Berlin's city administration has confirmed a significant data breach by the Rhysida ransomware gang, which is now attempting to extort the city. Mayor Kai Wergner has firmly stated that no ransom will be paid to the cybercriminals.
- Rhysida ransomware group claims to have exfiltrated 5.79 TB of data (approx. 1.44 million files) from Berlin.
- Stolen data includes critical infrastructure security assessments for water supply and sensitive government records.
- The Berlin administration refuses to pay the ransom, opting for a full criminal investigation.
The city administration of Berlin has officially confirmed that it has fallen victim to a sophisticated cyberattack. The breach was first detected in mid-August, but the situation escalated on August 28 when the Rhysida ransomware gang publicly listed the city on its leak site, claiming to hold a massive trove of sensitive information.
The scope of the theft is staggering. The threat actors claim to have stolen 5.79 TB of data, comprising roughly 1.44 million files. This includes not only HR and financial records but also plaintext credentials and password vaults belonging to senior officials. Most alarmingly, the leak allegedly contains security assessments concerning Berlin's water supply and classified Bundesrat committee records.
Why This Matters
BozokMedia analysis shows that Rhysida is employing a 'pressure-cooker' strategy by leveraging GDPR violations to force the city's hand. By threatening to leak personal data of citizens and officials, they aim to bypass the government's typical refusal to pay. This incident highlights a critical vulnerability: once attackers obtain valid credentials, prevention rates drop significantly, as traditional security layers often fail to detect authenticated but malicious activity.
"The targeting of critical infrastructure assessments marks a shift from simple financial theft to potential strategic espionage and sabotage."
Forensic investigations revealed that data was likely exfiltrated from the Senate Department for Mobility, Transport, Climate Protection and the Environment between August 7 and 12. In response, the affected departments were severed from the state network on August 14. Despite the breach, Senator Iris Spranger confirmed that the technical environment for the upcoming House of Representatives election remains secure.
Rhysida has been a persistent threat since mid-2023, specializing in targeting healthcare, education, and state government entities. While the exact entry point for the Berlin attack remains undisclosed, previous campaigns by the group involved the use of malicious Microsoft Teams installers to gain initial access.
| Data Category | Specific Content | Risk Level |
|---|---|---|
| Administrative | HR, Payroll, Legal records | High |
| Infrastructure | Water supply security reports | Critical |
| Personnel | Senior official credentials | Severe |
Frequently Asked Questions
1. Will the city of Berlin pay the ransom?
No, Mayor Kai Wergner has explicitly stated that the city will not pay the attackers.
2. Is the upcoming election at risk?
No, officials have stated there is no evidence that election data was compromised.