{"id":158102,"date":"2026-09-02T23:37:16","date_gmt":"2026-09-02T23:37:16","guid":{"rendered":"https:\/\/www.europesays.com\/dk\/158102\/"},"modified":"2026-09-02T23:37:16","modified_gmt":"2026-09-02T23:37:16","slug":"berlin-rejects-rhysida-ransomware-blackmail","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/dk\/158102\/","title":{"rendered":"Berlin Rejects Rhysida Ransomware Blackmail"},"content":{"rendered":"<p class=\"text-muted\">\n                                            <a href=\"https:\/\/www.bankinfosecurity.com\/fraud-management-cybercrime-c-409\" id=\"asset_topic_1_1\" rel=\"nofollow noopener\" target=\"_blank\">Fraud Management &amp; Cybercrime<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/geo-specific-c-518\" id=\"asset_topic_1_2\" rel=\"nofollow noopener\" target=\"_blank\">Geo-Specific<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/ransomware-c-399\" id=\"asset_topic_1_3\" rel=\"nofollow noopener\" target=\"_blank\">Ransomware<\/a>\n                                                    <\/p>\n<p>                    Extortion Group With Suspected Russian Provenance Imposes Friday Deadline<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/david-meyer-i-7589\" rel=\"nofollow noopener\" target=\"_blank\">David Meyer<\/a>                                                     \u2022<br \/>\n                        September 2, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/berlin-rejects-rhysida-ransomware-blackmail-a-32731#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/dk\/wp-content\/uploads\/2026\/09\/berlin-rejects-rhysida-ransomware-blackmail-image_large-8-a-32731.jpg\" alt=\"Berlin Rejects Rhysida Ransomware Blackmail\" class=\"img-responsive \"\/><br \/>\n                Image: TTstudio\/Shutterstock\/ISMG            <\/p>\n<p>Berlin officials temporarily canceled remote work and are scouring all their systems, after the notorious Rhysida ransomware gang attacked the German city-state in a double-extortion attempt that will come to some kind of conclusion this Friday.<\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/demostracion-del-producto-backup-y-recuperacion-de-vm-a-20235?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Demostraci\u00f3n Del Producto: Backup Y Recuperaci\u00f3n De VM<\/a><\/p>\n<p>The attack was detected on Aug. 14, and all departments of the Berlin Senate were immediately disconnected from their central network. Those affected in the attack were the departments for urban development, construction and housing &#8211; causing significant disruptions for those trying to claim housing benefits &#8211; and for mobility, transport, environment and climate protection. <\/p>\n<p>Berlin mayor Kai Wegner, who withdrew a re-election bid in July, <a href=\"https:\/\/www.berlin.de\/aktuelles\/10581479-958090-hackerangriff-auf-landesnetz-arbeit-mit-.html\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> initially that no sensitive data appeared to have been compromised. That assertion didn\u2019t last long. By last Friday, following forensic investigations, Wegner admitted that public and non-public data may have been taken between Aug. 7 and Aug. 12, and that the attackers were trying to blackmail the Berlin government. <\/p>\n<p>&#8220;The demand came in early on Thursday evening,&#8221; Wegner said. &#8220;Berlin will not give in to blackmail.&#8221;<\/p>\n<p>According to multiple reports citing security officials and information on the darkweb, and with <a href=\"https:\/\/www.morgenpost.de\/berlin\/article413028932\/untersuchungen-zu-cyberangriff-laufen-weiter-steckt-russland-dahinter.html\" target=\"_blank\" rel=\"nofollow noopener\">confirmation<\/a> from the Berlin Senate on Tuesday, the culprit was Rhysida, a prolific outfit that often targets organizations in the United States. Multiple <a href=\"https:\/\/www.bankinfosecurity.com\/rhysida-hacking-group-strikes-more-healthcare-providers-a-27677\" rel=\"nofollow noopener\" target=\"_blank\">American healthcare<\/a> providers have <a href=\"https:\/\/www.bankinfosecurity.com\/delaware-health-system-plans-to-settle-rhysida-hack-lawsuit-a-29512\" rel=\"nofollow noopener\" target=\"_blank\">fallen victim<\/a> although a Ransom-DB analysis in February <a href=\"https:\/\/www.ransom-db.com\/blog\/rhysida-ransomware-group-analysis-2026\" target=\"_blank\" rel=\"nofollow noopener\">found<\/a> that almost half of its known attacks landed elsewhere in the world, with Europe featuring strongly. <\/p>\n<p>Rhysida employs the now-standard tactic of double extortion, threatening leaks and the ongoing encryption of data on the victim\u2019s systems. It targeted the German city of Stuttgart in May of this year, demanding 5 bitcoin in payment for data it claimed to have stolen, although neither the theft nor any ransom payment have been publicly confirmed.<\/p>\n<p>This time, the groups wants 30 bitcoins from Berlin, and says it will publish the data if it doesn\u2019t get the cryptocurrency by this coming Friday. Rhysida is running an auction until then, claiming that it will only give the data to one buyer.<\/p>\n<p>According to Rhysida, the group claims to have 5.79 terabytes of Berlin Senate data, including 16,389 emails, 11,963 phone numbers, 148 banking codes, tens of thousands of contracts and judicial documents, and thousands of personnel files containing more personal data. <\/p>\n<p>Rhysida also says it took credentials that had been stored in plaintext, along with classified materials and vulnerability analyses of Berlin\u2019s water supply.<\/p>\n<p>Berlin Senate spokeswoman Christine Richter <a href=\"https:\/\/www.youtube.com\/live\/i7qi13FWbac?si=L39Z4ZF9Ca1yj2A5&amp;t=2213\" target=\"_blank\" rel=\"nofollow noopener\">reiterated<\/a> at a Tuesday press conference that the city would not cough up. She said a &#8220;significant amount of data&#8221; &#8211; some of it non-public &#8211; had been compromised at the two departments, but so far there was no evidence of any other departments being affected. Still, just to make sure, &#8220;all systems within the state of Berlin must be scanned to rule out the possibility that further data has been exfiltrated.&#8221; <\/p>\n<p>She said there are 12,000 such systems that need to be examined, though all the systems at the two affected departments have already been checked. Richter\u2019s office did not respond to a request for information regarding how long all of this might take.<\/p>\n<p>On Tuesday, Richter also appeared to confirm Rhysida\u2019s claim scoring credentials, explaining that passwords for &#8220;certain specialized applications&#8221; had been compromised, with the result that the two affected departments have &#8220;decided to implement additional security measures&#8221; that have resulted in &#8220;some operational restrictions, though both departments remain reachable by email.&#8221;<\/p>\n<p>The Berlin newspaper Tagesspiegel <a href=\"https:\/\/www.tagesspiegel.de\/berlin\/nach-hackerangriff-und-passwortklau-zwei-berliner-senatsverwaltungen-stoppen-homeoffice-zugriff-auf-ihre-netze-16001565.html\" target=\"_blank\" rel=\"nofollow noopener\">reported<\/a> sources in the departments as saying their home office access had been shut off on Monday &#8211; they can send and receive emails, but they can\u2019t establish VPN access to their internal networks, forcing them to work from their computers in the office. Richter confirmed this to the paper.<\/p>\n<p>Tagesspiegel <a href=\"https:\/\/www.tagesspiegel.de\/berlin\/wasserversorgung-passworter-dienstvergehen-diesen-berliner-datenschatz-bieten-die-hacker-im-darknet-an-15998171.html \" target=\"_blank\" rel=\"nofollow noopener\">reported<\/a> earlier in the week that snippets of the stolen data showing unencrypted login details had been helpfully stored in files with names like Password.docx, and that the passwords themselves included the likes of &#8220;Sunshine13&#8221; &#8211; not compliant with the recommendations of the Federal Office for Information Security, it noted.<\/p>\n<p>As for what will happen if Berlin sticks to its guns and withholds payment, Rhysida has a history of making good on its threats. In 2023, after the British Library refused to pay the group 20 bitcoin, it published around 600 gigabytes of the stolen files, including staff details that <a href=\"https:\/\/www.independent.co.uk\/news\/uk\/home-news\/british-library-strike-cyber-attack-b2855495.html\" target=\"_blank\" rel=\"nofollow noopener\">reportedly<\/a> forced some to move home. <\/p>\n<p>The Berlin Senate is adamant that the coming state election on Sept. 20 will not be affected by the hack. &#8220;The election environment is secure, according to our security officers,&#8221; said Interior Senator Iris Spranger.<\/p>\n<p>It remains unclear where Rhysida is based, although previous analyses have hinted at a connection with Russia and its satellites. The cybersecurity firm Cynet <a href=\"https:\/\/www.cynet.com\/blog\/rhysida-the-ransomware-gang-strikes-again\/\" target=\"_blank\" rel=\"nofollow noopener\">noted<\/a> in 2023 that Rhysida\u2019s ransomware software, ransom notes and leak site sometimes included snippets of Russian, and the group conspicuously avoided targeting organizations in Russia and other post-Soviet states. And, of course, Russia has been stepping up sabotage and drone attack efforts in Germany in the last year or two, due to Germany\u2019s support for Ukraine &#8211; on Tuesday the government <a href=\"https:\/\/www.dw.com\/en\/germany-interior-minister-warns-of-daily-hybrid-warfare\/a-78291550\" target=\"_blank\" rel=\"nofollow noopener\">accused<\/a> Russia of waging hybrid war.<\/p>\n<p>&#8220;There is no evidence of connections to Russia or even the Russian state&#8221; in the Berlin hack, Richter <a href=\"https:\/\/www.morgenpost.de\/berlin\/article413028932\/untersuchungen-zu-cyberangriff-laufen-weiter-steckt-russland-dahinter.html\" target=\"_blank\" rel=\"nofollow noopener\">told<\/a> the Berliner Morgenpost on Tuesday, &#8220;but such connections cannot be ruled out.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"Fraud Management &amp; Cybercrime , Geo-Specific , Ransomware Extortion Group With Suspected Russian Provenance Imposes Friday Deadline David&hellip;\n","protected":false},"author":2,"featured_media":158103,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[99],"tags":[43047,74128,74116,74119,74118,74117,112,74125,74126,74127,190,74129,17419,74120,74123,74124,46413,74122,74121,74131,16916,74130],"class_list":["post-158102","post","type-post","status-publish","format-standard","has-post-thumbnail","category-berlin","tag-anti-money-laundering","tag-authentication","tag-bank-information-security","tag-bank-information-security-regulations","tag-bank-regulations","tag-banking-information-security","tag-berlin","tag-fdic","tag-fincen","tag-gao","tag-germany","tag-glba","tag-identity-theft","tag-information-security","tag-information-security-articles","tag-information-security-events","tag-information-security-news","tag-information-security-webinars","tag-information-security-white-papers","tag-phishing","tag-risk-management","tag-sarbanes-oxley-sox"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@dk\/117204081036265799","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/posts\/158102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/comments?post=158102"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/posts\/158102\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/media\/158103"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/media?parent=158102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/categories?post=158102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/dk\/wp-json\/wp\/v2\/tags?post=158102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}