ON
← Back to feed
Hackers demand ransom after attack on Berlin state network
Germany🏛️ PoliticsCenter11 hr. ago

Hackers demand ransom after attack on Berlin state network

On August 28, 2026, Berlin confirmed that it had received a ransom demand following a cyberattack on the city’s state network. The attack reportedly began at least a week earlier, with data leakage starting as early as August 7, a week before the breach was discovered. The attackers are believed to be known to the Senate, according to informed sources. Berlin’s Governing Mayor Kai Wegner stated that the city would not pay the ransom and emphasized that the attack constituted a serious criminal act. The incident has triggered investigations by the State Criminal Police Office and the Berlin Public Prosecutor’s Office, working closely with federal security agencies. While some parts of the network were isolated for security reasons, the Senate assured that critical election-related systems remained fully secure. The attack is described as the largest cyber incident experienced by the city to date.

Berlin has confirmed that it is being extorted following a cyberattack on its state network. The city's governing body received a ransom demand after hackers infiltrated the system, according to Mayor Kai Wegner. The request arrived around 5:30 p.m. on Thursday, though officials have not disclosed the amount or nature of the data potentially compromised. The attack marks one of the largest cybersecurity incidents in Berlin’s history. The breach was discovered earlier this month, with initial reports indicating that unauthorized access had been ongoing since at least August 7th. On August 14th, security measures were heightened as parts of the state network, specifically those responsible for transportation and urban development, were isolated for safety reasons. A digital state secretary, Florian Hauer, revealed that the attackers had likely accessed sensitive personal information, although this remained unconfirmed. Investigations into the breach are ongoing, involving both local and federal authorities. Authorities have stated that they are cooperating closely with law enforcement agencies to trace the perpetrators. While the exact scope of the data loss remains unclear, there are concerns that personally identifiable information might have been exposed. This uncertainty has led to increased scrutiny of the city's cybersecurity protocols and prompted further technical assessments. A specialized firm is currently scanning the entire state network to determine the full extent of the breach, a process expected to take several months. Mayor Wegner emphasized that the city would not comply with the ransom demands. He described the incident as a serious criminal act, underscoring the gravity of the situation. However, he did not provide specific details regarding the identity of the attackers or their motives. Some sources suggest that the group behind the attack may already be known to the city’s administration, based on information obtained from well-informed circles. In response to the breach, Interior Senator Iris Spranger noted that the portion of the network critical for elections was fully secured. She assured that no data had been leaked from that segment, citing assurances from the city’s security advisors. Despite these reassurances, the broader implications of the breach remain under investigation. The city’s emergency team continues to work alongside external experts to assess the damage and implement additional safeguards. The ransom demand reportedly amounts to two million euros, according to recent reports. Although the figure was initially undisclosed, media outlets have since confirmed the sum. The short payment deadline imposed by the attackers adds pressure on the city to resolve the situation swiftly. Officials have not yet commented on whether they will attempt to negotiate or seek alternative solutions. As the investigation unfolds, the focus remains on securing the remaining portions of the network and preventing future breaches.

Go to the primary sources (5)

The official sources this coverage is built on. Read them directly to bypass framing.

7 reports

Deutsche Welle (English) logoDeutsche Welle (English)State / PublicCenterFactual 92Objective 857 days ago
Germany investigates arms cache found in woods near Berlin

German security authorities discovered a cache of handguns near Berlin last year, which they believe were intended for assassinations on behalf of Russian intelligence. The weapons, including two pistols and ammunition, were found in a forest and left undisturbed after being disabled by police. Interior Minister Alexander Dobrindt confirmed the suspect, detained in Romania, was linked to espionage and planned attacks, but declined to confirm Russian involvement. He described the suspect as a 'low-level agent' unaware of higher command and noted other operatives, including a Kazakh citizen, were detained this year. Dobrindt emphasized ongoing threats from foreign interference, citing recent incidents like an explosives-laden drone found at Leipzig Airport.

Bias read (Center): The article presents information from multiple sources, including government officials and media outlets, without overtly favoring any particular political stance. While the topic involves allegations of foreign involvement, the framing remains neutral, focusing on official statements and reported事实

Why factuality (92): The article provides detailed information from reputable sources like Süddeutsche Zeitung, NDR, and WDR. It accurately reports the discovery of a handgun cache near Berlin, the arrest of a suspect in Romania, and the involvement of Interior Minister Dobrindt. The facts align closely with the cross-s

Why objectivity (85): The article maintains a neutral tone, presenting facts without overt bias. While it includes quotes from the minister, it does not take sides or present opinionated commentary. The language remains professional and focused on reporting the facts without emotional manipulation.

taz – die tageszeitung logotaz – die tageszeitungIndependentProgressiveFactual 90Objective 656 days ago
Hacker attack in Berlin: So close to the elections, it's time to worry

A major cyberattack has disrupted parts of Berlin's administration, raising concerns ahead of the city's September 20 election. The attack targeted the Berlin state network, which is operated by the ITDZ service center, causing critical systems such as those handling welfare payments and transportation to fail. Interior Senator Iris Spranger (SPD) and Mayor Kai Wegner (CDU) addressed the crisis, emphasizing that sensitive data was not compromised and that electoral systems remained unaffected. However, the incident highlights vulnerabilities in Berlin’s digital infrastructure, particularly since not all municipal departments are connected to the central network. Investigations into the perpetrators are ongoing.

Bias read (Progressive): The article frames the cyberattack as a significant threat to democratic processes, aligning with left-leaning concerns about cybersecurity and governance. It emphasizes the potential risks to elections and criticizes the fragmented nature of Berlin’s IT infrastructure, which could be seen as a left

Why factuality (90): The article accurately reports on a hacker attack on the Berliner Landesnetz, mentioning the disruption of services like welfare payments and election processes. It cites the involvement of the Senate and officials such as Iris Spranger and Kai Wegner, providing specific details about the impact and

Why objectivity (65): The article takes a clear stance by blaming the attack and linking it to potential election interference, using strong language like 'Angriff auf Berlin.' While it provides factual details about the impact, it frames the issue in a political context, potentially influencing reader perception toward

Frankfurter Allgemeine (FAZ) logoFrankfurter Allgemeine (FAZ)Independent🔒CenterFactual 85Objective 707 days ago
Weapons found near Berlin: sneak attack

The article reports on the discovery of two firearms in Berlin, which were likely intended for attacks. German authorities suspect foreign involvement, highlighting the country's heightened security threat. The piece emphasizes the complexity of modern threats, including cyberattacks, disinformation campaigns, and acts of terrorism. It underscores the need for vigilance and collective defense against hybrid threats, while noting that the discovery was made before the perpetrators could act.

Bias read (Center): While the article discusses a politically sensitive issue involving national security and potential foreign interference, it does not take a clear ideological stance. Instead, it presents the findings and concerns of German authorities in a balanced manner, emphasizing the need for caution without明显

Why factuality (85): The article references a weapon find in Berlin and links it to foreign involvement and hybrid threats, but does not directly mention the Berliner Landesnetz (BeLa) cyberattack. It implies a broader security threat environment but lacks specific details about the BeLa incident. The article aligns wit

Why objectivity (70): The tone is alarmist and emphasizes national security threats, suggesting a heightened sense of danger. While it presents information from official sources, it frames the situation in terms of external threats and national defense, which may be seen as biased towards emphasizing security risks over

Stern logoSternIndependentConservativeFactual 55Objective 407 days ago
Dobrindt: Weapons depot near Berlin was probably used for attacks

The article reports on a statement by Austrian politician Josef Dobrindt suggesting that a weapons cache located near Berlin was likely intended for use in attacks. The claim implies a potential threat to security in the region, though no specific evidence or details are provided to substantiate the assertion. The piece focuses on the implications of such a discovery and its possible connection to extremist activities. It does not elaborate on any official investigations or confirmations regarding the alleged purpose of the weapons cache.

Bias read (Conservative): The article frames the existence of a weapons cache near Berlin in a manner that suggests a potential threat, which aligns with conservative concerns about security and national defense. The emphasis on the possibility of these weapons being used for attacks reflects a narrative that prioritizes law

Why factuality (55): The article attributes the discovery of the weapons cache to 'Agenten' (agents) without specifying which country they belong to, though it later implies Russian involvement. It cites no primary sources but aligns with the broader narrative from other outlets. The claim that the weapons were intended

Why objectivity (40): The tone is sensationalist, using phrases like 'wohl für Anschläge dienen' (likely meant for attacks) which imply intent without evidence. The article lacks balance by not presenting alternative viewpoints or questioning the implications.

Tagesschau (ARD) logoTagesschau (ARD)State / PublicCenter11 hr. ago
Hackers demand ransom after attack on Berlin state network

On August 28, 2026, Berlin confirmed that it had received a ransom demand following a cyberattack on the city’s state network. The attack reportedly began at least a week earlier, with data leakage starting as early as August 7, a week before the breach was discovered. The attackers are believed to be known to the Senate, according to informed sources. Berlin’s Governing Mayor Kai Wegner stated that the city would not pay the ransom and emphasized that the attack constituted a serious criminal act. The incident has triggered investigations by the State Criminal Police Office and the Berlin Public Prosecutor’s Office, working closely with federal security agencies. While some parts of the network were isolated for security reasons, the Senate assured that critical election-related systems remained fully secure. The attack is described as the largest cyber incident experienced by the city to date.

Bias read (Center): The article presents factual information about a cyberattack on Berlin's state network, including confirmation of a ransom demand, the timeline of the breach, and responses from officials. It does not exhibit overtly biased language, one-sided sourcing, or omissions that would indicate a clear lean.

Die Welt logoDie WeltIndependent🔒Center15 hr. ago
Berlin state authorities: blackmailers demand ransom after hacker attack apparently two million euros demanded

The Berlin state authorities have fallen victim to a cyberattack, after which hackers demanded a ransom of approximately two million euros. The attackers are believed to have accessed sensitive data and are now threatening to release it unless their demands are met. This incident has raised concerns about cybersecurity within governmental institutions. The situation is under investigation, and authorities are working to determine the extent of the breach and whether any data has been leaked. The attack highlights vulnerabilities in digital security infrastructure and could lead to increased efforts to strengthen protections against such threats.

Bias read (Center): The article reports on a cyberattack targeting Berlin state authorities, focusing on the ransom demand and the ongoing investigation. It does not exhibit clear ideological framing, loaded language, or one-sided sourcing. The report appears balanced, presenting the event factually without apparent sl

Tagesschau (ARD) logoTagesschau (ARD)State / PublicCenter5 days ago
Berlin Senate offices are back online after hack

As of August 23, 2026, all Berlin administrative services have been restored after being disrupted by a cyberattack. Two Senate departments, those responsible for urban development, construction, housing, mobility, traffic, climate protection, and environmental affairs, were disconnected from the state network for several days due to security concerns following the attack on August 14. The Senate office stated that measures were taken to enhance IT security, and services previously restricted are now available again. However, some minor disruptions and delays might still occur, and forensic investigations into the incident continue.

Bias read (Center): The article presents a factual update on a cybersecurity incident affecting Berlin's administration without overtly criticizing or praising any political entity. It reports on the situation, the actions taken, and ongoing investigations without taking a clear ideological stance. The tone remains客观 (

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories