- Joined
- Apr 5, 2024
- Messages
- 155
- Points
- 28
Hackers stole data from Berlin government networks. Authorities refused to pay the ransom.
Hackers stole data from Berlin government networks. Authorities refused to pay the ransom.
Hackers claim to have exfiltrated nearly 6 terabytes of data from the Berlin state government networks. Authorities have no intention of paying the ransom.
Berlin Summer
The digital infrastructure of the Berlin state administration was subjected to a cyberattack, followed by extortion attempts. The capital's leadership stated that it does not intend to pay the hackers.The attack took place between August 7 and 12, 2026; the perpetrators, believed to be the APT group Rhysida, claim to have exfiltrated nearly 6 terabytes of data, containing the personal information of more than 12,000 people.
Ministry of Mobility, Transport, Climate Protection and the Environment of the Senate of the Federal State of Berlin.
bedneyimages by Magnific Hackers claim to have stolen nearly 6 terabytes of data from Berlin's government networks
The Senate Office stated that a leak of confidential data about citizens of the administrative unit cannot be ruled out. However, the agency did not provide any recommendations for the citizens themselves.
"Berlin is being blackmailed," Mayor Kai Wegner said after a special Senate meeting in the Rotes Rathaus.
The Senate office said in a statement that state criminal police, prosecutors and federal security agencies were investigating the alleged perpetrators, but did not name any suspects.
Der Spiegel, in turn, noted that it was Rhysida that published information about the attack on the Berlin administration on its leak site.
In their publication, the hackers announced that they were able to download approximately 1.44 million files with a total size of 5.79 terabytes.
The set includes eleven file categories, the largest of which contains 124,823 files. All of these contain geographic maps and geodata, accounting for about a quarter of the total number of files.
From Spot Pilots to the Agent Era: How AI is Transforming Russian Fintech Digitalization
Berlin first reported the incident on August 17, acknowledging a security breach in the government network. The resources of the affected agencies were isolated from August 14 to 23.
At a press conference on August 19, Mayor Wegner stated that the incident was being treated as very serious, but emphasized that, to his knowledge at the time, no confidential data had been stolen.
Now, apparently, the situation is viewed differently.
Interior Senator Iris Spranger, for her part, stated that the hackers did not obtain any data related to the September 20 elections to the Berlin House of Representatives, and that security officials consider the election environment to be secure.
Rhysida
The Rhysida ransomware group (Storm-0832 according to Microsoft) is characterized by its relative indiscriminateness in its targeting: since 2023, it has attacked approximately 280 organizations in the education, healthcare, manufacturing, IT, and government sectors. The ransomware itself is rented out using the RaaS model. Its operators have been repeatedly observed using legitimate system utilities and Windows administration tools (living off-the-land).To gain initial access, the attackers used several methods. First, they used valid accounts on externally accessible remote services. Using these, the attackers authenticated to the internal VPN services of the target organizations, where the credentials had already been compromised and multifactor authentication was absent. Second, they actively exploited the Zerologon vulnerability (CVE-2020-1472), which allowed for privilege escalation in Microsoft's Netlogon remote access protocol. Microsoft patched this "bug" back in August 2020.
Western giants are suing VMware over licensing policies, and risks are growing for Russian companies as well.
The third favorite method was the banal, but effective phishing.
"Ransomware, especially those using RaaS programs, rarely possesses any particular expertise and clearly prefers to use proven initial penetration methods," says Mikhail Zaitsev , an information security expert at SEQ. "And the problem is that these methods, being widely known and described many times, remain relevant in both the commercial and government sectors worldwide."

