Hacker group Rhysida publishes 5.7 terabytes of Berlin administration data on darknet

Sensitive data from two Berlin Senate administrations became freely accessible on the darknet following a cyber attack. Berlin refused the ransom demand of 30 Bitcoin.

Hacker group Rhysida publishes 5.7 terabytes of Berlin administration data on darknet

Berlin Senate data accessible on darknet following hacker attack

Since Friday afternoon, stolen data from two Berlin Senate administrations have been publicly accessible on the darknet. According to the Süddeutsche Zeitung, the files can be downloaded from the darknet page of the hacker group Rhysida. Among them are contracts, passwords, personal data such as addresses and telephone numbers, as well as documents relating to critical infrastructure. Whether the stated 1.44 million files totalling approximately 5.7 terabytes are actually present could not be verified in the short term.

Investigative journalist Lars Winkelsdorf described the publication on X as "an absolute catastrophe". The security breach had "state-endangering proportions": emergency plans of the authorities, defence plans and secret communication channels of the German federal government are now publicly accessible.

Attack went undetected for days

The cyber attack became known on 14 August. The affected administrations are the Senate Administration for Mobility, Transport, Climate Protection and Environment, and the Senate Administration for Urban Development, Building and Housing. The hackers apparently had undetected access to internal computer systems from 7 to 12 August. The Berlin Senate had initially stated that only publicly accessible data had been leaked.

For a week it had been known that Rhysida was extorting the State of Berlin and threatening to publish the stolen data if no ransom was paid. The demand: 30 Bitcoin, currently worth around two million euros. Governing Mayor Kai Wegner (CDU) had stated that Berlin would not be extorted. The deadline set expired on Friday afternoon.

Personnel files and disciplinary proceedings among the documents

The now-published data originate from various departments of the affected administrations — including specialist departments, political processes and internal administrative matters. Scanned identity documents and certificates can be found among the files from the personnel department. Confidential documents relating to disciplinary proceedings were also published, marked "Confidential personnel matter!".

Rhysida has been attacking organisations for years

Over the past years, Rhysida has attacked dozens of organisations and companies, stolen data and either demanded payment or published the information on the darknet. Targets in the United States were frequently affected. In Germany, data from a Stuttgart property management company have already been published, though on a considerably smaller scale than in the current Berlin case.

Authorities call on those affected to file criminal charges

The Berlin administration announced that it would inform affected individuals depending on risk assessment. Those affected are called upon to file criminal charges with the police. Authorities currently assume that the "Berlin State Network" is no longer infiltrated.

Source: Süddeutsche Zeitung

Read this article in the original language