news.mlab.sh
Back to the feed
threat-intel

Berlin investigates new data leak after hackers publish stolen login credentials

High
Summary

Berlin authorities are investigating a new data leak following a cyberattack that compromised two city government ministries in August. Hackers published stolen login credentials and other sensitive information, potentially exposing personal data of public employees and Berlin residents. The Rhysida ransomware group claimed responsibility for the initial attack, and German authorities are investigating a related campaign linked to the same group, warning of a tactic involving fake CAPTCHA pages to install malware. The city is preparing for an upcoming election and has stated that election systems are secure.

Berlin authorities are investigating a new data leak following a cyberattack discovered in mid-August that compromised two Berlin city government ministries responsible for urban development and housing, and for transport, mobility, climate protection and the environment. The latest release follows a cyberattack that left some employees without their normal email and internet access and temporarily affected public services. Berlin’s data protection authority confirmed that the attackers stole a large amount of data from the two affected ministries and later published it online, including login credentials, personal information about public employees, and potentially data belonging to Berlin residents, such as names, addresses, dates of birth, bank information, email addresses, telephone numbers, and copies of documents submitted to the administration. The city has created an additional task force to review the leaked material and determine who may be affected.

Berlin has confirmed that data was stolen and that it received an extortion demand, but officials have not publicly attributed the attack to Rhysida or verified the hackers’ claims about the amount or contents of the stolen material. Rhysida ransomware group claimed responsibility for the breach in late August, saying it had stolen 5.79 terabytes of data, including tens of thousands of contracts, emails, passwords and classified information.

Germany’s Federal Office for Information Security (BSI) separately warned Friday about a cyberattack campaign linked to the same financially motivated hackers behind Rhysida. The BSI said reports it received indicated that attackers attempted both to steal data and install ransomware, allowing them to pressure victims with the threat of publishing stolen information. The agency said the campaign resembles the so-called TerminalFix attacks recently documented by Microsoft. Hackers compromise websites and display fake CAPTCHA verification pages that trick visitors into manually running malicious commands on their computers. The BSI said stolen information is ultimately published in 92 percent of cases in which victims are named on Rhysida’s leak site.

The Berlin breach comes shortly before the city’s Sept. 20 election. Berlin Interior Senator Iris Spranger previously said that authorities had found no evidence that data had been stolen from election systems and that the election environment was secure. Rhysida has operated since 2023 and has targeted governments, hospitals, schools and companies around the world. According to the BSI, government and public administration organizations are among the five sectors most frequently appearing on the group’s leak site, although education and health care remain its primary targets.

Read the full article at The Record