Breaking
IT86-year-old German man dies after being hit by a hot air balloon in SwitzerlandUSWeek 1 College Football Betting Preview: LSU vs. Clemson, Cal vs. UCLA, Oregon vs. Boise StateRUAn F-4 Phantom fighter jet crashed during an air show in GreeceRURussian forces strike Ukrainian drone production facility in DnepropetrovskBRLoose bull kills woman during rodeo in Barbosa Ferraz; tests suspendedCNThe 14th World DanceSports Competition opens in Chengdu with thousands of contestants from 25 countries and regions participating.RUNizhny Novgorod players and coaching staff arrived in Sochi for a match against the local First League clubITParents report separation from their children and announce an appeal against the Juvenile CourtARIrini's report raises questions about arms smuggling to Libya despite the international embargoITSurvivors of the New Year's Eve fire in Crans-Montana guests at the Monza Grand PrixIT86-year-old German man dies after being hit by a hot air balloon in SwitzerlandUSWeek 1 College Football Betting Preview: LSU vs. Clemson, Cal vs. UCLA, Oregon vs. Boise StateRUAn F-4 Phantom fighter jet crashed during an air show in GreeceRURussian forces strike Ukrainian drone production facility in DnepropetrovskBRLoose bull kills woman during rodeo in Barbosa Ferraz; tests suspendedCNThe 14th World DanceSports Competition opens in Chengdu with thousands of contestants from 25 countries and regions participating.RUNizhny Novgorod players and coaching staff arrived in Sochi for a match against the local First League clubITParents report separation from their children and announce an appeal against the Juvenile CourtARIrini's report raises questions about arms smuggling to Libya despite the international embargoITSurvivors of the New Year's Eve fire in Crans-Montana guests at the Monza Grand Prix
BackHackers publish stolen data from Berlin administration
Hackers publish stolen data from Berlin administration
Developing
Die Zeit35 minutes agoCrime3 min readGermanyView original

Hackers publish stolen data from Berlin administration

Quick Look

  • Three weeks after a hacker attack on the Berlin administration, criminals published 1.44 million files with a size of 5.8 terabytes on the darknet.
  • This affects, among other things, personal data of employees as well as security-relevant information on critical infrastructures such as thermal power plants, waterworks and defense companies.
  • The authorities are currently carrying out an intensive data check and warn of possible misuse through identity theft or phishing attacks.

AI-generated summary

Why It Matters

From August 7th to 12th, hackers gained unnoticed access to parts of the Berlin state network and skimmed large amounts of data. The administration did not notice the attack until August 14 and made it public three days later. The hacker group Rhyside demanded a ransom of 30 Bitcoin, which the Senate did not pay.

Font size

The blackmailers have carried out their threat: three weeks after the serious hacker attack on the Berlin administration, the hackers published large amounts of data. The big concern is that the sensitive information could now be exploited by criminals. What is known and what risks there are.

What happened?

From August 7th to 12th, hackers gained unnoticed access to parts of the Berlin state network and skimmed large amounts of data. The Senate departments for construction and transport were affected. The administration didn't notice the attack until August 14th - and made it public three days later. Only gradually did it emerge what treasure trove of data the criminals had stolen: 1.44 million files with a size of 5.8 terabytes. One terabyte is equivalent to around 1,000 gigabytes.

The hacker group Rhyside demanded a ransom of 30 Bitcoin - the equivalent of around two million euros. The Senate did not give in to this. After their ultimatum expired, the hackers published the data on the dark web on Friday. This refers to a part of the Internet that cannot be found in the traditional way - for example through the usual search engines. According to the Federal Office for Information Security (BSI), communication there is encrypted and the authors of content and those who access it want to remain as anonymous as possible.

What kind of data is it?

A comprehensive overview is still difficult at this point - it is not easy to sift through the huge amounts of data. According to information from the Chaos Computer Club, this includes personal data from administrative employees - personnel matters, references, emergency plans.

The “Tagesspiegel” reports that the hackers also published content that is relevant to the security of the Federal Republic and the capital. According to the information, this concerns data from facilities that are particularly worthy of protection, such as thermal power plants, tank farms, emergency power systems and substations. The hackers are also said to have leaked secret data about prisons, waterworks and defense companies, the Bundeswehr and the Berlin interior administration that affect defense.

Jochim Selzer, spokesman for the Chaos Computer Club, said he looked at some documents and found sensitive information about the state of the water supply in Berlin. The IT expert Manuel Atug does not want to view the documents on the Darknet himself for ethical reasons. However, he learned from reputable sources that the newspaper's information was correct, at least in the case of information about civil defense and defense companies. He is the founder and spokesman for AG Kritis, an independent working group that deals with critical infrastructures.

How are the authorities reacting now?

You are trying to get an overview of the published data. “The security authorities are currently carrying out an intensive data check,” the Berlin Senate announced on Friday evening. “IT forensic experts commissioned by the State of Berlin are also intensively examining the published data.” “The appropriate measures would be derived from this” - what that actually means remained unclear. However, the country announced that if individual affected people were identified, they would be informed “on a risk-based basis and in accordance with legal requirements”.

Upon request, the Federal Ministry of the Interior announced that federal authorities were also supporting the state of Berlin in the evaluation - namely the Federal Office for Information Security, the Federal Criminal Police Office and the Office for the Protection of the Constitution. A spokesman for the federal government said that, based on current knowledge, federal data systems were not affected.

A spokeswoman for the operational command of the Bundeswehr referred to the ongoing evaluation by the responsible security authorities and announced that after analyzing potential security risks, appropriate measures would be initiated to maintain military security. “There is a continuous comparison of information between the authorities involved, including via the National Cyber ​​Defense Center.”

What are the dangers of publishing?

If it is confirmed that the data contains security-relevant information, it could theoretically be exploited by foreign powers or terrorists for their own purposes. Information about critical infrastructures, companies and organizations could increase the threat level, depending on the sensitivity of the data, warns the BSI.

With regard to personal data, Jochim Selzer from the Chaos Computer Club points out the risk of identity theft. “The more I know about a person, the more accurately I can impersonate that person and the more accurately I can assess what I need to know about that person, for example in order to be able to order something on their behalf.”

The BSI also points out an increased threat from targeted phishing attacks following the data leak. People who have been in contact with affected people or institutions should therefore pay particular attention.

Why is there criticism?

The IT expert Atug accuses the state of Berlin of having acted “grossly negligently” and of not complying with secrecy regulations. There are very strict and precise regulations as well as several security levels for the storage and processing of secret documents. Apparently these were not applied sufficiently.

The police union in Berlin was dismayed by the events. “He has once again clearly shown Berlin’s politics that people have been sleeping here for years,” said GdP state deputy Thorsten Schleheider. “It cannot be the case that highly sensitive data was stolen here for days and that the only reaction appears to be to instruct employees to change their passwords.” That shows a certain helplessness.

Can the incident have an impact on the Berlin election?

The Berlin House of Representatives will be re-elected on September 20th. State returning officer Stephan Bröchler told “Bild”: “As things stand, the electoral environment is still not affected. So neither the preparation, nor the actual election day, nor the process leading up to the publication of the provisional results.”

The BSI fundamentally warned that there was a risk of so-called hack & leak operations in the political sphere, especially before elections. Stolen documents, emails or the like are published at a time that is convenient for the attacker and may be placed in the wrong context. However, according to the BSI, it is not suspected that the criminal hackers have a political intention in this specific case. It is assumed that the crime was “exclusively financially motivated”.

What to Watch

AI outlook — possibilities, not facts

  • The authorities will identify further security gaps in the Berlin administration and take appropriate protective measures.

    Very likely · Within weeks

  • An increasing number of phishing attempts are being observed against people who have been in contact with the affected institutions.

    Likely · Within days

Open Questions

  • What specific security-related data was published exactly?
  • How many people are directly at risk from the data leak?
  • What specific measures are derived from the data review?
  • Were there any other demands from the hackers besides the ransom?

Related Topics

This article was originally published by Die Zeit.

Related Stories

Federal authorities are investigating a hacker attack on the Berlin administration
Developing·

Federal authorities are investigating a hacker attack on the Berlin administration

Federal authorities such as BSI, BKA and BfV are supporting the investigation into the cyber attack on Berlin's Senate administrations, in which the hacker group Rhysida demanded a ransom of two million euros in Bitcoin and threatened to publish data. Governing Mayor Kai Wegner confirmed attempted blackmail and isolated networks, refused payment and highlighted daily cyberattacks on state networks across Germany.

Die Zeit
2 min read
More on this topicBerlin administration