Berlin state network hack prompts extortion standoff

Berlin’s state government has confirmed it is facing an extortion attempt tied to the August compromise of its administrative network and has publicly ruled out paying the ransom demanded by the attackers[5][3][15]. Officials said the city-state would not meet a demand for 30 bitcoin—just over €2 million—issued after a ransomware group claimed to have stolen a vast trove of government data and threatened to publish it[14][15][6]. The standoff underscores both the political stakes and the privacy risks arising from a breach hitting multiple key ministries ahead of Berlin’s upcoming vote[1][5].

The intrusion targeted the Berlin state network (BeLa) and was first detected on August 14, when unusual activity prompted authorities to disconnect affected systems from the central infrastructure[2][11][4]. Subsequent forensic work indicates that data had already been exfiltrated from the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and 12, prior to the shutdown[3][10][12]. At least two ministries—the departments responsible for urban development, construction and housing, and for mobility, transport, environment and climate protection—were taken offline, leaving staff to work largely via telephone while investigators assessed the scope of the incident[11][15][13]. Officials have said they currently believe the attack has been contained, but full analysis of what was accessed and copied remains ongoing[10][9].

The ransomware group Rhysida has claimed responsibility for the breach in a posting on its leak site, stating that it stole roughly 5.79 terabytes of data across about 1.44 million files from Berlin’s agencies[5][1]. The group alleges the cache includes personal information on more than 12,000 individuals, tens of thousands of administrative offense cases, over 46,500 contracts, court documents, emergency response plans, and thousands of files containing passwords and login credentials[6][5][1]. Berlin’s Senate Chancellery has said it cannot rule out that personal or otherwise non-public data was affected, and that the data leak in the mobility and environment portfolio was more serious than initially believed[3][12][10]. Authorities have not yet provided a detailed breakdown of which datasets were compromised, citing the need to protect ongoing investigative work and the privacy of impacted residents[12][3].

The breach has already disrupted the delivery of several public services, particularly in housing and mobility, where digital processes were forced back to paper or phone-based workflows while systems were isolated[11][15]. According to local reports, the isolation of departments beginning August 14 led to delays in processing and paying out housing benefits and other administrative services for several days[15][11]. Berlin has since restored connectivity for the affected Senate departments to the state network, with officials stressing that the ministries are again “in principle, operational,” even as security teams continue to harden systems and monitor for further anomalies[2]. Forensic teams, however, recently uncovered additional data outflows tied to the mobility and environment portfolio, suggesting that the attackers had a deeper foothold in at least part of the network than first assumed[3][10][12].

Investigators from Berlin’s Criminal Investigation Office (LKA), the public prosecutor’s office and federal security agencies are working “with full intensity” to identify the perpetrators and reconstruct the attack path through the state infrastructure[3][4]. Rhysida, which security researchers have linked to operations out of Russia or Eastern Europe, has a history of using data-leak countdowns and auctions to pressure victims into payment, and has now added “Berlin, Germany” to its roster of alleged targets[1][5][14]. Reports indicate that the group is threatening to publish the stolen files if the ransom is not paid, and has already advertised the cache as including sensitive information related to critical infrastructure and government operations[6][5][14]. Berlin’s mayor and senior officials have emphasized that, according to current assessments, election-specific infrastructure has not been compromised, seeking to reassure voters as the extortion campaign unfolds[1][15].

Technical details of the intrusion remain sparse, but local reporting suggests the attackers exploited a weakness in the IT operations of the Senate administration for urban development, construction and housing as a launching point into the broader state network[8][10]. No specific vulnerability or CVE has yet been publicly identified, and authorities have not disclosed whether the initial compromise stemmed from unpatched software, credential theft, or misconfiguration[8][9]. For defenders across the public sector, the incident illustrates the compounded risk of ransomware-plus-extortion campaigns against complex government networks, where sensitive data from multiple agencies can be aggregated and abused at scale. Ensuring robust network segmentation, continuous monitoring for lateral movement, secure backup strategies and rigorous third-party risk management will be critical as Berlin and other governments reassess their exposure in the wake of the Rhysida attack.

References

  1. Ransomware group says it stole Berlin data, offers it for auction
  2. After a hacker attack: Senate departments back online
  3. “The State of Berlin Will Not Be Blackmailed” – The Berlin …
  4. Cyberattack hits Berlin state ministries
  5. Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
  6. Hackers are demanding €2 million from Berlin for the stolen data
  7. Hackerangriff auf Berliner Landesnetz verübt – sensible Daten abgeflossen
  8. Cyberattack hits Berlin state ministries – AZERTAC
  9. Berlin: Verwaltungen erst eine Woche nach Hackerangriff vom Netz
  10. Two Berlin gov’t departments “unable to work” after cyberattack
  11. Hackerangriff auf Berlin: Senat räumt möglichen Abfluss sensibler Daten ein
  12. Berlin Isolates Two State Ministries After Breach Disrupts Public …
  13. Hackers demand $2.3M in ransom after breaching Berlin government network
  14. Berlin mayor: Hackers trying to blackmail city hall after data breach

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply