BERLIN, 31 AUG 2026 — Berlin's governing mayor Kai Wegner says the state is being blackmailed and will not meet the extortionists' demands. The data left the network between 7 and 12 August. The decision not to pay was taken after it had already gone.

The timeline is the story

Data flowed out of the Senate Department for Mobility, Transport, Climate Protection and Environment between 7 and 12 August. Departments were disconnected from the network on 14 August. Berlin disclosed publicly on 17 August, reconnected all Senate departments on 23 August, and the Rhysida ransomware group claimed responsibility on its leak site on 28 August.

The seven days between the first outflow and the disconnection is the operationally significant number, and the one nobody is discussing.

7 to 12 AugExfiltration window
14 AugDepartments disconnected, a week after it began
5.79 TBClaimed by Rhysida, on 12,076 individuals
Housing benefitApplications and payments unavailable during the shutdown

Refusing to pay does not undo an exfiltration

Not paying is the right policy, and it is routinely reported as a defensive success. It is not.

Ransomware operations of this type both encrypt files and steal them. Payment can buy a decryption key, which addresses the first. What it buys against the second is a promise not to publish, from a party whose business model depends on being able to publish. The data is already copied, already out of the network, and already beyond any control the victim has.

So a refusal is a decision about publication and about funding the next attack. It is defensible on both counts and it does not protect the 12,076 people whose information may be in the set. Reporting the refusal as the incident's resolution gets the sequence backwards. The harm was complete on 12 August; everything since has been about consequences.

The claimed figures are the attacker's

5.79 terabytes and 12,076 individuals are numbers from a leak-site entry, posted 16 days after the exfiltration ended.

Berlin's Senate Chancellery has said only that personal or other non-public data cannot be excluded from what was taken, which is a carefully constructed non-confirmation and the correct thing for an authority mid-investigation to say. It is not agreement with the figures.

We have covered this asymmetry repeatedly, most directly when an extortion group claimed 25 million records and the published data contained 218,000 unique email addresses. A leak-site figure is a negotiating position from the party that benefits from a large number. It arrives on day one; the verified count arrives in a notification letter months later, if at all.

The one difference here is that Rhysida published no ransom figure at all, which is unusual and slightly informative. A group that names a price is negotiating; a group that does not may already have concluded there is nothing to negotiate with a government that has said publicly it will not pay.

Who actually paid for this

Housing benefit applications and payments were unavailable while the network was disconnected.

That is the real cost line and it lands on people applying for housing benefit, which is a population with no financial buffer for a delayed payment. The state absorbed reputational damage and forensic expense. Claimants absorbed the part that mattered.

That reveals a systematic gap in how public-sector incidents are assessed. Cost estimates capture remediation, consultants and overtime, because those appear in a budget. The welfare consequence of a nine-day interruption to benefit payments does not appear anywhere, and it is plausibly the largest harm the incident caused.

Disconnection is a real decision, not a formality

Pulling departments off the network on 14 August is what stopped the outflow, and it is the action that caused the service disruption.

That trade is the hardest call in incident response and it is made under uncertainty. Disconnect early and you halt services on evidence that may prove to be nothing. Disconnect late and the data has gone. Berlin did it seven days after the first outflow, which on the published timeline means the exfiltration had already completed two days earlier.

Nothing in the public record explains that gap. There are innocent possibilities — the outflow may not have been detected until later, or the 7 August date may be a forensic reconstruction rather than an alert seen at the time. That is the most likely reading, and it points at detection rather than decision-making as the thing that failed.

The regional read

Government digital services across ASEAN concentrate the same way, and the lesson transfers more cleanly than the politics does.

Singapore's Smart Nation infrastructure, Malaysia's MyDigital and Indonesia's national data centre programme all place citizen-facing services on shared networks, which is efficient and means a compromise in one department can require disconnecting others. Indonesia's June 2024 incident showed exactly that shape: Brain Cipher ransomware at the temporary national data centre in Surabaya disrupted 282 public services across more than 200 government institutions, including immigration, visas and passports. Jakarta was asked for US$8m and refused, as Berlin has.

The transferable question is not about payment, which regional governments have already settled in policy. It is whether a benefit system's continuity plan assumes network access, when the correct response to a serious intrusion is to cut it off.