, and the data landed on September 4th. State senator Iris Spranger has stated that the attack did not reach election infrastructure, but the proximity to a major political event raises questions about the attackers' motivations. Berlin has separately urged the public not to circulate unverified claims about the contents of the leak—a request that's hard to grant in the age of social media and instant information sharing. The attack itself began earlier than the public disclosure suggests. Officials date an initial leak to between August 7th and 12th. Berlin shut down two departmental networks on August 14th, which stopped housing benefit applications for several days. Forensic work later found further losses in the transport and environment department.

Berlin sits in a country where 87% of companies reported a cyber attack last year, according to industry surveys. Attackers have also reached European institutions through officials' own messaging accounts, demonstrating that no organization is immune to sophisticated social engineering and technical exploitation. Mayor Kai Wegner said on August 28th that Berlin would not be blackmailed. Florian Hauer, the state's chief digital officer, said almost exactly the same thing on September 3rd. Hauer called an attack on the state network a serious crime that harms everyone, and said the safety of staff and residents came first. Berlin described the incident as an extremely serious crime and an attack on the state itself.

Conclusion: The Unanswered Questions

Nobody has yet published the part that would settle the argument. What did the attackers want beyond money? Does anyone stand behind them? And what is actually in 5.7 terabytes of data? Berlin says its investigations continue, and until they report, the only firm number in this story is the price the criminals set. What Berlin's response demonstrates, however, is that a refusal to pay is not passive—it's an active, multi-pronged strategy involving law enforcement, technical forensics, legal counsel, and human support services. For cybersecurity professionals watching this case unfold, the takeaway is clear: ransomware resilience isn't just about prevention; it's about having a comprehensive, transparent, and humane response plan ready when the deadline passes.