LIVE · cybersecurity feed
Live wire
ransomware

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]

zeroday.news ·

Berlin's city administration has confirmed that it is facing an extortion attempt following a cyberattack by the Rhysida ransomware group, which listed the city on its data leak site. The incident, discovered in mid-August, was publicly claimed by the attackers on August 28. Berlin Mayor Kai Wegner stated that the city will not pay the ransom. The State Criminal Police Office, the public prosecutor's office, and federal security agencies are currently investigating the breach.

Rhysida ransomware has been active since mid-2023, previously targeting healthcare organizations, state governments, educational institutions, and critical infrastructure. The group claims to have exfiltrated 5.79 terabytes of data, comprising approximately 1.44 million files, from Berlin's administrative network.

According to the attackers, the stolen information includes government, legal, financial, contractual, HR, infrastructure, health, and mapping records. Specific claims detail thousands of names, email addresses, phone numbers, and 148 International Bank Account Numbers (IBANs). The attackers also allege they obtained plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials.

Further claims from Rhysida include the exfiltration of personnel files, payroll information, administrative-offense records, email archives, SQL database dumps, identity documents, and banking information. Documents related to disciplinary proceedings and other named cases were also allegedly compromised. The group claims to possess classified or sensitive government material, including Bundesrat committee records and information on handling classified documents, as well as critical-infrastructure security assessments concerning Berlin's water supply. More than 3,200 documents marked as nondisclosure agreements are also purportedly among the stolen data.

The attackers are leveraging potential GDPR violations to pressure the Berlin government, issuing a four-day deadline for payment before the alleged stolen files are published.

Forensic investigators have determined that data was exfiltrated from the Senate Department for Mobility, Transport, Climate Protection and the Environment, likely between August 7 and 12. The affected Senate departments were disconnected from the state network on August 14. The investigation is ongoing, and the full extent of the data theft has yet to be determined.

Senator Iris Spranger confirmed that officials have found no evidence of compromised election data, and the technical environment supporting the upcoming Berlin House of Representatives election is considered secure. The initial method of entry used by Rhysida in this attack has not been disclosed. In a previous campaign, the ransomware operators reportedly used malicious Microsoft Teams installers to breach targets.

ransomwarebreach
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malware

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking

breach

McKesson Confirms Data Breach as Attacker Deadline Looms

The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems. The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek.

security

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]

malware

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]