Berlin Activates Crisis Response After Ransomware Group Publishes Stolen Government Data

Berlin Activates Crisis Response After Ransomware Group Publishes Stolen Government Data
Berlin Activates Crisis Response After Ransomware Group Publishes Stolen Government Data — BERLIN, GERMANY — Berlin has set up a central response unit to assess millions of files stolen from its government network after the Rhysid...

BERLIN, GERMANY — Berlin has set up a central response unit to assess millions of files stolen from its government network after the Rhysida ransomware group published the data following the city's refusal to pay an extortion demand.

Berlin authorities intensified their response on September 5 after stolen government data appeared on the dark web, beginning the task of determining which records were exposed and identifying citizens, employees and businesses that may need to be notified.

The breach affected two Senate departments after attackers gained access to parts of Berlin's government network in August. German public broadcaster Tagesschau reported that approximately 1.44 million files amounting to about 5.8 terabytes were taken, while Berlin had previously said the Rhysida group claimed to possess about 5.7 terabytes.

The publication marks a significant change in the incident. Berlin is no longer dealing only with the theft and attempted extortion of government data; authorities must now establish what information has actually entered the public domain and what risks it creates for people and organizations whose records may be among the files.

A central unit will coordinate the review, verification and assessment of the leaked material and help the affected departments inform citizens and businesses, according to Berlin authorities. The city's forensic investigation and the criminal inquiry remain underway.

Rhysida published data after Berlin rejected ransom demand

Rhysida had offered the stolen material for sale after claiming responsibility for the breach. Berlin said before the publication that the group was demanding 30 bitcoin — worth about €2 million at the time according to the city — and that the government would not pay.

Reuters reported that Rhysida advertised 5.79 terabytes of material. The group's claims included contracts, emails, telephone numbers, passwords and classified information, but those descriptions originated with the attackers and should not be treated as an independently verified inventory of the stolen files.

Berlin's government had already warned before the release that the stolen material could contain personal information belonging to state employees, residents and businesses.

Authorities have not yet publicly established the complete contents of the published dataset. That distinction is important because the size claimed by the ransomware group does not by itself establish how much of the material is authentic, sensitive, current or capable of causing harm.

The government has said people identified as affected will be contacted under German and European data-protection requirements. Berlin's new coordination structure includes the state criminal police, the data-protection authority, information-security officials, the affected Senate departments and other security bodies.

Federal agencies are also supporting the investigation. Germany's Federal Office for Information Security, Federal Criminal Police Office and domestic intelligence agency are involved, with information being shared through the country's Joint Cyber Defence Centre. Federal government systems were not known to have been affected as of September 5.

Data leak comes two weeks before Berlin election

The publication comes shortly before Berlin's September 20 state election, adding political sensitivity to the breach. The timing alone, however, does not establish that the intrusion was designed to influence the election.

The evidence reviewed by CRN Times supports treating the incident as a ransomware and government-data breach rather than an election attack unless investigators establish a connection. Available threat reporting describes Rhysida as financially motivated, while Berlin's election infrastructure and election data have not been identified as affected in the material reviewed.

That distinction also limits what can responsibly be inferred about the attackers. Rhysida has claimed responsibility, but attribution of the underlying intrusion and any determination about who directed or participated in it remain matters for the continuing investigation.

The immediate issue for Berlin is therefore the released data itself. Authorities must determine which of the roughly 1.44 million files are genuine, what personal or confidential information they contain, which individuals and organizations are affected and what additional security measures are required.

Berlin has described the cyberattack as an extremely serious crime and an attack on the state, while urging people not to circulate unverified claims about the leaked material. The government's next measurable task is to complete enough of its review to notify affected people and businesses while investigators continue trying to establish the full scope and responsibility for the intrusion.

More from this section

  • Loading related stories…

Keep comments relevant and respectful. Do not post spam, threats, personal information, copyrighted material without authorization, or unsupported allegations. Comments may be moderated or removed.

Previous article Next article

Contact