HomeMalware & ThreatsBerlin Declines to Compensate Hackers for Stolen Data from State Network

Berlin Declines to Compensate Hackers for Stolen Data from State Network

Published on

spot_img

Berlin Confirms Target of Extortion Following Cyber Attack

The state government of Berlin has formally acknowledged that it is currently facing an extortion attempt following a significant compromise of its state administrative network, which occurred in August. Officials have made it explicit that they will not concede to the demands of the extortionists. This declaration comes as the city continues to grapple with the implications of the breach.

In a recent statement, authorities disclosed that forensic investigations have unearthed additional data outflows originating from the Senate Department for Mobility, Transport, Climate Protection, and Environment. This data leakage is reported to have taken place between August 7 and August 12, 2026, although the scope and content of the data exfiltration are still under thorough examination. The Senate Chancellery has not ruled out the possibility that personal or other sensitive information may have been accessed during this breach.

The initial report of data outflow was communicated on August 7, just one week before the network was effectively severed on August 14. To date, the Berlin government has not specified how much data has been compromised. However, details have emerged from the attackers themselves. A post indexed on a leak site on August 28 claimed that 5.79 terabytes of data, including personal information belonging to over 12,000 individuals, had been stolen.

In light of the crisis, Governing Mayor Kai Wegner expressed concern during a special Senate session held at the Rotes Rathaus. He stated in a statement that “the state of Berlin is being blackmailed,” emphasizing the severity of the situation. Legislative discussions have brought to light an absence of guidance for individuals whose personal information might be at risk as of August 29.

The Senate Chancellery has confirmed that an extensive investigation has been launched, involving the state criminal police, public prosecutor, and federal security agencies to track down the alleged attackers. However, no specific group has been identified as responsible for the breach. Notably, the group Rhysida has been linked to this event by the publication Der Spiegel, which indicated that information was sourced from the group’s darknet leak site. The Hacker News corroborated that a listing titled “Berlin, Germany” appeared on Rhysida’s site on August 28.

The leaked information allegedly encompasses 5.79 terabytes consisting of approximately 1.44 million files. The attackers did not disclose a ransom amount in their publication, but they categorized the data into eleven file types, with a noteworthy emphasis on 124,823 maps and geodata files, accounting for a significant portion of the total.

In an effort to safeguard networks against such breaches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI and the Multi-State Information Sharing and Analysis Center (MS-ISAC), issued guidance detailing the tactics employed by the Rhysida group. The advisory outlined specific vulnerabilities exploited, including the use of valid accounts on external remote services, a critical elevation of privileges vulnerability known as Zerologon (CVE-2020-1472), and phishing strategies.

This advisory underscores that neither the FBI nor CISA encourages the payment of ransom due to the lack of guarantee of data recovery, which may further encourage malicious entities to target organizations. The recommendations provided stress the importance of remediating known vulnerabilities, enabling multi-factor authentication (MFA), and segmenting networks to curb the potential spread of ransomware.

As of August 29, monitoring services identified a total of 280 victims of the Rhysida group, nine of which are located in Germany. Among them are the Stuttgart city administration, which fell victim to a breach in May 2026, and the aid organization Welthungerhilfe, targeted in June 2025. Notably, the Port of Seattle was also affected, being indexed in September 2024.

The Senate Chancellery has committed to maintaining communication with Berlin’s state data protection commissioner and the Federal Office for Information Security (BSI) throughout this incident. Despite the serious nature of the breach, Interior Senator Iris Spranger assured the public that no relevant data related to the September 20 Abgeordnetenhaus election had been compromised and that the election environment remains secure.

This cyber incident, first reported on August 17, revealed that forensic investigations had confirmed the compromise of the state network. It was disclosed that affected departments had been isolated since the previous Friday to prevent further data loss. Following this incident, housing benefit applications and payments were temporarily disrupted as the two involved departments were taken offline. Nevertheless, all Senate departments were successfully reconnected to the network by August 23, although forensic investigations and ongoing scanning efforts are still in process.

Manchester Airports Group Faces Data Breach

In a separate yet related incident, the Manchester Airports Group (MAG), which oversees operations at Manchester, London Stansted, and East Midlands airports, has confirmed a data breach affecting customer data. On August 27, MAG announced that an unauthorized third party had obtained sensitive information related to car park bookings, lounge access, and in-airport Wi-Fi sign-ups.

A spokesperson for MAG assured that “at no point has passenger safety or aviation security been compromised.” Operations at the airports continue as normal, reinforcing their commitment to security. The nature of the data leaked includes email addresses, phone numbers, vehicle registrations, and postcodes, although MAG clarified that bank or payment details were not accessed.

As of August 29, access to the online Manage My Booking service was suspended as a precaution. An estimated 8.7 million customers were reported to be impacted, based on statements from company spokespeople. MAG has proactively reached out to affected customers and has directed them to the U.K. National Cyber Security Center’s guidance on data breaches.

Collectively, these incidents underscore the growing threats posed by cybercrime and the critical importance of robust cybersecurity measures in protecting sensitive information across various sectors.

Source link

Latest articles

Polymorphic Phishing Attack Creates Unique Credential-Stealing Page with Each Visit

A recent analysis has revealed a sophisticated phishing operation utilizing server-side polymorphism, which enables...

Hackers Exploiting Pre-Auth RCE Vulnerability in PaperCut Print Software

Attackers Exploit Critical Vulnerability in PaperCut Print Management Software Security researchers from Huntress have confirmed...

Android 17 Introduces Enhanced Network Security Protections

Google Enhances Network Security in Android 17 In a significant move to bolster user privacy,...

More like this

Polymorphic Phishing Attack Creates Unique Credential-Stealing Page with Each Visit

A recent analysis has revealed a sophisticated phishing operation utilizing server-side polymorphism, which enables...

Hackers Exploiting Pre-Auth RCE Vulnerability in PaperCut Print Software

Attackers Exploit Critical Vulnerability in PaperCut Print Management Software Security researchers from Huntress have confirmed...