Berlin says it won’t pay ransom after hackers steal government data
Hackers, claiming responsibility through the Rhysida ransomware group, have stolen 5.79 terabytes of data from Berlin’s government network, including contracts and classified information. Berlin has refused to pay a ransom and is investigating the scope of the breach, which occurred between August 7th and 12th, causing disruption to public services and raising concerns about potential interference with upcoming elections. The group, Rhysida, has been active since May 2023 and is believed to be Russian-speaking.
Berlin authorities have refused to pay a ransom demanded by hackers who allegedly stole data from the region’s government network. Governing Mayor Kai Wegner announced that the state of Berlin was being blackmailed, and the government would not comply with the attackers’ demands. The Rhysida ransomware group has claimed responsibility for the attack, adding Berlin to its dark-web leak site and stating they had stolen 5.79 terabytes of data, including 46,500 contracts, as well as emails, telephone numbers, passwords, and classified information.
The breach occurred between August 7th and August 12th, leading to significant disruption. Berlin disconnected affected systems from the wider state network on August 14th, cutting off two ministries – one responsible for urban development, construction and housing, and another overseeing mobility, transport, climate protection and the environment. Both ministries remained operational, but employees lost access to their usual IT systems, including email and internet services, forcing some staff to communicate by telephone, text message and fax.
The disruption also impacted other public services, with some district offices temporarily unable to process applications for housing benefits and education and participation assistance due to reliance on systems operated by the affected urban development ministry. Berlin’s state-owned IT provider, ITDZ Berlin, was not affected, as the two ministries share some IT infrastructure but operate their section of the state network independently.
The breach comes less than a month before Berlin holds elections to its House of Representatives on Sept. 20. Interior Senator Iris Spranger stated that election systems were protected against a similar attack, and that no data had been exfiltrated from them, according to security officials. Rhysida has been operating since at least May 2023, targeting governments, hospitals, schools, manufacturers and technology companies. The financially motivated ransomware operation typically steals victims’ data and encrypts their systems before demanding cryptocurrency payments. Cybersecurity researchers believe Rhysida is likely Russian-speaking or operating from the broader Russian region, though its operators’ identities and precise location remain unclear.
