Berlin Government Data Leaked After Mayor Refuses €2 Million Ransom
The cybercrime group Rhysida published 1.4 million records on the dark web following a phishing breach of city networks.
The Berlin city government has suffered a massive data breach resulting in the leak of approximately 1.4 million records after city officials refused to pay a multimillion-euro ransom. The incident exposes sensitive administrative files and critical infrastructure details, highlighting significant vulnerabilities in the German capital's digital defenses.
The breach was executed by the cybercrime group Rhysida, which gained access to city networks after an employee at the Berlin Transportation Authority opened a phishing email. The attackers targeted the Department of Transportation and the Department of Public Works, stealing roughly 1.4 million records. Following the theft, Rhysida demanded 30 bitcoins—approximately €2 million ($2.3 million)—to prevent the data's release. Governing Mayor Kai Wegner rejected the demand, stating, "The State of Berlin will not give in to blackmail," leading the group to publish the stolen files on the dark web.
Infrastructure at Risk
The stolen dataset is extensive, comprising employee files, official correspondence, and scanned identification documents. More critically, the leak includes sensitive information regarding "KRITIS" (critical infrastructure), including data on water treatment plants, fuel storage, power plants, and prisons. This level of access provides a blueprint of the city's most vital utilities and security installations, moving the threat from digital theft to potential operational risk.
Systemic Security Failures
The breach underscores a systemic failure in cybersecurity training and response within Berlin's administration. Thorsten Schleheider, vice-chairman of Berlin's police union, criticized the city's reaction, calling it "unthinkable" that sensitive data was compromised for days while the primary response appeared to be simply instructing employees to change their passwords.
Beyond the immediate leak, the personal data now available to criminals creates a long-term security vacuum. Jochim Selzer of the Chaos Computer Club warned that the depth of the stolen information allows for sophisticated impersonation, noting that the more an attacker knows about a person, the easier it is to impersonate them to commit further fraud or unauthorized transactions.
The Path Forward
Berlin officials are now tasked with mitigating the fallout of the leak and hardening networks against future phishing attempts. While the city maintained its policy against paying ransoms, the publication of critical infrastructure data means the government must now treat the security of its physical utilities as potentially compromised. Authorities continue to monitor the dark web for further distributions of the stolen records.