When the state gets extorted, “cybercrime” is no longer the right label.

The Rhysida group attacked Berlin’s Senate administration and is threatening to publish internal data on the darknet. Berlin’s authorities, politicians and the press are treating the case as what it is on paper: a criminal offence.

Our founder and CEO Mirko Ross thinks that’s a mistake and explains why in his guest commentary for kes.

His argument: anyone who paralyses public administration, uses citizens’ data as leverage and deliberately erodes trust in the state is not running an ordinary extortion scheme. Publishing the data isn’t about Berlin alone – it’s a threat backdrop for every future victim who is supposed to pay. And it works, as long as the state responds with restraint.

Policing alone rarely reaches perpetrators who operate across borders.

Classifying these attacks as acts of terrorism would change that: intelligence-led investigation, exposure of financial flows, identification of enablers. In other words, the tools we already take for granted in counter-terrorism.

Not a comfortable proposal. But one worth debating.

Read the full guest commentary at kes – Magazine for Information Security (German):
https://www.kes-informationssicherheit.de/artikel/taeter-ausbremsen-staerke-zeigen/

P.S. Want to continue the conversation? Mirko Ross will speak at the DNS Conference during Security Essen on “Robotics and agentic AI: when machines act on their own – opportunities and risks”, covering attack vectors against AI agents and how companies can defend against them.

Cyberattack and Blackmail Against the Berlin Senate - Action Must Be Taken Now. Mirko Ross in kes Magazine
Konrad Buck

Konrad Buck

Head of Press and Media Relations

Background & Expert Access for Media

I provide journalists with access to in-depth background information beyond our public materials, including:
  • Product & technology insights – technical context, solution architecture, and real-world use cases for professional and trade media
  • Expert commentary & background talks – our CEO is available as an expert source on current cybersecurity developments, threat landscapes, and the impact of AI on security and regulation
Media contact
I speak openly, fact-based, and without PR spin. I am a former IT journalist with decades of experience in the IT and cybersecurity space, familiar with the highs and lows of the industry. Off-the-record discussions are possible upon request.