The Berlin government is facing a cybersecurity crisis following the attack on its administrative network in August. The ransomware group Rhysida, which is attributed with the attack, claims to have stolen a large amount of details belonging to public bodies in the German capital and is now threatening to sell this data if the authorities do not pay the demanded ransom.
The response from the Berlin executive has been decisive. The mayor of Berlin, Kai Wegner, and the senator for the Interior and Sports, Iris Spranger, have assured that the administration is not willing to give in to the cybercriminals’ demands. “The State of Berlin will not be blackmailed,” they jointly stated last Friday.
According to the official statement released by the Press and Information Office of the State of Berlin, the Berlin State Criminal Police, the Public Prosecutor’s Office, and federal security authorities are working together to identify the perpetrators and determine which aspects have been compromised.
Rhysida claims to have obtained 5.79 terabytes of data from various Berlin agencies. Among the information the attackers claim to have stolen are about 46,500 contracts, as well as emails, phone numbers, passwords, and documents they classify as classified information.
The group claims it intends to start auctioning the data in approximately seven days, with a starting price of 30 bitcoins. The page used by Rhysida would also show a countdown to the supposed auction.
What happened
Forensic investigations carried out by the authorities have determined that new leaks occurred in Berlin’s state network between August 7 and 12.
The incident affected, among other systems, the infrastructure of the Senate Department for Mobility, Transport, Climate Protection, and the Environment. Systems of the Senate Department for Urban Development, Construction, and Housing were also affected.
The network disruption occurred on August 14, after the leaks detected by investigators had already taken place.
The Berlin government acknowledges that it cannot be ruled out that the affected information includes personal data and other data that is not of a public nature.
The executive maintains an active emergency task force for information and communication technologies while both forensic investigations and the analysis of the state network continue.
The incident also has a particularly delicate political dimension. Berlin’s state elections are scheduled for September 20, just a few weeks after the attack.
Rhysida, behind the attack
The Rhysida group has publicly claimed responsibility for the attack. It is a well-known ransomware operation whose origin could be in Russia or Eastern Europe linked to numerous incidents against public and private organizations. It was born in 2023, and since then, more than 300 violations have been attributed to it.
Among its most notable victims are the British Library and Insomniac Games. The group has also used leak sites on other occasions to threaten to publish stolen information when victims refuse to pay.
The strategy is now being repeated with Berlin: public pressure, a supposed countdown, and the threat of turning the stolen data into a new source of income through an auction.
