started · updated
Berlin administration suffers massive data breach by Rhysida ransomware group
The ransomware group Rhysida has published approximately 1.4 million stolen files following a cyberattack on the Berlin administration. The breach occurred between August 7 and August 14, reportedly initiated via a phishing email responded to by an employee of the German Transport Administration.
Berlin Mayor Kai Wegner refused to pay a ransom of 30 bitcoins, valued at approximately two million euros, stating that the city “will not be extorted.” In response to the refusal, the hackers released the data on the dark web. The stolen information includes personal files, payroll records, scanned identity documents, and official correspondence.
Experts from the Chaos Computer Club have warned that the leak could facilitate identity theft and other crimes. There are concerns regarding the exposure of sensitive data related to critical infrastructure, including thermal power plants, fuel depots, emergency electrical supplies, prisons, and water supply facilities. Additionally, documents related to chemical, biological, radiological, and nuclear (CBRN) planning were identified among the leaked files.
The regional government has ordered employees to change passwords and established a coordination office to manage the response, seeking assistance from the Federal Office for Information Security. While the Berlin police union criticized the administration for insufficient long-term system protection and inadequate employee training, electoral authorities confirmed the attack will not affect the upcoming September 20 elections for the Berlin House of Representatives.
Entities
Berlin Administration · Chaos Computer Club · Federal Office for Information Security · Kai Wegner · Rhysida