Berlin Confirms Data Theft After Rhysida Ransomware Attack Claims
The city administration of **Berlin** has confirmed a significant data theft following claims by the **Rhysida** ransomware gang. Cybercriminals are now attempting to extort the city, threatening to publish 5.79 TB of sensitive administrative data if their demands are not met. Authorities have stated they will not pay the ransom, initiating a multi-agency investigation into the incident.
The **Rhysida** ransomware group recently listed **Berlin** on its data leak site, publicly claiming responsibility for a cyberattack discovered in mid-August. This public claim, made on August 28, has prompted **Kai Wegner**, the Mayor of Berlin, to declare that the city will not yield to the extortion demands.
Investigations are now underway by the **State Criminal Police Office**, the public prosecutor's office, and federal security agencies to ascertain the full scope of the breach and identify the perpetrators.

### **Rhysida's Modus Operandi**
Active since mid-2023, **Rhysida** has established a track record of targeting critical sectors, including healthcare organizations, state governments, educational institutions, and vital infrastructure. The group employs a double-extortion tactic, exfiltrating sensitive data before encrypting systems and threatening public disclosure if a ransom is not paid.
In this incident, **Rhysida** claims to have exfiltrated a staggering 5.79 TB of data, encompassing approximately 1.44 million files from Berlin's administrative network.
### **Exfiltrated Data Details**
The stolen data is alleged to include a wide array of highly sensitive information:
* Government, legal, financial, contractual, HR, infrastructure, health, and mapping records.
* Thousands of names, email addresses, phone numbers, and **148 IBANs**.
* Plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials.
* Personnel files, payroll information, administrative-offense records, email archives, **SQL** database dumps, identity documents, and banking information.
* Documents related to disciplinary proceedings and other named cases.
* Allegedly classified or sensitive government material, including **Bundesrat** committee records and information about handling classified documents.
* Critical-infrastructure security assessments concerning Berlinβs water supply.
* More than **3,200 documents** marked as nondisclosure agreements.
The attackers are leveraging potential **GDPR** violations to increase pressure on the Berlin government, setting a four-day deadline for payment before the stolen files are published.

*Source: BleepingComputer*
### **Investigation and Response**
Forensic investigators have identified that data was also exfiltrated from the **Senate Department for Mobility, Transport, Climate Protection and the Environment**, likely between August 7 and 12. Consequently, the affected Senate departments were disconnected from the state network on August 14 as a containment measure.
**Senator Iris Spranger** has reassured the public that there is no evidence of election data compromise, and the technical infrastructure supporting the upcoming **Berlin House of Representatives** election is deemed secure.
The specific method of entry used by **Rhysida** in this attack has not yet been disclosed. However, in a previous campaign, **Microsoft** observed the group utilizing malicious **Teams** installers to breach target networks. The ongoing investigation aims to determine the full extent of the data theft and the initial vector of compromise.