Berlin Cyber Attack: Hackers Threaten to Sell 5.79TB of Stolen Data
Berlin has been targeted by a ransomware incident after cybercriminals breached municipal systems, exfiltrated data, and issued a demand for payment.
Ransomware Incident and Data Exfiltration
Berlin has been targeted by a ransomware incident after cybercriminals breached municipal systems, exfiltrated data, and issued a demand for payment. Mayor Kai Wegner confirmed the city would not comply with the extortion attempt. The attack involved the theft of 5.79 terabytes of information, with perpetrators threatening to sell the data through an online auction. The ransom request was disclosed on Thursday evening, though the exact sum was not disclosed publicly.
Ransom Demand and Refusal
Reports from German media indicated the attackers sought 30 bitcoin, equivalent to approximately €2 million. Wegner emphasized the city’s refusal to negotiate, stating “Berlin will not be blackmailed.” The Rhysida ransomware group, linked to operations in Russia and Eastern Europe, has asserted responsibility for the breach.
“Berlin will not be blackmailed.”
Compromised Data and Dark Web Auction
The Rhysida group announced plans to initiate an auction for the stolen data within seven days, according to Reuters. The compromised information reportedly includes documents such as contracts, non-disclosure agreements, personnel files, passwords, and personal contact details. A dark web portal associated with Rhysida displayed a countdown to the auction, with an initial bid of 30 bitcoin.
Impact on Municipal Services
The cyberattack disrupted several municipal services. An initial data breach occurred between August 7 and 12, followed by the shutdown of two departmental networks on August 14. This caused temporary unavailability of housing benefit applications and payment systems. Subsequent investigations revealed additional data leaks involving the transport and environment departments.
Previous Attacks and Global Reach
The mayor’s office acknowledged the possibility that personal or confidential information may have been accessed. Authorities have not publicly identified the perpetrators, but Rhysida’s dark web platform has been cited as the source of the stolen materials. The group has previously claimed responsibility for hundreds of attacks since 2023, targeting government agencies and private entities globally.
Response and Ongoing Investigations
In 2023, the British Museum experienced a similar breach, resulting in the theft of 500,000 files. After refusing to pay the ransom, the institution had visitor data publicly released by the attackers. Investigations into the Berlin incident are being conducted by state police, prosecutors, and federal security agencies, with officials describing the response as “urgent.” The probe aims to determine the scope and nature of the compromised data.
Broader Implications for Cybersecurity
The attack occurred ahead of local elections, though state senator Iris Spranger confirmed election systems remained unaffected. The breach highlights ongoing challenges in securing municipal infrastructure, with threat actors increasingly leveraging data exfiltration as a tool for coercion. Cybersecurity experts have urged organizations to enhance protective measures, including regular system audits and incident response planning.
