LIVE · cybersecurity feed
Live wire
ransomwarehigh

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

The government of Berlin is responding to a ransomware attack by the Rhysida group, which claims to have stolen 5.79 TB of data, including personal information and sensitive government documents. Officials have refused to pay the ransom, citing advice against such payments and asserting that election data was not compromised. The attack occurred weeks before a state election, raising concerns about its timing and the potential impact of data leaks.

zeroday.news ·

The Berlin state government is currently managing an extortion attempt by the Rhysida ransomware group, which claims to have stolen 5.79 terabytes of data from the city-state's administrative network. This incident comes just weeks before Berlin's state parliament elections on September 20.

Rhysida posted an entry on its leak site on August 28, claiming responsibility for the cyberattack. The group alleges it exfiltrated approximately 1.44 million files, including personal information on 12,076 individuals, 16,389 email addresses, 11,963 phone numbers, and 148 IBANs. The claimed dataset also includes over 5,000 personnel files, more than 5,000 administrative-offence files, payroll data, and leadership information.

Furthermore, Rhysida asserts it obtained plaintext passwords and credentials for systems such as GebäudAtlas, the ePayment PAYONE database, and Z_ADMIN accounts. Government and legal materials, including disciplinary proceedings, court cases, supervisory documents, NDA records, and Bundesrat committee protocols, are also among the claimed stolen data. The group even alleges possession of classified information related to handling sensitive materials and documents containing state secrets, as well as vulnerability analyses concerning Berlin's water supply. Identity documents like passports and ID cards from personnel records are also mentioned.

The Berlin government has confirmed it will not pay the ransom. Mayor Kai Wegner and Interior Senator Iris Spranger issued a joint statement affirming this stance, which aligns with advice from federal agencies against paying ransoms. Senator Spranger also stated that the upcoming election remains secure, with no election-related data compromised by the attackers so far, an assessment supported by security officials.

The compromise was first disclosed by Berlin on August 17, leading to the isolation of the Senate Department for Mobility, Transport, Climate Protection and Environment and a second department from the network. Forensic investigations later determined that the data exfiltration occurred between August 7 and August 12, with an initial outflow flagged internally on August 7, a week before network isolation. All Senate departments were reconnected to the network by August 23, though forensic teams continue to examine the systems.

Rhysida, which emerged in 2023, has claimed approximately 280 victims globally, with about half located in the United States. Nine of its reported victims are in Germany. Notable past targets include the British Library and Chile's army. A joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center, published in November 2023, details common Rhysida entry methods, including compromised VPN credentials without multi-factor authentication, exploitation of the Zerologon vulnerability (patched in 2020), and phishing.

The state's data protection commissioner and Germany's federal cybersecurity agency, the BSI, are monitoring the ongoing investigation. As of now, specific advice has not been issued to the individuals whose data Rhysida claims to have stolen, as investigators are still working to confirm the exact scope of the breach.

ransomwarerhysidadata breachgovernmentberlin
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

Brave browser adds email aliases to help users evade tracking

The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]

CVE-2026-76639high

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

A security researcher has discovered a chain of two vulnerabilities in the Unitree G1 humanoid robot that allows for remote, unauthenticated root access. The flaws can be exploited through a combination of Bluetooth, Unitree's cloud infrastructure, and the mobile app, enabling an attacker to compromise a robot and then use it to attack other nearby robots. Unitree has since patched the cloud vulnerability and issued bounties for the discovered flaws.

malwarehigh

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

A sophisticated cyber campaign dubbed TerminalFix, a variant of ClickFix, is targeting organizations by tricking users into executing malicious PowerShell commands via a fake Cloudflare CAPTCHA. This campaign deploys a multi-stage attack involving DLL sideloading, steganographic payload extraction from images, and extensive Active Directory reconnaissance. The ultimate goal is to establish a persistent reverse tunnel, granting attackers network-level proxy access to internal systems for further exploitation.

breach

McKesson discloses breach after ShinyHunters claims patient data theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]