Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state government is facing an extortion attempt following a data breach of its state network. Rhysida, a threat group, is suspected of stealing 5.79 terabytes of data, including maps and geodata, and the group gained initial access through compromised credentials and exploiting vulnerabilities like Zerologon. The FBI, CISA, and MS-ISAC have issued joint advisories on Rhysida’s tactics, urging remediation of known vulnerabilities and MFA implementation. Manchester Airports Group (MAG) separately reported a data breach affecting customer data related to car park and lounge bookings, but stated that airport operations were not impacted.
Berlin's state government is being blackmailed by an extortion attempt following a compromise of its state administrative network. Forensic work has revealed further data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, with the initial breach occurring between August 7 and August 12, 2026. The Senate Chancellery stated that personal or other non-public data could not be excluded from what was taken, and the state criminal police, public prosecutor, and federal security authorities are investigating the suspected perpetrators. Rhysida, a threat group, is believed to be behind the attack, and the FBI, CISA, and MS-ISAC have jointly issued an advisory detailing Rhysida’s tradecraft, including exploiting vulnerabilities like Zerologon (CVE-2020-1472) and leveraging compromised credentials. The advisory also highlights similarities between Rhysida and Vice Society (Storm-0832), a group tracked by Microsoft. As of August 29, Rhysida was linked to 280 victims, including the Stuttgart city administration and Welthungerhilfe.
Meanwhile, Manchester Airports Group (MAG), which operates several UK airports, announced a separate data breach. An unauthorized third party gained access to customer data related to car park, lounge, and Fast Track bookings, as well as in-airport WiFi sign-ups at MAG’s airports. The breach did not impact operational airport systems, and MAG stated that customer bank details were not compromised. Access to the online Manage My Booking service has been temporarily suspended. The incident has affected approximately 8.7 million customers, and MAG is directing affected individuals to the U.K. National Cyber Security Center’s data breach guidance.
