Berlin’s state government has confirmed that hackers are attempting to extort the city following the August compromise of its state administrative network, but officials say they will not pay the attackers.
A forensic investigation has also uncovered additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment. According to the Senate Chancellery, the newly identified data exfiltration occurred between August 7 and August 12, several days before the department was disconnected from the network on August 14.
Officials are still investigating the scope and nature of the stolen information. They have warned that personal information and other non-public data could be among the material taken from the network.
Berlin has not disclosed how much data was actually removed. However, a leak-site post attributed to the ransomware group Rhysida claims that 5.79 terabytes of data, covering around 1.44 million files, were obtained. The post also claims that information relating to 12,076 individuals was included.
The Berlin Senate has not independently confirmed those figures. The leak-site listing, which appeared on August 28, identifies the victim simply as Berlin, Germany and does not state a ransom amount. One of the largest categories listed consists of 124,823 maps and geodata files.
Governing Mayor Kai Wegner confirmed that Berlin is being blackmailed following a special Senate meeting at the Rotes Rathaus. The Senate Chancellery said state criminal police, prosecutors and federal security authorities are investigating the attack, but officials have not publicly attributed it to a specific group.
Rhysida has been identified as the suspected group behind the attack by German media and monitoring services. A monitoring service confirmed that an entry titled “Berlin, Germany” appeared on Rhysida’s leak site on August 28.
U.S. cybersecurity agencies have previously warned that Rhysida can gain access through compromised accounts on external-facing remote services, including VPN systems, particularly when multi-factor authentication is not enabled. The group has also been linked to attacks exploiting the Zerologon vulnerability, CVE-2020-1472, as well as phishing campaigns.
A joint advisory from the Cybersecurity and Infrastructure Security Agency, the FBI and the Multi-State Information Sharing and Analysis Center recommends organizations prioritize patching known exploited vulnerabilities, enable multi-factor authentication and segment networks to limit the spread of ransomware.
The agencies also discourage victims from paying ransom, noting that payment does not guarantee that stolen data will be recovered or deleted and could encourage further attacks.
The monitoring service listed 280 Rhysida victims worldwide as of August 29, including nine organizations in Germany. Previous victims include the Stuttgart city administration and the aid organization Welthungerhilfe.
Berlin’s data protection commissioner and the Federal Office for Information Security are being kept informed as the investigation continues. Interior Senator Iris Spranger said that, based on current findings, no data connected to the September 20 Abgeordnetenhaus election had left the relevant areas of the network and that security officials consider the election environment secure.
Berlin first publicly disclosed the cyberattack on August 17, stating that forensic analysis had confirmed a compromise of the state network. The affected departments had already been isolated from the network at that point.
The incident temporarily disrupted services including housing benefit applications and payments. All Senate departments were reconnected on August 23, while forensic investigations and network scanning remain ongoing.
In a separate incident in the U.K., Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, confirmed that an unauthorized third party obtained customer information connected to car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi registrations.
MAG said the incident did not compromise passenger safety or aviation security and that airport operations and parking services continue normally. The company said the accessed information includes email addresses, phone numbers, vehicle registration numbers and postcodes.
The company said the affected system does not contain customers’ bank or payment information and is separate from its operational airport systems.
As of August 29, MAG had suspended its online Manage My Booking service as a precaution. Customers with bookings within the following 72 hours were directed to contact customer services for changes.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Reports have suggested that around 8.7 million customers may be affected, based on comments from a company spokesperson, although MAG has not included an official figure in its published customer information.
MAG said it has contacted affected customers directly and advised them to remain alert for suspicious emails, text messages and phone calls following the data theft.
Berlin Refuses Hackers’ Ransom as Data Theft Expands





