Berlin defies data thieves and vows no ransom payment

Berlin refuses to pay after Rhysida-linked attackers exfiltrate data from the city's state network.

CSBadmin
2 Min Read

Berlin’s state government is refusing to pay after attackers breached its administrative network in August, with officials confirming an active extortion attempt and forensic teams still mapping the damage. The Senate Chancellery disclosed that additional data flowed out of the Mobility, Transport, Climate Protection and Environment department between August 7 and August 12, and it cannot rule out that personal records were among the haul.

The department first reported the outflow on August 7, a week before the city cut the network off on August 14. Berlin has not published an official figure for the loss. The only accounting comes from the attackers themselves: a leak-site entry indexed on August 28 claims 5.79 terabytes of data covering 12,076 individuals. Der Spiegel pinned the intrusion on the Rhysida ransomware group, citing the group’s darknet leak site and security sources involved in the response. Rhysida’s own site carried a “Berlin, Germany” listing by August 28, a fact verified through leak-site tracking the following day.

At a special Senate session, Governing Mayor Kai Wegner described the city’s position as one of being blackmailed. The state criminal police, the public prosecutor’s office, and federal security authorities are investigating, though no group has been officially named.

As of August 29, the Senate had published no guidance for residents whose records may be among the stolen data. Security teams should watch for phishing campaigns that leverage the stolen personal details, and affected agencies should treat the exfiltration window of August 7-14 as the boundary for credential rotation and forensic review.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.