The German capital is navigating a major digital crisis after being targeted by the cybercriminal group Rhysida. This organization, which specializes in infiltrating state structures, successfully exfiltrated several terabytes of sensitive data belonging to the State of Berlin. To prevent the disclosure of this information, the attackers issued a seven-day ultimatum, accompanied by a ransom demand of 30 bitcoins—equivalent to approximately 2 million euros at the time of the incident.

Adhering to a policy of zero tolerance toward digital blackmail, the Berlin Senate officially refused to cave to the hackers' pressure. While ethically sound, this decision had immediate consequences: as the deadline expired, the attackers published a vast portion of the stolen data on the darknet. Berlin's administrative services are now forced to analyze the exposed content to identify the citizens whose personal information has been compromised, in order to notify them individually in accordance with current legal protocols.

This incident highlights a chronic vulnerability of public institutions to cyber threats, often exacerbated by methods as simple as they are effective, such as phishing. Beyond the Berlin case, the accumulation of private data by government bodies poses a structural security problem. Recent news, marked by the sale of millions of U.S. driver's licenses on the darkweb or repeated attacks against French government agencies, illustrates an alarming trend where state infrastructure is becoming the preferred target for cybercriminals.

The refusal to pay the ransom sparks a complex debate on cyber crisis management. While the "no-payment" strategy avoids directly fueling the criminal economy and validating hackers' methods, it shifts the social and security costs onto citizens, who find themselves exposed to risks of identity theft or the malicious exploitation of their personal data. This affair once again highlights the worrying gap between the amount of data collected by the State and the actual capacity of these administrations to protect it against increasingly sophisticated technological threats.