Berlin Government Rocked by Second Data Leak Amid Rhysida Ransomware Investigation
German authorities are grappling with a fresh trove of stolen data from Berlin's government network, including login credentials, following an August cyberattack. While the **Rhysida** ransomware group claimed responsibility for the initial breach, the latest leak has prompted intensified security measures and a city-wide task force to assess the damage.
Berlin's government is once again in the crosshairs of cybercriminals, as a second batch of stolen data, including login credentials, was published online over the weekend. This follows a significant cyberattack discovered in mid-August that compromised two key Berlin ministries: urban development and housing, and transport, mobility, climate protection, and the environment.
### New Data Release Raises Alarm
On Sunday, Berlin's government confirmed the new data release contains login credentials but did not specify the systems they could access or their current validity. The perpetrators of this latest leak have not yet been identified.
In response, the city's urban development ministry has bolstered its security protocols, which may temporarily restrict access to some applications.
### "A Very Serious Crime"
**Berlin's data protection authority** stated on Friday that the attackers exfiltrated a substantial volume of data from the two affected ministries, subsequently publishing it online. Officials are currently sifting through the extensive files to determine the full scope of the breach.
The regulator confirmed that personal information of public employees was exposed, and data belonging to Berlin residents may also be compromised. Potentially affected information includes names, addresses, dates of birth, bank details, email addresses, telephone numbers, correspondence with government agencies, and copies of submitted documents.
**Governing Mayor Kai Wegner** condemned the incident on Saturday, calling it "a very serious crime committed against the State of Berlin." An additional task force has been established to review the leaked material and identify affected individuals.
### Berlin Refuses Ransom Payment
In late August, the **Rhysida** ransomware group publicly claimed responsibility for the initial breach, asserting they had stolen 5.79 terabytes of data, encompassing contracts, emails, passwords, and classified information.
While Berlin confirmed data theft and an extortion demand, officials have not publicly attributed the attack to **Rhysida** or corroborated the hackers' claims regarding the volume or content of the stolen material.
Mayor Wegner unequivocally stated last month that Berlin would not yield to blackmail. **Berlin Chief Digital Officer Florian Hauer** echoed this sentiment, declaring, "The State of Berlin will not be blackmailed."
The compromised systems were isolated from Berlin's broader government network on August 14th. Despite the disruption, both ministries remained operational, though some employees experienced temporary loss of email and internet access, impacting public services reliant on their systems.
### BSI Warns of Rhysida-Linked Campaign
Germany's **Federal Office for Information Security (BSI)** issued a separate warning on Friday about a cyberattack campaign linked to the financially motivated hackers behind **Rhysida**. While not explicitly naming Berlin, the agency confirmed it was informed in August about a government institution's compromise.
The **BSI** noted that the campaign bears resemblance to the **TerminalFix** attacks recently documented by **Microsoft**. These attacks involve compromising websites and displaying fake CAPTCHA verification pages, tricking visitors into executing malicious commands on their systems.
Reports received by the **BSI** indicate that attackers aimed to both steal data and deploy ransomware, enabling them to pressure victims with the threat of publishing exfiltrated information. The campaign utilizes malware identified as **LoremIpsumLoader** or **AxolotLoader**, which the **BSI** has linked to the same cybercriminal group associated with **Rhysida**.
"According to current findings, the campaign is being carried out by cybercriminal actors," the **BSI** stated. "So far, no connection to state-sponsored or politically motivated actors has been established."
Active since 2023, **Rhysida** has targeted governments, hospitals, schools, and companies globally. The **BSI** reports that government and public administration organizations are among the top five sectors frequently featured on the group's leak site, though education and healthcare remain primary targets. In 92% of cases where victims are named on Rhysida's leak site, stolen information is ultimately published.
The Berlin breach occurs shortly before the city's September 20th election. **Berlin Interior Senator Iris Spranger** previously stated that no evidence of data theft from election systems had been found, and the election environment remained secure.
