Reported by 1 source

The short version

  • Berlin Mayor Kai Wegner announced the city will not pay a ransom demand from hackers who compromised municipal networks and stole significant amounts of data.
  • The Rhysida group, suspected of operating from Russia and Eastern Europe, claims responsibility and threatens to auction stolen files if payment is not received.
  • While election infrastructure remains secure, the breach has disrupted housing benefit applications and transport services, raising concerns about personal data exposure.

Berlin authorities have firmly rejected a ransom demand from cybercriminals who breached municipal computer systems earlier this month, marking a significant escalation in digital security challenges for the German capital. Mayor Kai Wegner stated on Friday that the city would not succumb to blackmail, despite hackers claiming possession of sensitive internal documents and personal information. The refusal comes as investigators work urgently to determine the full extent of the data compromise and identify the specific perpetrators behind the intrusion.

The attack appears to have originated in early August, with officials confirming an initial data leak occurred between July 7 and August 12. By mid-August, the situation worsened when two departmental networks were forced offline on August 14. This disruption halted critical services, including applications for housing benefits and related payments, leaving residents unable to access essential support for several days. Forensic teams have since identified additional leaks within the transport and environment departments, suggesting the breach was broader than initially reported.

News Journal

The group claiming responsibility is known as Rhysida, a cybercriminal organization believed to operate out of Russia and Eastern Europe. This entity has been linked to numerous attacks on government institutions and businesses across multiple countries since emerging in 2023. Notably, Rhysida previously infiltrated the British Museum’s systems in 2023, stealing approximately half a million files containing visitor and staff data. When the museum refused to pay a ransom, the group published the stolen information on the dark web, establishing a pattern of leveraging public pressure through data exposure.

According to reports from Der Spiegel, the hackers are demanding 30 bitcoin, valued at roughly €2 million or £1.7 million, in exchange for not releasing the stolen material. The group has posted screenshots on its dark web site showing it possesses contracts, non-disclosure agreements, personnel files, passwords, and thousands of personal contact details. A countdown timer displayed on the site indicates that if the ransom is not paid, the group intends to begin auctioning the 5.79 terabytes of stolen data within seven days.

Mayor Wegner emphasized that state police, prosecutors, and federal security services are collaborating with utmost urgency to investigate the incident. The mayor’s office noted that inquiries into the content and scope of the compromised data are being pursued with great intensity. While authorities have not officially named the suspected attackers in public statements, the details align closely with Rhysida’s claims. Officials acknowledged that it cannot be ruled out that personal or other non-public data has been affected, raising privacy concerns for both city employees and residents.

The timing of the breach is particularly sensitive, occurring roughly one month before Berlin holds its municipal elections. State Senator Iris Spranger insisted that election infrastructure had not been compromised, aiming to reassure voters that the democratic process remains secure despite the cyber incident. However, the disruption to daily services and the potential exposure of personal data have sparked anxiety among citizens who rely on these digital platforms for essential government interactions.

The Rhysida group’s tactics reflect a growing trend in ransomware operations where attackers not only encrypt systems but also steal data to create dual leverage. By threatening to auction stolen information, they increase pressure on victims to pay, even if decryption is not the primary goal. This approach has proven effective in previous cases, such as the British Museum incident, where the publication of sensitive files caused reputational damage and privacy violations regardless of whether operational systems were restored.

As investigations continue, Berlin faces the dual challenge of restoring full functionality to its digital services while mitigating the risks associated with exposed data. The city’s decision not to pay the ransom sets a precedent for handling similar threats, though it may also invite further retaliation from the cybercriminal group. Residents and employees whose data was compromised will likely need to monitor their personal information for signs of misuse in the coming months.

The incident underscores the vulnerability of municipal infrastructure to sophisticated cyberattacks and highlights the need for robust security measures. While the immediate crisis involves service disruptions and data theft, the long-term implications include potential legal liabilities and erosion of public trust. Berlin’s response will be closely watched by other cities facing similar threats, as authorities balance the risks of paying ransoms against the costs of data exposure and operational downtime.

In the absence of a ransom payment, the focus now shifts to damage control and forensic analysis. Authorities must determine exactly which records were accessed and whether any malicious software remains in the system. The coming weeks will be critical in assessing the full impact of the breach and implementing safeguards to prevent future incidents. As the countdown on the hackers’ site ticks down, the city prepares for the possibility that stolen data may soon become publicly available.

Sources behind this briefing

Go to the original reporting

  • BBC World↗Berlin is being blackmailed by hackers, mayor says