AI Security AI安全 6h ago Updated 2h ago 更新于 2小时前 43

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network 柏林拒绝向窃取市政府网络数据的黑客支付赎金

Berlin's state administrative network was compromised in August 2026 by the Rhysida ransomware group, with 5.79 terabytes of data and personal information on approximately 12,076 individuals allegedly exfiltrated The Berlin government publicly refused to pay the ransom, aligning with FBI/CISA guidance that payment does not guarantee recovery and may embolden further attacks Rhysida's initial access routes include compromised VPN credentials (especially where MFA is absent), Zerologon privilege e 柏林州政府网络于2026年8月遭勒索软件组织Rhysida攻击,窃取约5.79TB数据及12,076人个人信息,政府明确拒绝支付赎金 Rhysida组织典型攻击路径包括:利用失效凭证访问外部VPN、利用Zerologon漏洞(CVE-2020-1472)提权、钓鱼邮件,CISA/FBI/MS-ISAC联合建议优先修复已知漏洞并启用MFA 曼彻斯特机场集团(MAG)确认客户数据被盗,涉及停车场、贵宾室、Fast Track预订及WiFi注册信息,含邮箱、电话、车牌和邮编,但航空安全未受影响 截至2026年8月29日,Rhysida组织已有280名受害者,其中德国9起,包括斯图加特市政府和Welt

68
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Berlin's state administrative network was compromised in August 2026 by the Rhysida ransomware group, with 5.79 terabytes of data and personal information on approximately 12,076 individuals allegedly exfiltrated
  • The Berlin government publicly refused to pay the ransom, aligning with FBI/CISA guidance that payment does not guarantee recovery and may embolden further attacks
  • Rhysida's initial access routes include compromised VPN credentials (especially where MFA is absent), Zerologon privilege escalation, and phishing attacks
  • Manchester Airports Group confirmed a separate data breach involving customer data from car park, lounge, Fast Track, and WiFi sign-ups across three airport sites
  • The breach did not affect election-related data for Berlin's September 20 Abgeordnetenhaus election, and airport operations continued normally

Why It Matters

This incident highlights the persistent threat of ransomware groups like Rhysida targeting critical government infrastructure and the importance of foundational cybersecurity hygiene—particularly MFA adoption and vulnerability patching. The Berlin case also demonstrates the growing trend of governments publicly refusing ransom payments, which may influence policy responses worldwide.

Technical Details

  • Attack Vector: Rhysida gained initial access through compromised valid accounts on external-facing VPN services, exploiting organizations lacking default multi-factor authentication; Zerologon (CVE-2020-1472) and phishing were also documented entry points
  • Data Exfiltration: Forensic work identified data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7-12, 2026; attackers claimed 5.79 TB across 1.44 million files, including 124,823 maps and geodata files
  • Network Isolation: Two affected departments were cut off from the state network on August 14, with all Senate departments reconnected by August 23; housing benefit applications and payments were disrupted during the outage
  • Attribution: Rhysida, a double extortion ransomware group, was identified via darknet leak site activity; the group has 280 listed victims as of August 29, with nine in Germany including Stuttgart city administration and Welthungerhilfe
  • MAG Breach: Unauthorized third party obtained customer data (emails, phone numbers, vehicle registrations, postcodes) from booking and WiFi systems at Manchester, London Stansted, and East Midlands airports

Industry Insight

  • Government organizations should prioritize enabling MFA by default on all external-facing remote services and VPNs, as credential compromise remains the leading initial access vector for ransomware groups
  • The Berlin government's refusal to pay sets a precedent that may encourage other municipalities to adopt similar no-payment policies, potentially reducing ransomware profitability
  • Organizations should maintain operational continuity plans for critical services, as demonstrated by MAG's ability to continue airport operations despite the data breach

TL;DR

  • 柏林州政府网络于2026年8月遭勒索软件组织Rhysida攻击,窃取约5.79TB数据及12,076人个人信息,政府明确拒绝支付赎金
  • Rhysida组织典型攻击路径包括:利用失效凭证访问外部VPN、利用Zerologon漏洞(CVE-2020-1472)提权、钓鱼邮件,CISA/FBI/MS-ISAC联合建议优先修复已知漏洞并启用MFA
  • 曼彻斯特机场集团(MAG)确认客户数据被盗,涉及停车场、贵宾室、Fast Track预订及WiFi注册信息,含邮箱、电话、车牌和邮编,但航空安全未受影响
  • 截至2026年8月29日,Rhysida组织已有280名受害者,其中德国9起,包括斯图加特市政府和Welthungerhilfe慈善组织
  • 柏林州数据保护专员及联邦信息安全局(BSI)已介入,9月20日议会选举相关数据未受影响,选举环境被视为安全

为什么值得看

本文揭示了2026年欧洲关键基础设施和政府机构面临的勒索软件威胁态势,Rhysida作为活跃的双向勒索组织,其攻击手法和受害范围对公共部门网络安全具有警示意义。同时,曼彻斯特机场数据泄露事件反映了交通枢纽等民用设施同样面临严峻的数据保护挑战,两起事件共同凸显了MFA部署、漏洞管理和网络分段在防御体系中的核心地位。

技术解析

  • 攻击手法与漏洞利用:Rhysida组织主要通过三种初始访问途径入侵——使用被盗有效凭证访问外部VPN(尤其针对未默认启用MFA的组织)、利用Zerologon漏洞(CVE-2020-1472)进行权限提升、以及钓鱼攻击。该漏洞影响Microsoft Netlogon Remote Protocol,微软已于2020年8月11日发布补丁。
  • 数据泄露规模与内容:柏林事件中攻击者声称扫描5.79TB数据、约144万文件,其中最大类别为124,823个地图和地理数据文件,占总文件数约四分之一;涉及12,076人个人信息。曼彻斯特机场事件泄露数据包括邮箱、电话、车牌号和邮编,不涉及银行账户信息。
  • 组织关联与活动范围:Rhysida与Vice Society(微软追踪为Storm-0832)存在操作手法相似性,Check Point于2023年已指出两者重叠。截至2026年8月29日,该组织已公开280名受害者,美国西雅图港(运营西雅图-塔科马国际机场)亦在列。
  • 应急响应与系统恢复:柏林受影响部门于8月14日断网,8月23日全部重新连接,住房福利申请和支付服务曾中断; forensic work和全网扫描仍在持续。曼彻斯特机场运营和停车服务保持正常。

行业启示

  • MFA强制部署已成底线要求:多起事件表明,未默认启用多因素认证的外部VPN访问是勒索软件组织的主要突破口,公共机构和关键基础设施应立即审查并强化身份验证机制。
  • 漏洞管理需建立优先级响应机制:Zerologon等已知高危漏洞补丁发布已超五年仍被利用,组织应建立漏洞修复SLA,对CVSS评分9.0以上的漏洞实施紧急响应流程。
  • 不支付赎金策略需配套完善的数据备份与恢复能力:FBI/CISA明确不建议支付赎金,但政府机构需提前建立离线备份、网络分段和快速恢复预案,以降低勒索攻击对关键服务的实际影响。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全