Rhysida rivendica 5,79 terabyte di dati dal governo di Berlino: rifiutato il riscatto, indagini in corso
Ransomware

Illustrative image generated with AI

Rhysida claims 5.79 terabytes of data from Berlin government: ransom refused, investigations ongoing

Rhysida ransomware group claims 5.79TB data from Berlin government including personal info; ransom refused. Investigations continue amid election concerns.

Text generated by artificial intelligence, published without human review. AI transparency

How the attack on the administrative network came to light

The Berlin state government is dealing with a cyber extortion case after an attack on the city-state’s administrative network. The compromise was publicly disclosed on 17 August, when authorities isolated the Senate Department for Mobility, Transport, Climate Protection and the Environment and a second department from the network. Forensic investigations later placed the actual data exfiltration between 7 and 12 August. The affected department had internally flagged an initial anomalous flow as early as 7 August, ten days before the official announcement. All Senate departments were reconnected to the network on 23 August, but forensic checks continue.

The Rhysida ransomware group claimed the attack on its leak site on 28 August with a listing titled "Berlin, Germany". The group says it stole 5.79 terabytes of data in about 1.44 million files, including personal information on 12,076 individuals. Berlin authorities have already refused the ransom demand. Broadcaster RBB was first to report the extortion demand.

What the claim contains: from personnel files to plaintext credentials

The figures and contents listed by Rhysida have not been independently verified. The group claims to hold personal data on 12,076 people: 16,389 email addresses, 11,963 phone numbers and 148 IBANs. More than 5,000 personnel files and a similar number of administrative offence files would complete the haul, along with salary data and leadership information.

The claim also cites plaintext passwords and credentials for the GebäudAtlas systems, ePayment PAYONE database and Z_ADMIN accounts. Rhysida says it stole government and legal material: disciplinary proceedings, court cases, supervisory records, non-disclosure agreements and Bundesrat committee protocols. The list also includes data related to handling classified material and documents that would contain state secrets, vulnerability analyses of Berlin’s water network, passports and identity cards from personnel files, contracts, financial documents, health data, password archives and SQL/PST archives.

According to Rhysida, the material could amount to violations of the GDPR, German classified information rules, criminal law, and KRITIS/BSIG requirements for critical infrastructure.

Who Rhysida is and how it enters networks

Tracking services cited by Reuters attribute about 280 victims to Rhysida since its emergence in 2023. Nine of these are in Germany; notable targets include the British Library and the Chilean army. Around half of the victims are in the United States, followed by the United Kingdom, Canada and Italy: a distribution that suggests opportunistic targeting rather than geography.

A joint CISA-FBI-MS-ISAC advisory published in November 2023 identifies the group’s typical access vectors: compromised VPN credentials in organizations lacking multi-factor authentication, exploitation of the Zerologon vulnerability patched by Microsoft in 2020, and traditional phishing. It has not been disclosed which of these vectors was used in the Berlin attack. Forensic investigations are still ongoing, and reconnected systems remain under review.

Impact on individuals and election risk

At the time of publication, neither the Berlin data protection office nor the Senate Chancellery has provided specific guidance to the roughly 12,000 people whose data Rhysida claims to have stolen. The state data protection authority and the German Federal Office for Information Security (BSI) are following the investigation. It is not yet established exactly what was accessed and exfiltrated: the absence of official communications is not equivalent to safety.

The proximity to the election makes the case particularly sensitive. On 20 September Berlin will elect its state parliament. Interior Senator Iris Spranger has said the election remains secure and that so far the attackers have not stolen data related to the election. Security officials agree with that assessment.

In a joint statement released before the leak-site claim, Mayor Kai Wegner and Senator Spranger said the state of Berlin will not give in to extortion. The position is consistent with the warning from US federal agencies that paying does not guarantee data recovery and can encourage further attacks.

What remains unclear and what organizations can do

The time between the first internal detection on 7 August and the network isolation announced on 17 August will likely be reviewed closely. The exact versions of the affected systems are not known, nor whether initial access occurred via VPN, Zerologon or phishing.

For organizations using similar infrastructure, the countermeasures consistent with Rhysida’s known vectors remain three: adopt multi-factor authentication for VPNs and exposed systems, apply Microsoft’s 2020 Zerologon patch, and strengthen anti-phishing defences. Berlin authorities have already refused to pay the ransom. Forensic investigations are ongoing and reconnected systems remain under review.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsRhysidaBerlin government data breachransomware attackcybersecuritypersonal dataGDPRinvestigationelection security
Back to home