Hacker group Rhysida publishes 5.26 TB of Berlin government data on dark web

After its extortion deadline expired, the group Rhysida made 1.44 million files from Berlin government agencies publicly accessible on the dark web.

Hacker group Rhysida publishes 5.26 TB of Berlin government data on dark web

Berlin government data published on dark web after ultimatum

At 15:35, the criminal hacker group Rhysida uploaded 5.26 terabytes of sensitive data from Berlin administrative bodies and government agencies to the dark web. According to BILD, a total of 1,439,893 files were made publicly accessible. The group wrote in English: "All data has been made public. Have fun with it, data hunters."

The exact extent of impact for affected private individuals remains unclear at present.

Data theft between 7 and 12 August

According to BILD's information, the attackers downloaded data from the Berlin Senate administration network between 7 and 12 August. The documents affected include critical infrastructure materials, LKA investigations, and account numbers. In a dark web catalogue, Rhysida listed the scope of the theft: 46,522 contracts, 5,941 passwords, 16,389 email addresses and approximately 5,000 personnel files.

Previously, the group had offered the data at auction on the dark web. The minimum bid was 30 bitcoin – equivalent to approximately two million euros. Since no buyer paid the price, the hackers made good on their ultimatum and made the files available for download to anyone.

Berlin refused ransom

Governing Mayor Kai Wegner (53, CDU) had previously refused to pay a ransom. "Berlin will not be extorted," he said. The state had no contact with the extortionists at any point.

The Senate administration for urban development, construction and housing established a crisis team. A spokesman for the Senate Chancellery told BILD: "There are currently no findings that the state network remains infiltrated. However, forensic investigations are ongoing. The investigations are also examining whether possibly further data was leaked." According to the Senate's assessment, there have been no additional data breaches so far.

Who is Rhysida?

Authorities believe the cybercriminals have connections to Russia. They took their name from a venomous centipede from South America – apparently as a metaphor for their malware, which runs undetected through IT infrastructures and infects systems.

Rhysida does not exclusively target major cities and administrations. According to the group's dark web entries, American tradespeople, small-town administrations and medical companies have also been extorted. In some cases, ransom is said to have been paid – the word "Sold" then appears in red text on the dark web page under the name of the affected company.

Political debate in Berlin

In political circles in Berlin, there is now discussion about whether a payment to prevent the data breach would have been justified – or whether it would have made the city more vulnerable to future extortion attempts. Investigations and forensic analyses are ongoing.

Source: BILD

Read this article in the original language