VMTech
Discuss a project

Berlin rejects extortion demand after state network breach

Berlin rejects extortion demand after state network breach

Berlin’s state government has confirmed an extortion attempt after its state administrative network was compromised in August 2026, and said it will not meet the attackers’ demands. Forensic work also identified further data outflows involving the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and August 12.

The scale and content of the data taken are still under examination. The Senate Chancellery said it cannot rule out the theft of personal or other non-public data, while Berlin has not published a figure for the volume of material exfiltrated.

Attack claims remain unverified

An entry titled “Berlin, Germany” appeared on the Rhysida leak site on August 28, according to leak-site monitoring reviewed by The Hacker News. The listing claims 5.79 terabytes of data, roughly 1.44 million files and personal information concerning 12,076 individuals. Those figures are attacker claims, not figures confirmed by Berlin.

The post identifies the victim only as Berlin, Germany. Its listed file categories include 124,823 maps and geodata files, but the eleven categories together account for only about a quarter of the claimed file total. No ransom amount was displayed in the entry.

Berlin’s governing mayor, Kai Wegner, said after a special Senate session that the state was being blackmailed. The state criminal police, public prosecutor and federal security authorities are investigating. The Senate Chancellery said the Berlin data protection commissioner and the Federal Office for Information Security, or BSI, are being kept informed.

Services restored as investigation continues

Berlin first disclosed the compromise on August 17, saying the affected departments had been isolated from the network since August 14. Housing benefit applications and payments were unavailable while the two departments were disconnected. All Senate departments were reconnected on August 23, but forensic work and network scanning continue.

Interior Senator Iris Spranger said that, based on the information available, no data had left systems relevant to the September 20 Abgeordnetenhaus election and that the election environment was considered secure.

Defensive lessons from Rhysida guidance

Der Spiegel linked the incident to Rhysida, citing the group’s darknet posting and security sources, though Berlin has not publicly identified the perpetrators. A 2023 joint advisory from CISA, the FBI and MS-ISAC describes Rhysida’s double-extortion activity and records valid credentials used on external remote services, phishing and exploitation of Zerologon, CVE-2020-1472, as initial-access routes.

The advisory says ransom payment does not guarantee recovery and can encourage further targeting. It recommends prioritising known exploited vulnerabilities, enabling multi-factor authentication across services and segmenting networks to limit ransomware spread. For organisations, Berlin’s case underlines the operational value of testing those controls and maintaining recovery plans that do not rely on an extortion payment.

#ransomware#databreach#cybersecurity#mfasecurity
Open analytics
On the site 0 views
min read 3 28.08.2026
Instagram

Berlin rejects extortion demand after state network breach

Open the post on Instagram ↗