Berlin cyber attack: state secrets and crisis plans leaked by Rhysida hacker group

The Rhysida hacker group has released 5.79 terabytes of data stolen from Berlin's regional administration, including national security documents. The ransom was not paid.

Berlin cyber attack: state secrets and crisis plans leaked by Rhysida hacker group

State crisis plans and nuclear protocols may have been exposed in Berlin hacker attack

The cyber attack on Berlin's regional administration may have far more serious consequences than initially assumed – according to Telex. The hacker group known as Rhysida published all the documents it had obtained on the dark web in late August, after Berlin refused to pay the 30 bitcoin ransom – approximately 770 million Hungarian forints. The materials that came to light at that time included several German newspapers and cybersecurity specialists who found documents that were sensitive from a national security perspective.

The attack took place between 8 and 12 August: the hackers broke into the systems of Berlin's regional transport, climate protection, environment, urban development and housing departments. City authorities isolated the affected systems on 14 August, and three days later made the attack public. Rhysida took responsibility on 28 August, and itemised what it had stolen: 5.79 terabytes of data, approximately 1.44 million files, which according to their claims contain personal data of more than 12,000 people, encrypted documents and documents relating to critical infrastructure.

The exact method of the breach has yet to be determined by either Berlin authorities or investigators. Based on previous experience, it is likely that they gained access to the system through phishing, other social engineering or with the help of an internal contact. From there they stole the data within a matter of days, then activated ransomware that encrypted files stored on internal systems.

Berlin did not give in to the extortion – according to experts, this move is generally the right decision in such situations. As a result, Rhysida released the entire database last Friday. Berlin's regional administration responded the following day, Saturday: in their statement they indicated that four newly formed working groups would investigate exactly what had leaked, and would immediately notify affected institutions in the case of critical data. They also involved outside legal experts, and provided additional support to citizens who reported their involvement.

Multiple German newspapers and specialist portals analysed the content of the leaked materials. According to Tagesspiegel's summary of Cybernews, the database contained numerous documents related to national security: documents about power plants, security companies, systems to be used in emergencies and the German armed forces. Spiegel came across hundreds of documents relating to the expansion of the Federal Chancellery, including expert opinions and statements issued by government bodies.

According to Euronews, the database also contains a folder named "AG CBRN-Rahmenplanung" – the acronym CBRN refers to chemical, biological, radiological and nuclear threats – which suggests that protocols developed for such crisis situations may also have been exposed. German investigative journalist Lars Winkeldorf wrote on X that in his view this data leak is "worse than all previous terrorist attacks combined", primarily because the documents include all the detailed information about what the German state would do in a potentially catastrophic crisis situation – and these documents are now accessible to anyone, "from Moscow through Tehran to all extremists around the world".

Berlin's regional administration cautions against the public drawing conclusions from data uncovered by journalists, experts or laypeople that remains unconfirmed. At the same time, the establishment of the four working groups, the involvement of outside experts and the additional support provided to those affected suggests that the authorities themselves are aware of the seriousness of the situation.

The investigation is not progressing without obstacles. One of Berlin's districts, Lichtenberg, refused to grant access to its servers to CrowdStrike, the cybersecurity firm commissioned by Berlin's regional administration, citing the argument that this would provide unrestricted access to its internal systems. Meanwhile, several experts have also raised questions about the responsibility of Berlin's regional administration, arguing that the attacked systems did not comply with relevant cybersecurity regulations.

Although the incident did not affect electoral infrastructure, its impact on the Berlin elections scheduled for 20 September cannot be ruled out. Particular attention should be paid to the fact that Rhysida recently also took action in Hungary: the hacker group claimed to have gained access to data from Széchenyi Programiroda Nonprofit Kft. – the company confirmed this to Telex. They demanded 20 bitcoins from the Hungarian target, approximately 500 million Hungarian forints.

Source: Telex

Read this article in the original language