CyberSecurity SEE

Rhysida Releases Berlin Government Data Following €2 Million Extortion Demand

Rhysida Releases Berlin Government Data Following €2 Million Extortion Demand

Berlin State Confirms Data Breach as Rhysida Ransomware Gang Publishes Stolen Information

In a significant cybersecurity incident, Berlin’s state government has confirmed that the Rhysida ransomware group has released stolen data on the dark web after the authorities refused to comply with an extortion demand. The ransomware gang had threatened to make public sensitive data unless the State of Berlin paid a ransom of 30 bitcoins, which equates to approximately €2 million. This ultimatum was set with a deadline of Friday, September 4.

The state government made it clear that it would not yield to such extortion attempts. In a detailed statement released on its official website on the day of the deadline, authorities indicated that the ultimatum presented by Rhysida had elapsed. Analysis by cybersecurity experts confirmed that the entire dataset claimed by the hackers had indeed been published online.

Rhysida’s claims included the assertion that they had accessed around 5.7 terabytes of sensitive information. The State of Berlin had previously issued warnings that the personal information of employees, as well as data of citizens and businesses, could be impacted as part of this breach. In the same announcement, the government noted that, as of now, there were "no indications" that the state network remained compromised, which offers some assurance to its citizens and stakeholders.

To manage the potential fallout from this data leak, IT forensic experts are currently examining the contents of the stolen dataset. The authorities have stressed the importance of thorough analysis and are committed to informing all potentially affected individuals once this process is completed. According to a statement from the Senate Chancellery, if specific individuals are identified during this analysis, they will be notified accordingly, adhering to legal frameworks and risk-based assessments.

In addition to the authorities’ efforts, Berlin citizens who discover that their personal information has been made public are encouraged to report this to law enforcement agencies. This proactive approach aims to mitigate any further repercussions from the breach and offers support to individuals who may be particularly vulnerable due to the exposure of their data.

Florian Hauer, the chief digital officer for the State of Berlin, emphasized the government’s stance against blackmail. He reassured the public, stating that the safety of both the State of Berlin’s employees and its citizens remains the top priority. This commitment signals the government’s determination to confront cyber threats head-on, regardless of the associated risks.

Sensitive State Disaster Plans and Personal Data Exposed

The situation escalated further when reports indicated that the leaked dataset included highly sensitive information, including state emergency plans concerning potential terrorist attacks and disaster scenarios. This confidential data was organized within a folder labeled "AG CBRN-Rahmenplanung," where "CBRN" refers to chemical, biological, radiological, and nuclear threats. The exposure of such vital state documents raises serious concerns about national security and the potential implications for public safety.

Moreover, Rhysida has claimed that the dataset contains personal information relating to tens of thousands of individuals. Among the compromised data are personnel files of state employees, which include absence lists, payroll records, and home addresses—an alarming breach of privacy that could affect numerous individuals.

Rhysida’s operations represent a growing trend in ransomware-as-a-service (RaaS) models, first appearing in the cybersecurity landscape in May 2023. This group has notably targeted public institutions and critical services, threatening the functionality of vital government sectors. They have been tied to a series of high-profile attacks on U.S. healthcare providers, including a significant breach at Cookeville Regional Medical Center in Tennessee in 2025, which compromised the data of over 337,000 patients.

Additionally, Rhysida affiliates have been implicated in major ransomware attacks, such as the one against the British Library in 2023, which suffered severe operational disruptions and incurred hefty recovery costs after refusing to meet the attackers’ demands.

The incident in Berlin not only highlights the complexities and dangers associated with modern cybersecurity threats but also underscores the resilience and resolve of government entities in the face of malicious cyber activities. The approach taken by state officials to stand firm against extortion attempts, coupled with their commitment to transparency and public safety, will likely influence how similar incidents are managed in the future. As the investigation continues and the ramifications of this breach unfold, the focus remains on protecting affected individuals and ensuring the integrity of the state’s cybersecurity measures moving forward.

Source link

Exit mobile version