AI Security AI安全 7h ago Updated 2h ago 更新于 2小时前 38

Berlin Won't Pay Extortion Group Claiming Data Theft 柏林拒绝向声称窃取数据的勒索组织支付赎金

Rhysida ransomware group claimed responsibility for a major cyberattack on Berlin's municipal government networks, stealing over 5.7 terabytes of sensitive data The attack targeted the Senate Department for Mobility, Transport, Climate Protection, and Environment, as well as the Senate Department for Urban Development, Construction, and Housing Berlin's leadership, including Governing Mayor Kai Wegner, confirmed the city will not pay the 30 Bitcoin (~$2.3 million) ransom demand Data exfiltrated Rhysida勒索软件组织声称对柏林市政府网络遭受的重大网络攻击负责,窃取超过5.7TB敏感数据 此次攻击针对柏林市 mobility、交通、气候保护和环境参议院部门,以及城市发展和建设住房参议院部门 柏林市政府领导层,包括执政市长Kai Wegner,确认该市不会支付30比特币(约230万美元)的勒索要求 泄露数据包括超过12,000人的个人信息、16,000个电子邮件地址、工资单数据、密码、IBAN账号和机密政府文件 入侵发生在2025年8月7日至12日期间,攻击于8月14日被发现,随即立即关闭了网络

55
Hot 热度
55
Quality 质量
50
Impact 影响力

Analysis 深度分析

TL;DR

  • Rhysida ransomware group claimed responsibility for a major cyberattack on Berlin's municipal government networks, stealing over 5.7 terabytes of sensitive data
  • The attack targeted the Senate Department for Mobility, Transport, Climate Protection, and Environment, as well as the Senate Department for Urban Development, Construction, and Housing
  • Berlin's leadership, including Governing Mayor Kai Wegner, confirmed the city will not pay the 30 Bitcoin (~$2.3 million) ransom demand
  • Data exfiltrated included personal information of over 12,000 individuals, 16,000 email addresses, payroll data, passwords, IBANs, and confidential government documents
  • The breach occurred between August 7-12, 2025, with the attack discovered on August 14, prompting immediate network shutdowns

Why It Matters

This incident highlights the escalating threat of ransomware targeting critical municipal infrastructure and government entities, demonstrating how cyberattacks on local governments can compromise vast amounts of citizen data. It underscores the growing trend of ransomware groups like Rhysida specifically targeting public sector organizations with large data holdings, and the difficult policy decisions governments face when deciding whether to negotiate with threat actors.

Technical Details

  • Attack vector and scope: The Rhysida ransomware group infiltrated Berlin's government networks, exfiltrating 5.7 TB of data spanning multiple departments before encrypting systems
  • Data compromised: Over 12,000 individuals' personal information, 16,000 email addresses, ~12,000 phone numbers, plaintext credentials, IBANs, payroll information, passport/ID data, legal documents, contracts, and HR files
  • Ransom demand: 30 Bitcoin (approximately $2.3 million at the time), demanded via the group's Tor-based leak site where Berlin was briefly listed on August 28
  • Containment measures: Both affected department networks were shut down on August 14; investigation involves state criminal police, federal security agencies, and the public prosecutor's office
  • Timeline: Data theft occurred August 7-12; incident discovered August 14; Rhysida claimed responsibility on August 28

Industry Insight

  • Government entities should treat ransom payment as a last resort; Berlin's stance reinforces the growing institutional resistance to funding criminal operations, though this also means accepting the reputational and legal consequences of breached data
  • The scale of data exfiltration (5.7 TB) from municipal networks demonstrates that even local government organizations are prime targets due to often-lax cybersecurity postures compared to federal agencies
  • Organizations should prioritize data classification, encryption at rest and in transit, and zero-trust architectures to limit the blast radius of potential breaches, especially for departments handling sensitive citizen information

摘要

Rhysida勒索软件组织声称对柏林市政府网络遭受的重大网络攻击负责,窃取超过5.7TB敏感数据
此次攻击针对柏林市 mobility、交通、气候保护和环境参议院部门,以及城市发展和建设住房参议院部门
柏林市政府领导层,包括执政市长Kai Wegner,确认该市不会支付30比特币(约230万美元)的勒索要求
泄露数据包括超过12,000人的个人信息、16,000个电子邮件地址、工资单数据、密码、IBAN账号和机密政府文件
入侵发生在2025年8月7日至12日期间,攻击于8月14日被发现,随即立即关闭了网络

深度分析

简要总结

  • Rhysida勒索软件组织声称对柏林市政府网络遭受的重大网络攻击负责,窃取超过5.7TB敏感数据
  • 攻击针对柏林市 mobility、交通、气候保护和环境参议院部门,以及城市发展和建设住房参议院部门
  • 柏林市政府领导层,包括执政市长Kai Wegner,确认该市不会支付30比特币(约230万美元)的勒索要求
  • 泄露数据包括超过12,000人的个人信息、16,000个电子邮件地址、工资单数据、密码、IBAN账号和机密政府文件
  • 入侵发生在2025年8月7日至12日期间,攻击于8月14日被发现,随即立即关闭了网络

为何重要

此事件凸显了针对关键市政基础设施和政府机构的勒索软件威胁日益升级,展示了针对地方政府的网络攻击如何可能导致大量公民数据泄露。这强调了像Rhysida这样的勒索软件组织专门针对拥有大量数据资产的公共部门组织的趋势,以及政府在决定是否与威胁行为者谈判时面临的艰难政策抉择。

技术细节

  • 攻击途径和影响范围:Rhysida勒索软件组织入侵柏林市政府网络,在加密系统前从多个部门窃取了5.7TB数据
  • 泄露数据:超过12,000人的个人信息、16,000个电子邮件地址、约12,000个电话号码、明文凭证、IBAN账号、工资信息、护照/身份证数据、法律

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全