Illustration of Berlin's Rotes Rathaus with a digital lock or shield overlay, symbolizing a cyberattack on the city's network.

Berlin Defies Hackers: City Refuses Ransom After Major Data Breach

Share
Share

Berlin’s state government has declared a firm stance against cyber extortionists, confirming it is the target of a significant blackmail attempt following a sophisticated compromise of its administrative network. The city has unequivocally stated it will not yield to the hackers’ demands, even as forensic investigations uncover further data exfiltration.

A Digital Heist: The Scope of the Breach

The cyberattack, which first came to light in August, saw a major data outflow from the Senate Department for Mobility, Transport, Climate Protection and Environment. Investigations have pinpointed the exfiltration period between August 7 and August 12, 2026. While the full scope and content of the stolen data are still under examination, the Senate Chancellery has not ruled out the possibility of personal or other non-public information being compromised.

The department initially reported an outflow on August 7, a week before it was disconnected from the network on August 14. Although Berlin authorities have refrained from disclosing the exact volume of data stolen, the attackers themselves have made bold claims. A leak-site post, indexed on August 28, alleges the theft of a staggering 5.79 terabytes of data, including personal information pertaining to 12,076 individuals. The post further details approximately 1.44 million files, with a significant portion comprising 124,823 maps and geodata files.

Despite the gravity of the situation, official communications from the Senate as of August 29 had not yet provided specific guidance for individuals whose data might be affected.

Unwavering Resolve: Berlin’s Official Stance

Governing Mayor Kai Wegner minced no words following a special Senate session at the Rotes Rathaus. “The state of Berlin is being blackmailed,” Wegner stated, underscoring the city’s determination not to capitulate. The Senate Chancellery confirmed that the state criminal police, public prosecutor, and federal security authorities are actively investigating the suspected perpetrators.

Unmasking the Perpetrators: The Rhysida Threat

While official sources initially refrained from naming the attackers, German publication Der Spiegel, citing security sources, attributed the attack to the notorious Rhysida ransomware group on August 28. This attribution was subsequently corroborated by The Hacker News via a leak-site monitoring service, confirming an entry titled “Berlin, Germany” on Rhysida’s darknet site.

Rhysida’s Modus Operandi

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have previously detailed Rhysida’s typical tradecraft in a joint advisory issued in November 2023. Their common initial access vectors include:

  • Exploiting valid accounts on external-facing remote services, often leveraging compromised credentials where multi-factor authentication (MFA) is absent.
  • Utilizing Zerologon (CVE-2020-1472), a critical elevation of privileges vulnerability in Microsoft’s Netlogon Remote Protocol, patched in August 2020.
  • Successful phishing campaigns targeting victim networks.

The advisory explicitly warns against paying ransoms, emphasizing that it offers no guarantee of data recovery and may only embolden cyber adversaries.

Global Cybersecurity Warnings and Best Practices

In the wake of Rhysida’s double extortion attacks, cybersecurity agencies globally advocate for robust defensive measures. Key recommendations include:

  • Prioritizing the remediation of known exploited vulnerabilities.
  • Implementing multi-factor authentication across all services.
  • Segmenting networks to contain potential ransomware spread.

Notably, open-source intelligence has also highlighted similarities between Rhysida and Vice Society (tracked by Microsoft as Storm-0832), suggesting a potential overlap in their operations, a connection also noted by Check Point in 2023.

Wider Impact and Election Security Assurances

Rhysida’s reach extends far beyond Berlin. As of August 29, a monitoring service listed 280 victims globally, with nine in Germany alone. Past targets include the Stuttgart city administration (May 2026) and the aid organization Welthungerhilfe (June 2025), as well as the Port of Seattle (September 2024).

Despite the breach, Interior Senator Iris Spranger has reassured the public that no data relevant to the upcoming September 20 Abgeordnetenhaus election was compromised. Her security officers maintain that the election environment remains secure. Berlin’s state data protection commissioner and the Federal Office for Information Security (BSI) are being continuously informed about the incident.

Governing Mayor Kai Wegner, speaking at an August 19 press conference, reiterated the seriousness of the incident, emphasizing the ongoing efforts to understand and mitigate its impact.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *