Edition 28.08.2026
Euro Gazette

Trade press for commerce and distribution · Europe

Systems··3 min

Berlin Senate Confirms State Is Being Blackmailed After Cyberattack, Withholds Details

The Berlin Senate announced on 28 August 2026 that the state is under blackmail following a hacker attack on its Landesnetz, but gave no information on the perpetrators, demands or any ransom.

Milan Reuter

On Friday afternoon, 28 August 2026, the Berliner Senat (Berlin Senate) publicly confirmed that the state is being blackmailed in connection with a recent hacker attack on its Landesnetz (state IT network). The announcement, made at a short‑notice press conference in the Rotes Rathaus (Berlin City Hall), was delivered by Governing Mayor Kai Wegner (CDU) and Interior Senator Iris Spranger (SPD). While the officials stressed the seriousness of the incident, they offered no details about the attackers, their demands or any ransom request.

Official Confirmation at Rotes Rathaus

The press briefing was convened after rumours circulated all morning that Berlin was the target of a coordinated cyber‑extortion campaign. Wegner opened the session by stating, "Wir haben es mit einer schweren Straftat zu tun. Das Land Berlin wird von den Tätern erpresst," which translates as, "We are dealing with a serious crime. The state of Berlin is being extorted by the perpetrators." Spranger echoed the sentiment, confirming that the Senate would not yield to any blackmail attempts.

What Is Known and What Remains Unclear

The Senate’s statement confirmed three key points:

  • The state is being blackmailed in connection with the recent hack of the Landesnetz.
  • No ransom demand or other specific demands were disclosed.
  • It cannot be ruled out that personal and other data may have been exfiltrated from the affected servers.

Beyond these facts, the Senate left a number of critical questions unanswered. The identity of the attackers, the exact nature of the blackmail material, and any deadlines or payment mechanisms were not discussed. Journalists pressing for clarification were denied the opportunity to ask follow‑up questions.

Potential Implications for Berlin’s Digital Infrastructure

While the immediate financial impact of the extortion attempt remains unknown, the incident raises broader concerns about the resilience of public‑sector IT systems in Germany. The Landesnetz, which underpins a range of municipal services—from public transport ticketing to social‑service databases—could be a high‑value target for state‑sponsored or financially motivated actors.

Cyber‑security experts warn that the lack of publicly disclosed details may be a deliberate strategy to avoid giving attackers a platform for further intimidation. However, the admission that data may have been stolen could trigger mandatory notifications under the EU’s Network and Information Security Directive (NIS‑2), potentially obligating Berlin to inform affected citizens and regulators.

Analysis: The Growing Threat of State‑Targeted Extortion

Extortion attacks on government entities have risen sharply across Europe in the past two years, driven by the increasing sophistication of ransomware groups and the high value of public‑sector data. Berlin’s decision to confirm the blackmail publicly—while withholding specifics—mirrors a trend among European capitals to balance transparency with operational security.

Analysts suggest three possible scenarios:

  1. Data‑leak threat: Attackers may threaten to publish sensitive citizen data unless a payment is made.
  2. Service disruption: The blackmail could be linked to a demand to halt further attacks that could cripple essential services.
  3. Political leverage: In rare cases, extortion is used to extract policy concessions or influence decision‑making.

Without concrete details, it is impossible to determine which scenario applies to Berlin. Nonetheless, the incident underscores the need for robust incident‑response frameworks and regular penetration testing of critical infrastructure.

Timeline of Key Events

Chronology of the Berlin blackmail confirmation
DateEvent
2026‑08‑14First public reports of a hacker intrusion into the Landesnetz.
2026‑08‑28 (afternoon)Berliner Senat confirms blackmail at a press conference in the Rotes Rathaus.
Source: taz (https://taz.de/Angriff-auf-IT-des-Berliner-Senats/!6207914/)

As the investigation continues, Berlin’s IT security teams are reportedly working with federal authorities and private cyber‑forensics firms to trace the breach, assess data loss, and harden vulnerable systems. The Senate has pledged to keep the public informed, though it has warned that further updates may be limited for security reasons.

"We will not give in to blackmail," Wegner said, emphasizing the city's resolve to protect its citizens and infrastructure.

For now, the full scope of the attack and the exact demands remain shrouded in secrecy, leaving Berlin’s residents and businesses to await further clarification from their government.