Rhysida Ransomware Attack on Berlin Demands 30 Bitcoin for Stolen Government Data
Mixed

Rhysida Ransomware Attack on Berlin Demands 30 Bitcoin for Stolen Government Data

A massive cyberattack targeting the state administration of Berlin is allegedly linked to the ransomware group Rhysida. This information was reported by “Spiegel”, who cited a recent entry on the group’s leak site in the Darknet. Involved security circles confirmed this suspicion after being contacted by the news magazine.

In their ransom message, the suspected hackers claim to have compromised nearly six terabytes of data during their campaign. They are demanding a payment of 30 Bitcoin from the state of Berlin, threatening to release the stolen data if the sum is not met. The countdown timer displayed in their message indicates that Berlin has a one-week deadline, ending this Friday, to make the demanded payment.

According to the hackers’ Darknet announcement, the sheer volume of data transferred is significantly higher than what Berlin acknowledged following the cyber incident. Should the claims made by Rhysida hold true, highly sensitive information has fallen into their hands.

This data includes records from almost 80,000 administrative offense procedures and more than 46,500 contracts. Furthermore, the attackers reportedly have information regarding critical infrastructure facilities, sensitive judicial documents, emergency plans, passwords, and nearly 6,000 files containing login credentials. The hackers presented snippets of individual documents as proof, featuring headings such as “Confidential Personnel Matters,” alongside the letterheads of the Federal Council and the Senate Administration for Mobility. While the hackers’ claims and the authenticity of the documents shown could not be independently verified initially, the history of the ransomware gang suggests that they must be taken seriously.

This group has been active for several years. Rhysida notably gained notoriety following an attack on the British Library in the autumn of 2023, which encrypted the library’s systems. Other known victims of Rhysida include the German World Hunger Aid and the Stuttgart city administration.