Berlin officials have refused to pay a multi-million euro ransom after a cyberattack resulted in the theft of nearly six terabytes of municipal data.

Berlin officials have officially declared that the German capital will not yield to the demands of cybercriminals following a significant security breach. The city’s leadership confirmed that a sophisticated hacking group has targeted municipal systems, resulting in the theft of a large volume of sensitive data. Mayor Kai Wegner issued a strong public statement affirming that the local government refuses to engage in negotiations or pay any ransom, maintaining a firm stance against the tactics employed

The incident, which surfaced publicly late last week, has triggered an extensive investigation involving state police, local prosecutors, and federal security agencies. Authorities are currently working to determine the full extent of the intrusion and to identify the specific nature of the information that has been compromised. The government has prioritized the security of its infrastructure and is working around the clock to mitigate the impact of the breach on public services.

Reports indicate that the criminal organization behind the attack has demanded a payment of 30 bitcoin, which is currently valued at approximately €2 million or £1.7 million. The hackers have utilized a dark web platform to publicize their demands, setting a strict seven-day countdown before they intend to auction off the stolen data. The threat actor, identified as the Rhysida group, is allegedly holding nearly six terabytes of information obtained from city servers.

This group has gained notoriety for its aggressive approach to digital extortion, often targeting government entities and large-scale institutions. The data potentially at risk includes internal contracts, non-disclosure agreements, staff personnel files, and numerous personal contact details. Officials have acknowledged that they cannot rule out the possibility that non-public personal information has been accessed, prompting a comprehensive review of the city's digital archives to assess the exposure of its citizens and employees.

The cyberattack has already caused measurable disruptions to Berlin’s administrative functions. Initial signs of the breach were detected in early August, leading to the proactive shutdown of several department networks on August 14. This move was intended to isolate the threat but resulted in the suspension of critical services, including the processing of housing benefits and various municipal payment applications, leaving many residents temporarily unable to access necessary support.

As forensic investigations continue, officials have identified that the breach extended into the transport and environment departments. While the city works to restore these vital services, the focus remains on securing the integrity of the remaining network infrastructure. Despite the scale of the disruption, the government has moved to reassure the public that essential processes are being prioritized and that security measures are being reinforced to prevent further unauthorized access.

The Rhysida group, believed to be operating out of Russia and Eastern Europe, has been active since 2023 and has a history of high-profile attacks. They previously targeted the British Museum, successfully extracting hundreds of thousands of files and disrupting operations globally. When the museum refused to meet their financial demands, the group proceeded to publish the stolen personal data of staff and visitors on the dark web, demonstrating a pattern of behavior that Berlin authorities are now actively working to counter.

With Berlin approaching an upcoming election period, concerns regarding the security of democratic processes have been raised. However, officials have maintained that the city's election infrastructure remains secure and has not been compromised breach, the protection of personal privacy for the city's residents, and the ongoing collaboration with federal law enforcement to track those responsible for the attack.

Leave a Reply

Your email address will not be published. Required fields are marked *