Cybercrime: AI to help assess the risk posed by hacked Berlin data
Translated from German and summarized by DistantNews. Read the original for the full story.
At a glance
- Cybercriminals have published about 1.3 million files stolen from Berlinโs administration network after the state declined a ransom demand of roughly 2 million euros.
- Berlin plans to use AI tools to categorize the files and prioritize those posing the greatest potential risk.
- Officials said the attackโs entry point remains unclear, while the state is investigating what information the files contain.
Berlin officials are turning to artificial intelligence to sort through roughly 1.3 million files that cybercriminals released online after the state refused to pay a ransom.
The attackers gave Berlinโs Senate until Friday afternoon to pay 30 bitcoins, worth about 2 million euros. After the deadline passed, they published around 755,000 files, Chief Digital Officer Florian Hauer told the Digitalization Committee. A further package released overnight from Saturday to Sunday contained another 550,000 to 560,000 files.
That is an immense sum of files that has been taken, purely in numerical terms.
โThat is an immense sum of files that has been taken, purely in numerical terms,โ Hauer said. The immediate task, he explained, is to determine what information the files contain. Reviewing each file individually would be extremely time-consuming, particularly because a single file may contain several documents.
AI tools are therefore expected to categorize the material and display different levels of risk. Investigators would then examine the files considered most hazardous first. Hauer said officials had treated the broad publication of the data as the most likely outcome after Berlin rejected the ransom demand. โThat is exactly what happened,โ he said.
That is exactly what happened.
Alexander Slotty, a state secretary in the Senate Department for Urban Development, said it was still unclear how and where the attack began. The Rhysida hacking group is known to use phishing emails, which can give attackers access to a system when recipients click on a link and allow malware to enter.
โThere is really nothing to sugarcoat about this situation. Nevertheless, there is also good news,โ Slotty said. He said the leaked material represented about 1% of the data stored on the departmentโs servers. โOne percent can still mean more than a million pieces of data, and of course that is overwhelming,โ he said. โBut it is also not more than that.โ
There is really nothing to sugarcoat about this situation. Nevertheless, there is also good news.
Originally published by Die Zeit in German. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.