Berlin hackers publish stolen data after city refuses to pay ransom | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The deadline for payment of a €2 million ($2.3 million) ransom to hackers who stole data from Berlin’s state government expired on Friday, resulting in the release of masses of sensitive information on the dark web.

The blackmailers had set up a countdown on their leak site, which expired at around 3.35 pm (1335 GMT).

The group known as Rhysida then carried out their threat to publish the data package – amounting to around 5.8 terabytes – on the dark web.

“All files have been uploaded to the publicly accessible section – have fun browsing, data hunters!’, the blackmailers’ website site stated when their ‘auction’ on the dark web ended.

How much was actually released is yet to be ascertained by cybercrime investigators.

The around 1.44 million illegally obtained files are said to include not only more than 5,000 personnel files, fine proceedings and payslips, but also confidential documents from parliamentary committees and vulnerability analyses of Berlin’s drinking water supply.

The blackmailers had previously boasted of having obtained login details and passwords in plain text – including for administrative databases and payment service providers.

The Berlin state administration had previously confirmed the cyberattack, which came to light on August 14.

The hackers had demanded a ransom of 30 bitcoin, equivalent to around €2 million. The city state executive had previously reiterated that, as a matter of principle, it would not give in to extortion and would not pay.

Experts praised refusal to pay up

The city’s refusal to give in to the attempted blackmail met with approval from experts. Bianca Kastl from the Chaos Computer Club told public broadcaster RBB Inforadio that the decision was the right one.

“If these groups were to continue receiving support in the form of money or other resources, they would, of course, carry on,” she said. “We must cut off their financial lifeline.”

Prominent IT security expert Christof Fischer noted that, by law, the state is not permitted to make payments in response to blackmail.

However, the situation in cases such as the one in Berlin is very difficult, he said: “The data is in the hands of criminals, and in many cases, its publication has very damaging consequences. So far, I am not aware of any case where a payment was made and the data was published anyway.”

It is reasonable to assume that the perpetrators, who are thought to mostly reside in Eastern European countries, made this data available to the authorities there to buy protection from investigations against themselves, Fischer told dpa.

Investigators from the State Criminal Police Office (LKA) and the Federal Office for Information Security (BSI) are involved in analysing and managing the incident.

Should the data package be made public in its entirety, the authorities concerned, as well as thousands of citizens and employees, face significant data protection and security risks.



Click Here For The Original Source.

——————————————————–

..........

.

.