Berlin investigates new data leak after hackers publish stolen login credentials
Berlin investigates a fresh leak after Rhysida hackers published stolen login credentials; the city refuses to pay the ransom demand.
Berlin confirmed hackers published additional stolen data, including login credentials, from a mid-August cyberattack on two city ministries responsible for urban development/housing and transport/climate. The Rhysida ransomware group claimed the breach in late August, saying it stole 5.79 TB of data including contracts, emails, passwords and classified information; Berlin acknowledged an extortion demand but refused to pay. Berlin's data protection regulator said the leak includes personal data on public employees and possibly residents, such as names, addresses, dates of birth and bank information. Germany's BSI separately linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware tied to financially motivated Rhysida-associated hackers, days before Berlin's Sept. 20 election.
Berlin says it won’t pay ransom after hackers steal government data
Berlin refuses ransom as Rhysida ransomware group claims theft of 5.79 TB of government data ahead of September 20 elections.
The Rhysida ransomware group claimed responsibility for stealing 5.79 TB of data from Berlin's government network, including 46,500 contracts, emails, phone numbers, passwords and classified information, and listed it for auction starting at 30 bitcoin (~$2.3 million). Berlin discovered the breach in mid-August, disconnected two ministries from the state network on August 14, and refused to pay the ransom; authorities have not officially attributed the attack. Data is believed taken between August 7 and 12, and district services such as housing benefit processing were disrupted. Officials said election infrastructure is protected ahead of the September 20 House of Representatives vote, and state IT provider ITDZ Berlin was unaffected.