Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state administrative network was compromised in August 2026 by the Rhysida ransomware group, with 5.79 terabytes of data and personal information on approximately 12,076 individuals allegedly exfiltrated The Berlin government publicly refused to pay the ransom, aligning with FBI/CISA guidance that payment does not guarantee recovery and may embolden further attacks Rhysida's initial access routes include compromised VPN credentials (especially where MFA is absent), Zerologon privilege e
Analysis
TL;DR
- Berlin's state administrative network was compromised in August 2026 by the Rhysida ransomware group, with 5.79 terabytes of data and personal information on approximately 12,076 individuals allegedly exfiltrated
- The Berlin government publicly refused to pay the ransom, aligning with FBI/CISA guidance that payment does not guarantee recovery and may embolden further attacks
- Rhysida's initial access routes include compromised VPN credentials (especially where MFA is absent), Zerologon privilege escalation, and phishing attacks
- Manchester Airports Group confirmed a separate data breach involving customer data from car park, lounge, Fast Track, and WiFi sign-ups across three airport sites
- The breach did not affect election-related data for Berlin's September 20 Abgeordnetenhaus election, and airport operations continued normally
Why It Matters
This incident highlights the persistent threat of ransomware groups like Rhysida targeting critical government infrastructure and the importance of foundational cybersecurity hygiene—particularly MFA adoption and vulnerability patching. The Berlin case also demonstrates the growing trend of governments publicly refusing ransom payments, which may influence policy responses worldwide.
Technical Details
- Attack Vector: Rhysida gained initial access through compromised valid accounts on external-facing VPN services, exploiting organizations lacking default multi-factor authentication; Zerologon (CVE-2020-1472) and phishing were also documented entry points
- Data Exfiltration: Forensic work identified data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7-12, 2026; attackers claimed 5.79 TB across 1.44 million files, including 124,823 maps and geodata files
- Network Isolation: Two affected departments were cut off from the state network on August 14, with all Senate departments reconnected by August 23; housing benefit applications and payments were disrupted during the outage
- Attribution: Rhysida, a double extortion ransomware group, was identified via darknet leak site activity; the group has 280 listed victims as of August 29, with nine in Germany including Stuttgart city administration and Welthungerhilfe
- MAG Breach: Unauthorized third party obtained customer data (emails, phone numbers, vehicle registrations, postcodes) from booking and WiFi systems at Manchester, London Stansted, and East Midlands airports
Industry Insight
- Government organizations should prioritize enabling MFA by default on all external-facing remote services and VPNs, as credential compromise remains the leading initial access vector for ransomware groups
- The Berlin government's refusal to pay sets a precedent that may encourage other municipalities to adopt similar no-payment policies, potentially reducing ransomware profitability
- Organizations should maintain operational continuity plans for critical services, as demonstrated by MAG's ability to continue airport operations despite the data breach
Disclaimer: The above content is generated by AI and is for reference only.