HomeMalware & ThreatsBerlin Rejects Rhysida Ransomware Blackmail

Berlin Rejects Rhysida Ransomware Blackmail

Published on

spot_img

Extortion Group With Suspected Russian Provenance Imposes Friday Deadline

In a chilling turn of events, Berlin officials have found themselves grappling with a serious cybersecurity crisis following an attack by the notorious Rhysida ransomware gang. This incident has culminated in a pressing ultimatum, with the group demanding a significant ransom by Friday. The city’s administration has responded by temporarily canceling remote work and intensifying scrutiny of all their systems.

The attack was first identified on August 14, prompting immediate action from the Berlin Senate, which disconnected all departments from their central network. A number of key departments were specifically targeted, including those responsible for urban development, construction, housing, mobility, transport, and environmental protection. This resulted in severe disruptions, particularly for residents attempting to access housing benefits.

Initially, the mayor of Berlin, Kai Wegner, attempted to reassure the public, declaring that no sensitive data seemed to have been compromised. However, by the following Friday, further forensic investigations revealed a more troubling scenario. Wegner admitted that both public and non-public data could have been compromised between August 7 and August 12, with your prominent blackmail attempt directed at the Berlin government.

“The demand came in early on Thursday evening,” Wegner stated firmly. “Berlin will not give in to blackmail.”

Reports from various information sources, including the dark web, confirmed suspicions that the Rhysida group was responsible for this attack. This organization has gained notoriety for targeting entities in the United States, with numerous American healthcare providers having suffered previous assaults. Interestingly, however, a Ransom-DB analysis indicated that almost half of Rhysida’s known attacks impacted locations outside of the United States, with Europe being a significant target.

Rhysida employs a strategy of double extortion, which involves threats of data leaks alongside ongoing encryption of a victim’s data. The group had previously targeted Stuttgart in May, demanding a ransom of 5 Bitcoin for stolen data, though no confirmation of the theft or ransom payment has emerged.

In the current attack, the ransom demanded by Rhysida has escalated to 30 Bitcoin, with a direct threat to publish sensitive data if payment is not made by the looming Friday deadline. Furthermore, the gang claims to have secured an extensive cache of data totaling 5.79 terabytes from the Berlin Senate, which includes over 16,000 emails, nearly 12,000 phone numbers, and hundreds of banking codes, along with numerous contracts and judicial documents.

In addition to these, Rhysida asserts that it has accessed plaintext-stored credentials and classified materials that include vulnerability assessments concerning Berlin’s water supply – a particularly concerning revelation.

Christine Richter, a spokesperson for the Berlin Senate, voiced the administration’s stance during a press conference, reaffirming that the city will not succumb to the extortion. She acknowledged that while a "significant amount of data" had been compromised, there was no evidence to suggest that other departments were affected. However, as a precaution, all Berlin’s systems must be thoroughly examined to ensure that no additional data has been exfiltrated.

In her remarks, Richter noted that about 12,000 systems require scrutiny, although systems within the affected departments had already undergone checks. She did not comment on the timeline for completing this extensive assessment. Further investigation revealed that passwords for numerous "specialized applications" had been compromised, prompting the departments to implement additional security measures, which resulted in operational restrictions but did not compromise email accessibility.

Reports indicate that, in light of the attack, remote work access for employees of the affected departments was halted. While employees can still send and receive emails, access to VPN connections for internal networks has been severed, compelling them to work from their in-office computers.

It was also reported that the hackers had carelessly stored snippets of the stolen data in files labeled with titles like “Password.docx,” which contained unencrypted login credentials. Some of these passwords notably included simple phrases like “Sunshine13,” which do not comply with security standards recommended by Germany’s Federal Office for Information Security.

Considering the potential repercussions if the city maintains its refusal to pay the ransom, industry experts note that Rhysida has a history of following through on threats. An earlier incident in 2023 revealed that after the British Library declined to meet a ransom demand, the group published around 600 gigabytes of stolen files, compromising the personal details of numerous staff members.

Despite the gravity of the situation, the Berlin Senate has stated that the scheduled state election on September 20 would proceed unaffected. Nevertheless, Interior Senator Iris Spranger assured the public that security officers had assessed the election environment as secure.

The precise origins of Rhysida remain unclear, although analyses have suggested possible links to Russia and its geopolitical sphere. Cybersecurity firm Cynet pointed out that the group’s ransomware software, as well as communications and leak site language, often contained snippets of Russian. Furthermore, Rhysida seems to deliberately refrain from targeting organizations within Russia or post-Soviet states, raising further speculation.

In a recent statement to the Berliner Morgenpost, Richter maintained that no concrete evidence had been uncovered connecting the hackers to Russia or the Russian state, albeit acknowledging that such ties cannot be conclusively dismissed. As geopolitical tensions rise, particularly in the wake of Russia’s actions in Ukraine, cybersecurity experts remain vigilant, highlighting the complex and evolving landscape of cyber threats facing governmental entities.

Source link

Latest articles

Gambling Goblin Transforms Brazilian Government Websites into SEO Tools

Cybercrime Outfit Exploits Brazilian Government Websites for SEO Fraud In a significant security breach, a...

Global Public-Private Initiative Disrupts Russia-Linked Sality Botnet

Cybercrime, Fraud Management & Cybercrime US, European Law Enforcement, Cyber Firms Target Two-Decade-Old...

Exploited JFrog Artifactory Vulnerability Raises Alarms in Software Supply Chain

Critical Vulnerability in Artifactory: Urgent User Upgrades Recommended A serious security vulnerability has been uncovered...

Russian Man Extradited for Malware Campaign Targeting Freelancers

A Russian national has faced extradition to the United States amid serious accusations surrounding...

More like this

Gambling Goblin Transforms Brazilian Government Websites into SEO Tools

Cybercrime Outfit Exploits Brazilian Government Websites for SEO Fraud In a significant security breach, a...

Global Public-Private Initiative Disrupts Russia-Linked Sality Botnet

Cybercrime, Fraud Management & Cybercrime US, European Law Enforcement, Cyber Firms Target Two-Decade-Old...

Exploited JFrog Artifactory Vulnerability Raises Alarms in Software Supply Chain

Critical Vulnerability in Artifactory: Urgent User Upgrades Recommended A serious security vulnerability has been uncovered...