Connect with us

Security

Berlin Stands Firm: No Payment for Hackers Who Stole Data from State Network

Published

on

The capital city of Berlin is currently facing an extortion attempt after its state administrative network was compromised in August. The state government has confirmed the extortion but has stated that they will not comply with the demands of the attackers.

Further investigation revealed that data was leaked from the Senate Department for Mobility, Transport, Climate Protection, and Environment between August 7 and August 12, 2026. The extent of the leaked data is still under examination, raising concerns about the exposure of personal or confidential information.

Although the department initially reported the data breach on August 7, it was only disconnected from the network on August 14. The exact amount of data that was leaked has not been disclosed by Berlin, but an anonymous leak-site post claimed that 5.79 terabytes of data and personal information on 12,076 individuals were compromised.

The authorities are actively investigating the incident, with the state criminal police, public prosecutor, and federal security agencies working to identify the perpetrators behind the attack. The group responsible for the attack has been named as Rhysida, known for their double extortion tactics.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have issued a joint advisory detailing Rhysida’s methods of gaining access to victim networks, including exploiting vulnerabilities and phishing attacks.

While the agencies do not recommend paying ransom to cybercriminals, they advise organizations to prioritize security measures such as patching known vulnerabilities, implementing multi-factor authentication, and segmenting networks to prevent the spread of ransomware.

See also  Cisco Urges Immediate Action Against Unpatched AsyncOS Zero-Day Attacks

  • Valid accounts on external-facing remote services are one of the entry points for attackers, especially in organizations lacking multi-factor authentication.
  • Zerologon (CVE-2020-1472), a vulnerability in Microsoft’s Netlogon Remote Protocol, has been exploited by Rhysida to elevate privileges.
  • Phishing attacks have also been successful in infiltrating victim networks.

Similarities have been noted between Rhysida and Vice Society, another cybercriminal group tracked by Microsoft. The monitoring service has identified 280 Rhysida victims as of August 29, with targets including government entities and organizations in various countries.

Meanwhile, Manchester Airports Group (MAG) has confirmed a data breach affecting customer information related to car park bookings and in-airport services at Manchester, London Stansted, and East Midlands airports. The breach did not compromise passenger safety or aviation security.

Affected customers have been notified, and MAG advises vigilance against potential phishing attempts. The incident has prompted the suspension of online booking services, with affected customers urged to contact customer services for assistance.

Both incidents highlight the ongoing threat of cyberattacks and the importance of robust security measures to protect sensitive data and prevent unauthorized access.

Trending