The City of Berlin has become the latest public institution to have stolen data leaked online after refusing to meet a ransom demand paid in bitcoin.

According to the facts confirmed in this case, hackers breached systems tied to the City of Berlin and exfiltrated data, then demanded payment in bitcoin in exchange for not releasing the material publicly. The attackers set a deadline for the ransom to be paid.

That deadline has now passed. The City of Berlin did not pay the ransom, and the hackers followed through on their threat, publishing the stolen data on the darknet.

The case follows a pattern familiar to cybersecurity observers across Europe: attackers gain access to a target's systems, threaten public exposure of sensitive material unless paid in cryptocurrency, and carry out the leak once an ultimatum lapses without payment. Bitcoin's use in such schemes stems from the pseudonymous nature of transactions on the network, which attackers calculate offers them a degree of insulation from identification, even though blockchain transactions are ultimately traceable and law enforcement agencies have increasingly developed capabilities to follow funds after the fact.

What is known so far

The specifics of what data was taken, how many residents or systems were affected, and what technical vulnerabilities the attackers exploited have not been detailed in the information available at this stage. What is established is the sequence of events: theft, ransom demand in bitcoin, an expired deadline, and publication of the stolen material on the darknet.

For a European capital, the episode underscores a recurring exposure faced by municipal and public-sector bodies, which often manage large volumes of citizen data while operating under the same ransomware threat model long faced by private companies. The refusal to pay reflects a stance increasingly adopted by public institutions across Europe, where paying ransoms is often discouraged or restricted on the grounds that it funds further criminal activity and offers no guarantee that stolen data will not be leaked regardless.

That risk has now materialised in Berlin's case. With the data already circulating on the darknet, attention turns to what remedial steps the city takes next, including any notification obligations toward affected individuals and any investigation into how the breach occurred in the first place. No further details on these points have been made available.