Berlino sotto estorsione: sottratti dati dalla rete statale, il governo rifiuta il riscatto
Ransomware

Illustrative image generated with AI

Berlin Under Extortion: Data Stolen from State Network as Government Refuses to Pay Ransom

Berlin confirmed data theft from two ministries in a cyberattack and refused to pay ransom. Rhysida claims 5.79TB stolen, unverified by officials.

Text generated by artificial intelligence, published without human review. AI transparency

Data Stolen from Two State Ministries

The Berlin state government has confirmed that a cyberattack against its administrative network resulted in data theft. The attackers also issued an extortion demand, which the city does not intend to meet.

The position was stated on Friday by Governing Mayor Kai Wegner: Berlin will not pay the ransom. Authorities are still working to determine what information was actually stolen and who may be affected.

The incident involved two government bodies:

  • the ministry responsible for urban development, construction and housing;
  • the ministry responsible for mobility, transport, climate protection and the environment.

The two ministries share part of their IT infrastructure and independently administer their respective sections of the state network. The public-sector IT provider ITDZ Berlin, however, does not appear to have been compromised.

According to the available reconstruction, the data may have been accessed between August 7 and 12. The intrusion was discovered in mid-August, and on August 14 Berlin isolated the affected systems from the rest of the state network.

This segmentation limited the possibility of further lateral movement, but it had immediate operational consequences.

Rhysida Claims 5.79 Terabytes, but the Figures Are Unverified

Around the same time, the Rhysida ransomware group listed Berlin on its dark-web leak site. However, the claim does not constitute official attribution.

Berlin authorities have not confirmed that Rhysida was responsible for the intrusion. They have also not verified the quantity or nature of the files advertised by the group.

Rhysida claims to have stolen 5.79 terabytes of government information. The announcement refers to:

  • 46,500 contracts;
  • email messages;
  • telephone numbers;
  • passwords;
  • classified documents or information.

The material was offered for auction with a starting price of 30 bitcoin, which the extortionists described as equivalent to approximately $2.3 million. The listing also displayed a countdown of approximately seven days.

These details should be treated with caution. Ransomware groups have a direct interest in exaggerating the volume, sensitivity and value of stolen data in order to increase pressure on the victim and attract potential buyers.

The confirmed facts are more limited: Berlin acknowledges that data was exfiltrated and that a monetary demand was received. The volume of the theft, the presence of classified information and the actual exposure of the passwords mentioned by Rhysida remain to be verified.

The possibility that personal data or other non-public information was involved has not been ruled out.

Isolation Disrupted Routine IT Services

After the intrusion was discovered, the systems used by the two ministries were disconnected from the wider state network. The offices continued to operate, but they could no longer use essential services such as email and Internet access normally.

Some staff had to rely on telephone calls, SMS and fax. The measure illustrates how the consequences of an incident can also depend on containment activities, not only on whether computers are encrypted.

It is not known whether Rhysida encrypted systems or files in this case. The group typically uses a double-extortion model, combining data theft with the disruption or encryption of IT environments. Berlin’s data exfiltration has been confirmed, but insufficient information has been disclosed to determine whether encryption also occurred.

The impact extended beyond the two ministries. Some district offices were temporarily unable to process applications related to housing benefits and education and participation benefits. These procedures depend on systems administered by the urban development ministry.

The disruption highlights a critical dependency: even when a peripheral agency is not directly compromised, it may lose essential capabilities if the public-sector provider or the ministry operating central applications is isolated.

The Risk to Citizens, Employees and Contractual Counterparties

The possible theft of emails, contact details, contracts and credentials creates several different risks. The severity will depend on what the forensic investigation is able to confirm.

If the archives contained passwords that are still valid, attackers could attempt subsequent access to other services. Email accounts and telephone numbers could be used for targeted phishing campaigns in which messages imitate genuine names, cases and administrative relationships.

The 46,500 contracts claimed by the group could contain information about suppliers, consultants, construction projects or business relationships. Their presence in the stolen material, however, has not been validated by the authorities.

The reference to “classified information” also comes from the extortionists’ communication. At this stage, it is impossible to determine whether the material actually consists of classified documents, internal files or a description designed to increase the auction’s value.

Berlin initially stated that it had no indications that sensitive information had been compromised. Subsequent findings confirmed that data had been stolen, making a more extensive assessment necessary.

No technical indicators of compromise have been made public, such as IP addresses, domains, file hashes or the names of tools used. The initial access method and any vulnerability exploited are also unknown.

Employees, suppliers and citizens therefore have no list of indicators they can independently check. They should remain particularly cautious about emails, phone calls or SMS messages that reference genuine administrative matters and request credentials, payments or the opening of attachments.

Electoral Systems Are Segregated and Protected

The attack occurred less than a month before elections for the Berlin House of Representatives, scheduled for September 20. Its proximity to the election has raised questions about the security of the electoral infrastructure.

Interior Senator Iris Spranger said on Friday that these systems are protected against a similar attack. Based on the available information, no election-related data appears to have been exfiltrated.

Security officials consider the environment used for the election secure. No evidence has emerged linking the compromise of the two ministries to an attempt to alter the vote or gain access to the relevant systems.

The distinction is essential: an attack against government agencies shortly before an election can fuel alarm and disinformation, but it does not by itself prove interference with voting procedures.

Forensic Investigation Underway, No Definitive Attribution

Rhysida has been active since at least May 2023 and has targeted public administrations, hospitals, schools, manufacturing companies and technology firms in multiple countries. Its operating model generally combines file theft, encryption and cryptocurrency payment demands.

Researchers believe the operators may be Russian-speaking or operating in the broader Russian sphere. There is no public certainty, however, about their identity, location or organizational structure.

In the Berlin case, the claim therefore remains a statement made by the group. Attribution will require technical evidence from the compromised systems, access logs and any tools or artifacts left by the attackers.

The confirmed measures include isolating the affected environments, conducting forensic checks and separately protecting the electoral infrastructure. Berlin has also ruled out paying the ransom.

The immediate priority is to determine what actually left the network. Only after the stolen files have been inventoried will it be possible to notify potentially affected parties, revoke exposed credentials and assess the risks arising from possible publication of the data.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsBerlin cyberattackRhysida ransomwaredata breachgovernment hackingransom refusalITDZ Berlin
Back to home