Berlin administration under cyber blackmail: ultimatum expires
Quick Look
- A hacker group called Rhysida stole 5.8 terabytes of data in an attack on the Berlin administration's data network and demanded a ransom of 30 Bitcoins.
- The ultimatum expires in the afternoon.
- If the requirement is not met, there is a risk of sensitive data being published, including personal information and infrastructure data.
AI-generated summary
Why It Matters
A hacker group called Rhysida carried out an attack on the Berlin administration's data network in August 2024 and stole 5.8 terabytes of data. The data is auctioned off on the dark web, with a ransom of 30 Bitcoins being demanded.
The ultimatum that cyber criminals have given the state of Berlin expires in the afternoon. The blackmailers obtained large amounts of data and documents during a hacker attack on the Berlin administration's data network. According to the Senate Chancellery, a professional hacker group called Rhysida is demanding a ransom of 30 Bitcoins, around two million euros. Joachim Selzer, spokesman for the Chaos Computer Club, expects that at least parts of the huge amount of data will be published if the state of Berlin does not agree to it, as he told the German Press Agency.
The stolen data has been offered for sale for a week on the Darknet, a part of the Internet that is not easily accessible, as part of an auction that ends in the afternoon. Rhysida claims to have stolen almost 5.8 terabytes of data in the hacker attack that became known in mid-August.
This may also include personal data of employees of the State of Berlin as well as citizens and companies, as the Senate Chancellery announced on Thursday evening.
The minimum bid for the auction is 30 Bitcoins. Berlin's governing mayor Kai Wegner (CDU) declared on Friday last week that the country would not comply with the blackmailers' demands.
Cybercriminals could sell data to the highest bidder
“I suspect that they will then offer the easily salable parts of the data, such as email addresses, for sale on the black market,” said Selzer. “It was possible to leave your email address and a bid on the group’s website,” explained the IT expert. “I assume that people have already made bids in the past few days and that after the ultimatum ends, contact will be made with these people to determine whether this is really a serious offer.”
There are other options for cybercriminals: “It may of course be that they simply display data that is embarrassing for the administration but may not sell very well,” says the IT administrator. “Also to leave the message: “Be careful, we are not to be trifled with.”» According to Selzer's assessment, cybercriminals are keen to be taken seriously - also with a view to future blackmail attempts.
He assumes that in the attack on the data network of the Senate Transport Administration and the Building Administration they obtained data that could actually be unpleasant to publish: “The hackers showed a few pages, including data from disciplinary proceedings. “They claim to also have security analyzes on the vulnerability of Berlin’s water supply,” said Selzer.
Hackers have stolen data on a massive scale
“And they apparently got hold of the Berlin administration’s passwords in plain text, some of which have already been published. I really hope that these exact passwords have now been changed.” The hackers claim they got 5.8 terabytes of data. These are tens of thousands of documents - according to them, in addition to passwords, they also include infrastructure data, emails, telephone numbers, account numbers.
The Senate Chancellery recommends that those affected whose data is published should file a criminal complaint - via the Berlin police internet watchdog or at any local police station. According to the information, the employees have already been informed that advice is available to them.
One thing is certain: With their hacker attack, the cybercriminals had the opportunity to penetrate the administration's data network for days and allow data to flow out. “If the 5.8 terabytes were pure text data, that would be an insane amount of data. “That’s more than anyone could ever read in a lifetime,” said Selzer. “Because there is also image data underneath, it puts it into perspective a bit.”
What to Watch
AI outlook — possibilities, not facts
The hacker group Rhysida will attempt to contact bidders after the ultimatum expires to check the seriousness of their offers.
Likely · Within days
Parts of the stolen data, particularly email addresses and passwords, are offered for sale on the black market.
Very likely · Within weeks
Open Questions
- What specific personal data was stolen?
- How sensitive is the alleged infrastructure data on water supply?
- Will the stolen data actually be made public if the ransom is not paid?
- Has the Berlin administration changed all passwords?
