A hacker group has published large volumes of data allegedly stolen from Berlin's state government network on the darknet, after the city-state refused to meet a ransom demand of 30 Bitcoin, worth roughly €2 million at current prices.
The Berlin Senate confirmed that no payment was made to the attackers. "Es wurden keine Zahlungen geleistet," a spokesperson for the Senate, Christine Richter, told BTC-ECHO. The deadline set by the hacker group expired on Friday afternoon, after which the group says it released the material.
Broadcaster rbb first reported on the ultimatum and the subsequent publication of the data. According to the hackers, the leak consists of around 1.4 million files distributed across several packages. The material is said to include work references, tenders, employee evaluations and personnel files.
Attack traced to mid-August
The underlying cyberattack on Berlin's state network is reported to have taken place in mid-August. Security authorities and IT forensic experts are now working through the leaked files as part of an ongoing investigation into what was taken and how the breach occurred.
The case adds to a pattern seen across Europe in recent years, where ransomware groups increasingly demand payment in Bitcoin rather than fiat currency, calculating that the pseudonymous nature of blockchain transactions makes it harder for law enforcement to trace payments back to individuals. Public authorities, however, have grown more consistent in publicly refusing such demands, partly on the grounds that payment offers no guarantee data will not be leaked regardless, and partly to avoid setting a precedent that could invite further attacks.
For Berlin, the immediate concern now shifts from the ransom itself to containment: identifying exactly what left the network, notifying affected employees and contractors whose personnel files may be among the leaked material, and assessing whether further exposure is possible. No timeline has been given for when the investigation into the leaked files will conclude.
The episode underscores the exposure of public-sector IT systems to ransomware operators who continue to price their demands in cryptocurrency, a trend that shows no sign of reversing even as more government bodies across Europe adopt a policy of non-payment.




