Berlin Government Under Extortion Attempt, Manchester Airports Group Suffers Data Breach
The state government of Berlin has confirmed it is facing an extortion attempt following a significant compromise of its administrative network, attributed to the **Rhysida** ransomware group. Simultaneously, **Manchester Airports Group (MAG)** has disclosed a data breach affecting customer information across its three major UK airports.
## Berlin Government Faces Ransomware Extortion
Berlin's state government has publicly confirmed that it is the target of an extortion attempt. This follows an August compromise of the city's state administrative network, which led to further data outflows identified in the **Senate Department for Mobility, Transport, Climate Protection and Environment** between August 7 and August 12, 2026.
The **Senate Chancellery** is still assessing the scope and content of the exfiltrated data, unable to rule out the theft of personal or other non-public information. While Berlin has not released an official figure for the data loss, the attackers claim to have exfiltrated 5.79 terabytes of data and personal information belonging to 12,076 individuals.
Governing Mayor **Kai Wegner** stated, "The state of Berlin is being blackmailed," emphasizing the government's refusal to meet the extortionists' demands. Investigations are ongoing by state criminal police, the public prosecutor, and federal security authorities.
### Rhysida Ransomware Group Implicated
German publication *Der Spiegel* first attributed the attack to the **Rhysida** ransomware group, citing an entry on their darknet leak site. This attribution was subsequently confirmed by leak-site monitoring services.
The **Rhysida** post, titled "Berlin, Germany," claims to have scanned 5.79 terabytes of data and approximately 1.44 million files. It lists eleven file categories, with maps and geodata files comprising the largest segment. No specific ransom amount was disclosed in the entry.
### Rhysida Tradecraft and Recommendations
A joint advisory from the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)**, the **Federal Bureau of Investigation (FBI)**, and the **Multi-State Information Sharing and Analysis Center (MS-ISAC)** details **Rhysida's** common initial access vectors:
* **Valid accounts on external-facing remote services**: Often exploiting compromised credentials for VPN access, particularly in organizations lacking multi-factor authentication (**MFA**).
* **Zerologon (CVE-2020-1472)**: An elevation of privileges vulnerability in **Microsoft's Netlogon Remote Protocol**, patched in August 2020.
* **Phishing**: A consistently successful method for gaining network access.
The advisory, issued in November 2023, reiterates that the FBI and CISA do not advocate paying ransoms, as it offers no guarantee of data recovery and may encourage further attacks. Key recommendations include prioritizing the remediation of known exploited vulnerabilities, implementing **MFA** across all services, and robust network segmentation.
Open-source intelligence also suggests similarities between **Rhysida** and **Vice Society** (tracked by **Microsoft** as **Storm-0832**), an overlap previously highlighted by **Check Point** in 2023.
As of August 29, **Rhysida** has claimed 280 victims globally, with nine in Germany, including the Stuttgart city administration and the aid organization **Welthungerhilfe**. The **Port of Seattle**, which operates **Seattle-Tacoma International Airport**, was also listed as a victim in September 2024.
Berlin's Interior Senator **Iris Spranger** confirmed that no data relevant to the upcoming September 20 **Abgeordnetenhaus** election was compromised, and the election environment remains secure.
## Manchester Airports Group Confirms Customer Data Theft
**Manchester Airports Group (MAG)**, operator of **Manchester**, **London Stansted**, and **East Midlands** airports, announced on August 27 that an unauthorized third party had accessed customer data. The breach affects information related to car park, lounge, and Fast Track bookings, as well as in-airport WiFi sign-ups.
**MAG** assures the public that "at no point has passenger safety or aviation security been compromised," and airport operations remain unaffected. The stolen data includes email addresses, phone numbers, vehicle registrations, and postcodes. Critically, **MAG** states that neither the company nor the compromised system holds customers' bank or payment details.
The incident did not impact operational airport systems. As a precautionary measure, access to the online "Manage My Booking" service has been suspended. Customers with bookings within the next 72 hours are directed to customer services.
While **MAG** has not released an official count, reports suggest approximately 8.7 million customers may be affected. The company has directly contacted impacted individuals, advising them to review the **U.K. National Cyber Security Center's (NCSC)** data breach guidance and remain vigilant against suspicious communications.