Berlin Cyber Incident Prompts Data Theft Investigation And Ransom Refusal

Berlin Cyber Incident Prompts Data Theft Investigation And Ransom Refusal

Berlin’s state government has confirmed that it is facing an extortion attempt following the cyberattack on the city’s state administrative network that was disclosed earlier this month. During a special Senate session, Governing Mayor Kai Wegner stated that the state of Berlin would not meet the demands of those responsible for the incident. Authorities also revealed that forensic investigations have identified additional data transfers involving the Senate Department for Mobility, Transport, Climate Protection and Environment, with the activity occurring between August 7 and August 12, 2026. Investigators are continuing to determine the scope and content of the information involved, and officials said it cannot yet be ruled out that personal or other non public data was included. According to the Senate Chancellery, the department initially reported suspicious data transfers on August 7, seven days before it was disconnected from the state network on August 14. While Berlin has not disclosed the amount of information involved, a post published on a ransomware leak site on August 28 claimed that 5.79 terabytes of data, including information relating to 12,076 individuals, had been obtained. As of August 29, authorities had not issued guidance for individuals whose information may have been affected. The Senate Chancellery confirmed that the state criminal police, public prosecutors, and federal security agencies are investigating the incident, although no official attribution has been announced. Reports from Der Spiegel and leak monitoring services have linked the incident to the Rhysida ransomware group after an entry titled “Berlin, Germany” appeared on the group’s leak site.

The leak site claims to contain approximately 5.79 terabytes of data and around 1.44 million files, although it identifies the victim only as Berlin, Germany rather than naming a specific government department. No ransom demand has been publicly disclosed. Earlier guidance issued jointly by CISA, FBI, and the Multi State Information Sharing and Analysis Center describes Rhysida as a ransomware group that commonly gains initial access through compromised VPN credentials, phishing attacks, or previously disclosed vulnerabilities such as Zerologon. The advisory also recommends that organizations strengthen security by enabling multi factor authentication, addressing known vulnerabilities promptly, and segmenting networks to limit the spread of ransomware. Security researchers have previously noted similarities between Rhysida and the Vice Society threat activity. According to monitoring services, Rhysida has been linked to 280 victims worldwide as of August 29, including nine organizations in Germany. Recent incidents listed include the Stuttgart city administration in May 2026 and the humanitarian organization Welthungerhilfe in June 2025, while previous victims also include the Port of Seattle, which operates Seattle Tacoma International Airport. Berlin officials said the Federal Office for Information Security and the state data protection commissioner continue to receive updates as the investigation progresses. Interior Senator Iris Spranger also stated that current assessments indicate no data related to the September 20 Abgeordnetenhaus election was affected and that election related systems remain secure. Berlin first disclosed the compromise on August 17 after forensic analysis confirmed unauthorized access to the state network, and the affected departments were isolated. All Senate departments were reconnected on August 23, although forensic examinations and network scanning activities remain ongoing.

In a separate cybersecurity incident, Manchester Airports Group confirmed on August 27 that an unauthorized third party obtained customer information associated with car park bookings, airport lounge reservations, Fast Track services, and public WiFi registrations at Manchester, London Stansted, and East Midlands airports. The company stated that airport operations, customer parking services, passenger safety, and aviation security were not affected by the incident. According to Manchester Airports Group, the information involved includes email addresses, telephone numbers, vehicle registration details, and postcodes. The company emphasized that neither it nor the affected booking system stores customers’ bank account or payment information. Officials also clarified that the affected platform operates separately from Manchester Airports Group’s operational airport systems. The organization has advised passengers to continue travelling as normal while security investigations continue. As a precaution, access to the online Manage My Booking service has been temporarily suspended, and customers requiring booking changes within the next 72 hours have been directed to contact customer services directly during business hours. Although media reports have cited approximately 8.7 million potentially affected customers based on comments from a company spokesperson, Manchester Airports Group has not confirmed the number in its official statements.

Manchester Airports Group said it has contacted affected customers directly and encouraged them to remain alert for suspicious emails, text messages, and phone calls that could attempt to misuse personal information obtained during the incident. The company has also directed customers to guidance published by the United Kingdom National Cyber Security Center regarding recommended actions following a data breach. Both the Berlin government incident and the Manchester Airports Group disclosure highlight the continued challenges organizations face in protecting sensitive information while responding to increasingly sophisticated cyber threats. Authorities and affected organizations continue to investigate both incidents while working to determine the full impact of the unauthorized access and strengthen ongoing security measures.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment