Cybersecurity: Hacker Ultimatum Expires as Criminal Group Publishes Sensitive Data
Translated from German and summarized by DistantNews. Read the original for the full story.
At a glance
- The Rhysida ransomware group published data stolen in an attack on Berlin’s government network after the city administration refused to pay a ransom of 30 bitcoin, worth about 2 million euros.
- Chaos Computer Club expert Joachim Selzer said the publicly accessible files included personnel matters, employment records, signed applications and other internal information that could facilitate identity theft.
- Cybersecurity experts supported Berlin’s decision not to pay, although they warned that publishing the data could have serious consequences.
The ultimatum issued by the Rhysida hacker group has expired, and the criminals say they have made the stolen data from Berlin’s administration publicly accessible on the dark web.
Every file has been uploaded to the publicly accessible area. Have fun browsing, data hunters!
“Every file has been uploaded to the publicly accessible area. Have fun browsing, data hunters!” the group wrote on its website after its ransom deadline passed on Friday afternoon. The attackers had demanded 30 bitcoin, worth around 2 million euros.
Joachim Selzer, a spokesperson for the Chaos Computer Club, told the German Press Agency that the group appeared to have published the complete dataset. The files reportedly include personnel matters, employment references and applications bearing officials’ signatures. One example was an application for a new mobile phone that included the employee’s signature.
From what I can see here now, they have put the complete dataset live for everyone to view.
Selzer warned that the material could be useful for identity theft. Criminals who know enough about a person can impersonate them more convincingly and judge what information they need to place orders in that person’s name. He said the data would more likely be misused over the medium term because the large collection would first need to be reviewed.
These are a lot of internal data that were not intended for the public. I can see personnel matters here, including employment references.
Berlin’s Senate had already said it would not give in to the extortion attempt or pay a ransom. IT security expert Christof Fischer welcomed that position, noting that the state is legally prohibited from making extortion payments. He also said incidents like the Berlin attack remain difficult because stolen data in criminals’ hands can cause serious harm when published.
The data are in the hands of criminals, and publication often has very damaging effects.
Originally published by Die Zeit in German. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.