Berlin Refuses Ransom, Hackers Dump 6TB of State Files Online – SOFX | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The Rhysida ransomware group published nearly six terabytes of data stolen from Berlin’s state administration on the dark web after the German capital refused to pay a 30-bitcoin ransom, worth about $2.3 million. The files went live on September 4, when the group’s extortion countdown expired.

Rhysida claims the dump holds 1,439,893 files taken from the Berliner Landesnetz, the shared network linking roughly 600 government sites across the city. A September 6 review by Berlin newspaper Der Tagesspiegel has so far cataloged at least 755,121 files in the published set, about half the claimed total, showing how far verification still trails the attackers’ own accounting.

The most sensitive material is the content. Researchers identified a folder labeled “AG CBRN-Rahmenplanung,” German planning documents for chemical, biological, radiological, and nuclear threat scenarios. Rhysida’s leak-site inventory also lists 8,110 infrastructure files it says include vulnerability assessments of Berlin’s water supply, and 5,941 files described as holding passwords, some in plaintext. The Chaos Computer Club, Germany’s largest hacker association, confirmed the water-supply material after reviewing part of the data.

Berlin’s government has neither confirmed nor denied Rhysida’s specific figures. In a September 5 statement, the State of Berlin’s press office said the files are being analyzed with utmost urgency and that any critical facility found to be at risk would be alerted without delay.

The decisive failure came before the leak. State Secretary for Digital Affairs Florian Hauer said the intrusion ran from August 7 to August 12, and that Berlin detected an unusual data outflow on August 7 but did not disconnect the two affected Senate departments from the central network until August 14. That seven-day interval handed the attackers their full working window.

A joint advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Multi-State Information Sharing and Analysis Center describes Rhysida’s method as mapping and moving through a network before staging data for theft. Berlin’s gap sits inside that pre-theft phase. Security firm Sophos measured the median time from initial access to payload at four days in 2025, meaning the city’s containment lag exceeded the industry’s worst-case benchmark. During the shutdown that followed isolation, housing-benefit payments were suspended for more than 50,000 households.

Governing Mayor Kai Wegner and Interior Senator Iris Spranger said the state would not be blackmailed. Spranger said systems supporting Berlin’s September 20 state election are isolated from the compromised network and were not affected.

Rhysida’s refusal-and-release pattern is documented. The group published the British Library’s stolen data in 2023 after that institution declined to pay. Researchers assess that Rhysida operates from Russia or the former Soviet sphere, citing Russian-language communications and a targeting policy that spares organizations in those states.

A second dispute has opened over the response. Berlin’s Senate Chancellery hired U.S. firm CrowdStrike to sweep district systems with its Falcon tool for any trace Rhysida left behind. The Lichtenberg district is refusing the vendor access, arguing in an internal letter obtained by broadcaster rbb that the software would gain near-unlimited reach into its data and prove impossible to remove. The Chancellery told the district that Falcon is the only option and that the Senate will cover the costs.

Germany’s Federal Office for Information Security has warned of an elevated cyber threat level following the leak. Berlin’s forensic review remains ongoing, and no date has been set for notifying the individuals whose records the attackers claim to hold.

——————————————————–


Click Here For The Original Source.

.........................