Security News

Ransomware Gang Rhysida Demands Ransom From Berlin Government — City Refuses to Pay

Security Week · 31 Aug 2026
Key Takeaway Don't assume ransomware only targets big organisations — invest in backups, credential monitoring, and incident response planning now, before an attacker forces the decision.

The Rhysida ransomware group has claimed responsibility for stealing more than 5TB of data from systems linked to the city of Berlin, allegedly including personal information and login credentials. Berlin authorities have confirmed they will not pay the extortion demand, a decision consistent with growing guidance from cybersecurity agencies worldwide that discourages ransom payments.

Rhysida is a known ransomware-as-a-service operation that typically breaches networks, steals sensitive data, and threatens to publish or sell it unless payment is made. Refusing to pay does not eliminate the risk that stolen data could still be leaked or misused, meaning affected individuals and organisations may still face fallout from identity theft or fraud even without a payout.

While this incident involves a government entity, small and medium businesses face the same style of attacks. Criminal groups increasingly target smaller organisations precisely because they may have weaker defences and be seen as easier, faster payouts. Strong backups, credential hygiene, and early detection of intrusions remain the best defence against becoming the next headline.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.