Fraud Management & Cybercrime
,
Geo-Specific
,
Ransomware
Extortion Group With Suspected Russian Provenance Imposes Friday Deadline
Berlin officials temporarily canceled remote work and are scouring all their systems, after the notorious Rhysida ransomware gang attacked the German city-state in a double-extortion attempt that will come to some kind of conclusion this Friday.
See Also: Demostración Del Producto: Backup Y Recuperación De VM
The attack was detected on Aug. 14, and all departments of the Berlin Senate were immediately disconnected from their central network. Those affected in the attack were the departments for urban development, construction and housing – causing significant disruptions for those trying to claim housing benefits – and for mobility, transport, environment and climate protection.
Berlin mayor Kai Wegner, who withdrew a re-election bid in July, said initially that no sensitive data appeared to have been compromised. That assertion didn’t last long. By last Friday, following forensic investigations, Wegner admitted that public and non-public data may have been taken between Aug. 7 and Aug. 12, and that the attackers were trying to blackmail the Berlin government.
“The demand came in early on Thursday evening,” Wegner said. “Berlin will not give in to blackmail.”
According to multiple reports citing security officials and information on the darkweb, and with confirmation from the Berlin Senate on Tuesday, the culprit was Rhysida, a prolific outfit that often targets organizations in the United States. Multiple American healthcare providers have fallen victim although a Ransom-DB analysis in February found that almost half of its known attacks landed elsewhere in the world, with Europe featuring strongly.
Rhysida employs the now-standard tactic of double extortion, threatening leaks and the ongoing encryption of data on the victim’s systems. It targeted the German city of Stuttgart in May of this year, demanding 5 bitcoin in payment for data it claimed to have stolen, although neither the theft nor any ransom payment have been publicly confirmed.
This time, the groups wants 30 bitcoins from Berlin, and says it will publish the data if it doesn’t get the cryptocurrency by this coming Friday. Rhysida is running an auction until then, claiming that it will only give the data to one buyer.
According to Rhysida, the group claims to have 5.79 terabytes of Berlin Senate data, including 16,389 emails, 11,963 phone numbers, 148 banking codes, tens of thousands of contracts and judicial documents, and thousands of personnel files containing more personal data.
Rhysida also says it took credentials that had been stored in plaintext, along with classified materials and vulnerability analyses of Berlin’s water supply.
Berlin Senate spokeswoman Christine Richter reiterated at a Tuesday press conference that the city would not cough up. She said a “significant amount of data” – some of it non-public – had been compromised at the two departments, but so far there was no evidence of any other departments being affected. Still, just to make sure, “all systems within the state of Berlin must be scanned to rule out the possibility that further data has been exfiltrated.”
She said there are 12,000 such systems that need to be examined, though all the systems at the two affected departments have already been checked. Richter’s office did not respond to a request for information regarding how long all of this might take.
On Tuesday, Richter also appeared to confirm Rhysida’s claim scoring credentials, explaining that passwords for “certain specialized applications” had been compromised, with the result that the two affected departments have “decided to implement additional security measures” that have resulted in “some operational restrictions, though both departments remain reachable by email.”
The Berlin newspaper Tagesspiegel reported sources in the departments as saying their home office access had been shut off on Monday – they can send and receive emails, but they can’t establish VPN access to their internal networks, forcing them to work from their computers in the office. Richter confirmed this to the paper.
Tagesspiegel reported earlier in the week that snippets of the stolen data showing unencrypted login details had been helpfully stored in files with names like Password.docx, and that the passwords themselves included the likes of “Sunshine13” – not compliant with the recommendations of the Federal Office for Information Security, it noted.
As for what will happen if Berlin sticks to its guns and withholds payment, Rhysida has a history of making good on its threats. In 2023, after the British Library refused to pay the group 20 bitcoin, it published around 600 gigabytes of the stolen files, including staff details that reportedly forced some to move home.
The Berlin Senate is adamant that the coming state election on Sept. 20 will not be affected by the hack. “The election environment is secure, according to our security officers,” said Interior Senator Iris Spranger.
It remains unclear where Rhysida is based, although previous analyses have hinted at a connection with Russia and its satellites. The cybersecurity firm Cynet noted in 2023 that Rhysida’s ransomware software, ransom notes and leak site sometimes included snippets of Russian, and the group conspicuously avoided targeting organizations in Russia and other post-Soviet states. And, of course, Russia has been stepping up sabotage and drone attack efforts in Germany in the last year or two, due to Germany’s support for Ukraine – on Tuesday the government accused Russia of waging hybrid war.
“There is no evidence of connections to Russia or even the Russian state” in the Berlin hack, Richter told the Berliner Morgenpost on Tuesday, “but such connections cannot be ruled out.”
Click Here For The Original Source.
