DistantNews
Support us
🇩🇪 Germany /Technology

Berlin: Hackers apparently publish more than one million files

From Der Spiegel · () German

Translated from German and summarized by DistantNews. Read the original for the full story.

At a glance

News Named sources Ongoing story
  • The Rhysida ransomware group published a data package of about 5.8 terabytes after Berlin’s Senate refused its demand for 30 bitcoin, worth roughly 2 million euros.
  • The released material reportedly includes more than 1.4 million files, including records from administrative cases, contracts, critical infrastructure, court documents, emergency plans, passwords and login data.
  • Germany’s Federal Office for Information Security said the attackers appeared financially motivated and issued a warning about their multistage method.

The Rhysida hacker group has carried out its threat against Berlin’s Senate, placing almost six terabytes of data online after the authorities refused to pay a ransom of 30 bitcoin, roughly 2 million euros.

The attackers had started a countdown on their leak site after a major cyberattack on Berlin’s state administration. The deadline expired at about 3:35 p.m. on Friday. Shortly afterward, a data package measuring around 5.8 terabytes appeared on the darknet. Members of the group also posted lists of file names on social media. More than 1.4 million files could now be publicly accessible.

According to the extortionists, the material includes data from nearly 80,000 administrative-offense proceedings and more than 46,500 contracts. It also reportedly contains information on critical infrastructure facilities, court records, emergency plans, passwords and nearly 6,000 files containing login details.

No connection with state or politically motivated actors has so far been established.

· Germany’s Federal Office for Information SecurityThe agency assessed the attackers as financially motivated cybercriminals.

The Federal Office for Information Security said it believed the perpetrators came from the cybercrime sphere and acted solely for financial reasons. “No connection with state or politically motivated actors has so far been established,” the agency said in a notice cited by Der Spiegel. It warned other organizations about the attackers’ complex, multistage approach. Microsoft had previously described the same method in a blog post and named it “TerminalFix.”

The Senate’s refusal to respond to the extortion attempt received support from cybersecurity specialists. Bianca Kastl of the Chaos Computer Club said the decision was correct, arguing that paying would allow such groups to continue operating. IT security expert Christof Fischer said the situation remained difficult because criminals now held the data, while publication could cause serious harm. He said he knew of no case in which a ransom had been paid and the data had still been released. Fischer also said the attackers, who often live in Eastern European countries, might provide the data to local authorities in exchange for protection from investigations.

If you continued supporting these groups with money or other things, they would of course keep going. You have to financially dry them out.

· Bianca KastlThe Chaos Computer Club representative backed Berlin’s refusal to pay the ransom.
About this summary

Originally published by Der Spiegel in German. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.