ZeroHour
Story · 1 source · 1 articlefirst updated ()

Berlin refuses €2m ransom as Rhysida leaks ~5.7 TB of stolen government data, including CBRN emergency plans

highRansomwareexploited in the wildimportance 78
What's new: First merged summary of this story. Rhysida published the stolen data after Berlin refused its ransom. Newly reported details: the 30-bitcoin (~€2m) ransom demand with a September 4 deadline, the scale of the leak (roughly 5.7 TB / about 1.4 million files), the inclusion of the 'AG CBRN-Rahmenplanung' folder with sensitive terrorist-attack and CBRN disaster plans, BSI's link to TerminalFix…
Merged summary · glm-5.3 · rewritten as coverage arrives

The Rhysida ransomware gang published roughly 5.7 TB of data stolen from Berlin's state government — including login credentials, personnel files and sensitive CBRN disaster plans — after the city refused a 30-bitcoin (~€2m) ransom, weeks before Berlin's…

Berlin is investigating a fresh data leak after the Rhysida ransomware group published stolen data from a mid-August cyberattack on two city ministries responsible for urban development/housing and transport/climate. Rhysida claimed the breach in late August, saying it stole 5.79 TB of data; Infosecurity Magazine reports the published dump at roughly 5.7 TB — about 1.4 million files — including contracts, emails, passwords, login credentials and classified information. Berlin acknowledged the extortion demand but refused to pay the 30 bitcoins (about €2m) sought by the September 4 deadline. The published dump reportedly includes a folder titled 'AG CBRN-Rahmenplanung' containing sensitive state emergency plans for terrorist attacks and CBRN disaster scenarios, plus personnel files, absence lists, payroll data and home addresses. Berlin's data protection regulator said the leak includes personal data on public employees and possibly residents — names, addresses, dates of birth and bank information — with reports suggesting tens of thousands of people could be affected. Germany's BSI separately linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware tied to financially motivated, Rhysida-associated hackers. Officials say the affected systems were isolated from Berlin's government network on Aug. 14, there are no indications the state network remains compromised, and there is no evidence that systems for Berlin's Sept. 20 election were affected; the city says it will notify affected individuals on a risk-based basis once forensic analysis is complete. Rhysida, active since May 2023, previously attacked the British Library and US healthcare providers.

  • Rhysida claimed the breach in late August and says it stole 5.79 TB of data; Infosecurity Magazine reports the published dump at roughly 5.7 TB, about 1.4 million files (sources differ slightly on volume).
  • The mid-August attack hit two Berlin city ministries — urban development/housing and transport/climate; affected systems were isolated from the government network on Aug. 14.
  • Ransom demand: 30 bitcoins (about €2m) with a September 4 deadline; Berlin refused to pay, with officials saying the city will not be blackmailed.
  • Published data includes login credentials, contracts, emails, passwords and classified information, plus a folder titled 'AG CBRN-Rahmenplanung' with sensitive state emergency plans for terrorist attacks and CBRN disaster scenarios.
  • The leak also contains personnel files, absence lists, payroll data and home addresses; Berlin's data protection regulator says it includes names, addresses, dates of birth and bank information on public employees and possibly residents,…
  • Germany's BSI linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware associated with Rhysida-affiliated, financially motivated hackers.
  • Officials report no evidence that Berlin's Sept. 20 election systems were affected and no indications the state network remains compromised; affected individuals will be notified on a risk-based basis after forensic analysis.
  • Rhysida has been active since May 2023 and previously attacked the British Library and US healthcare providers.

Coverage timeline

  1. · 9d ago
    The Record· 72
    Berlin investigates new data leak after hackers publish stolen login credentials

    Berlin investigates a fresh leak after Rhysida hackers published stolen login credentials; the city refuses to pay the ransom demand.