Breaking
ITThe man accused of the murder of a 65-year-old of Moroccan origin in Udine was arrested in BasilianoESThe first prize of the Extraordinary September Draw of the National Lottery goes to the number 26246UKMarco Brenner wins shortened Vuelta stage 14 as Pogacar ends season with surgeryTRZelenskiy announced that negotiations with Trump's representatives have started in RussiaRUFamous Turkish actor Serhat Mustafa Kilic was found dead in an apartment in IstanbulESSony Pictures Television fires Jim Thornton after being caught in a pedophile chat during a flightITIran-US war: three Iranian oil tankers hit after missile attacks against US shipsITHaaland decides Manchester City-Coventry, Tottenham stops Nottingham ForestARA fuel truck fire in Sanandaj sparks an emergency response from fire brigadesCRYPTO-FRTrump threatens trade embargo if Fed doesn't cut ratesITThe man accused of the murder of a 65-year-old of Moroccan origin in Udine was arrested in BasilianoESThe first prize of the Extraordinary September Draw of the National Lottery goes to the number 26246UKMarco Brenner wins shortened Vuelta stage 14 as Pogacar ends season with surgeryTRZelenskiy announced that negotiations with Trump's representatives have started in RussiaRUFamous Turkish actor Serhat Mustafa Kilic was found dead in an apartment in IstanbulESSony Pictures Television fires Jim Thornton after being caught in a pedophile chat during a flightITIran-US war: three Iranian oil tankers hit after missile attacks against US shipsITHaaland decides Manchester City-Coventry, Tottenham stops Nottingham ForestARA fuel truck fire in Sanandaj sparks an emergency response from fire brigadesCRYPTO-FRTrump threatens trade embargo if Fed doesn't cut rates
BackHacker attack on Berlin's state network: sensitive defense data leaked on the darknet
Hacker attack on Berlin's state network: sensitive defense data leaked on the darknet
BREAKING
Süddeutsche Zeitung47 minutes agoCrime2 min readGermanyView original

Hacker attack on Berlin's state network: sensitive defense data leaked on the darknet

Quick Look

  • After a successful attack on the Berlin state network, the hacker group Rhysida published sensitive data, including defense plans, emergency concepts and personal information.
  • The Senate rejected a ransom demand of 30 Bitcoin.
  • Federal and state authorities are investigating the incident, which also affects data from the Bundeswehr and the federal government.

AI-generated summary

Why It Matters

The Rhysida hacker group has been active since mid-2021 and has previously attacked institutions such as the British National Library and the Chilean military for ransom. The attack on the Berlin state network was carried out via two senate administrations with their own IT, which are not centrally managed by the state IT service center.

Font size

What happened?

Two weeks ago it became known that there had been an IT incident in the Berlin state network. The hacker group Rhyside gained access to huge amounts of data and demanded a ransom of 30 Bitcoin - the equivalent of around two million euros. The Senate did not give in to this. After their ultimatum expired, the hackers published the data on the darknet on Friday, according to their own information, 1.44 million files with a volume of around 5.7 terabytes. According to information from the Süddeutsche Zeitung, the data can since then be downloaded from the Rhysida group's darknet page. “The “Rhysida” group is known to the security authorities and has been active since mid-2021. "It is fundamentally considered criminal and financially motivated," emphasizes the Federal Ministry of the Interior. In the past, it had already attacked various public and private institutions, such as the British National Library or the Chilean military - in order to extort money using the data.

Which sensitive data is affected?

These are documents from administrative operations, such as contracts, protocols, passwords. The data set also contains personal data such as addresses and telephone numbers or confidential personnel files, as well as many tax documents. The SZ also found application documents, email traffic and many working papers marked “confidential”. Security-relevant information such as emergency plans and secret communication channels are also said to have been leaked.

What causes particular concern?

According to SZ information, there are dozens of sensitive documents on defense plans in an emergency, such as protection against attacks with chemical agents, plans for Berlin's civil defense, barracks and data on critical infrastructure facilities, such as waterworks, thermal power plants, tank farms, emergency power systems and substations. Secret data, such as prison blueprints and information about defense companies, can now also be viewed on the Darknet. The CDU foreign and defense politician Roderich Kiesewetter told the Süddeutsche Zeitung about the scale of the incident: “This data leak is of serious proportions and endangers our national security.”

What is particularly problematic?

The fact that highly sensitive plans for overall defense, the protection of critical infrastructure and emergency concepts for crises and defense are now circulating on the dark web “and are open to opposing intelligence services and terrorist networks is extremely serious,” says Kiesewetter. The federal and state governments must immediately forensically examine which documents were leaked, “and fundamentally revise and adapt compromised protection and deployment plans without any delay.” In addition, it is a bitter revenge that cybersecurity standards and classified information requirements in the federal structure and at the state level are still handled inconsistently and carelessly. “If we want to make our overall defense resilient, we must raise digital defense and security at all federal interfaces to the same high-security level.”

Why does the case go far beyond Berlin?

Because secret data about the Bundeswehr and the federal government is also affected. "The federal government is aware of the data leak. The detailed evaluation is currently being carried out by the responsible federal and state security authorities," said a spokeswoman for the Bundeswehr's operational command command when asked by the Süddeutsche Zeitung. “After analyzing potential security risks, appropriate measures will be initiated to maintain military security.” The National Cyber ​​Defense Center is also involved. Experts are already talking about a disaster, especially in a highly fragile phase. The Bundeswehr has been insisting on much more secrecy and data security for months - for a long time, information on power grids was handled far too transparently. After an attack at the beginning of the year, Berlin experienced its worst blackout since the Second World War. "We were naive and believed that it was sensible for us to disclose it. We should urgently give up this naivety now, otherwise we would even invite the saboteurs," said the deputy commander of the operational command, General André Bodemann, in an interview with the SZ.

How do private citizens find out whether they are affected?

Anyone who has Darknet access can theoretically search the files, but this is very time-consuming and involves a certain amount of risk. The Berlin administration wants to inform people who appear in the leaked data, depending on their risk assessment. There is also a contact point for administrative employees. It is said that those affected are called upon to file a criminal complaint with the police. The Berlin data protection officer also recommends updating passwords for administrative and online services and monitoring account movements.

How could the hackers get the data?

What is certain is that the attack took place on August 7th via the Senate Department for Mobility, Transport and Environment and the Senate Department for Building and Housing. Both authorities have their own IT and are not directly managed by the state's own IT service center. Some critics see the lack of consolidation of public IT as risky. The Berlin Senate Chancellery initially stated that only publicly accessible data was leaked in the attack. That turned out to be wrong. The time of the attack was also only discovered late. In the past, Rhysida had gained network access using phishing attacks. The attackers imitate websites or pose as trustworthy colleagues or official administrators in emails in order to obtain access data. Hackers can then use such compromised data to access systems and wipe them out unnoticed.

Is there still a risk of further attacks?

According to the state of Berlin, there is currently no evidence that the state network is still infiltrated. The network connects around 600 locations in Berlin, such as administrative buildings, fire stations and scientific institutions.

The Federal Office for Information Security (BSI) recognizes a fundamentally increased threat situation. “The BSI explicitly points out that the publication of stolen data can result in various risks for those affected and ultimately for society,” explained a spokesman. There is a risk of so-called hack & leak operations in the political sphere, especially before elections. Stolen documents, emails or the like are published at a time that is convenient for the attacker and may be placed in the wrong context.

How does Berlin react to the attack?

In Berlin they declared that they would not respond to attempts at blackmail. Accordingly, the country let the deadline pass on Friday afternoon. Since passwords and access data were also published, access to the systems was also restricted, reports the Tagesspiegel. Employees of the affected administrations could no longer log in to internal programs from their home office via VPN, but had to be present in the office to do so. According to Interior Senator Iris Spranger (SPD), the election to the House of Representatives on September 20th in Berlin is technically secured against hacker attacks. A temporary disruption to the state returning officer's website can be explained by the fact that the state network was heavily burdened by the system analyses. “As things stand, no data has been leaked there,” she told the capital portal berlin.de. According to security officials, the election is safe.

But the very hesitant and sparse reactions also show that the dimension has surprised many people and some difficult news about what has happened is still to come. And that's why the case has long been one for the federal government. A spokesman for Interior Minister Alexander Dobrindt (CSU) emphasizes that the Federal Office for Information Security (BSI), the Federal Criminal Police Office and the Federal Office for the Protection of the Constitution (BfV) are already supporting the authorities in Berlin in the investigation.

What to Watch

AI outlook — possibilities, not facts

  • The federal and state authorities will introduce uniform cybersecurity standards for public IT.

    Likely · Within months

  • Further investigations are being carried out into possible hack and leak operations before the elections.

    Possible · Within weeks

Open Questions

  • What specific measures are being taken to revise compromised protection plans?
  • How is uniformity of cybersecurity standards achieved between the federal and state governments?
  • Is there any evidence that the leaked data has already been used by hostile actors?

Related Topics

This article was originally published by Süddeutsche Zeitung.

Related Stories

Investigations into the management of a nursing home in Bremen due to allegations of bodily harm and mistreatment
Developing·

Investigations into the management of a nursing home in Bremen due to allegations of bodily harm and mistreatment

The public prosecutor's office is investigating the management of a nursing home in Bremen on suspicion of bodily harm and mistreatment of those under protection. Residents are said to have not been adequately cared for and were partly dehydrated. The managing director rejects the allegations and emphasizes that the staffing is sufficient and has been confirmed by the home supervision.

Die Zeit
1 min read
Federal authorities are investigating a hacker attack on the Berlin administration
Developing·

Federal authorities are investigating a hacker attack on the Berlin administration

Federal authorities such as BSI, BKA and BfV are supporting the investigation into the cyber attack on Berlin's Senate administrations, in which the hacker group Rhysida demanded a ransom of two million euros in Bitcoin and threatened to publish data. Governing Mayor Kai Wegner confirmed attempted blackmail and isolated networks, refused payment and highlighted daily cyberattacks on state networks across Germany.

Die Zeit
2 min read
Hackers publish stolen data from Berlin administration
Developing·

Hackers publish stolen data from Berlin administration

Three weeks after a hacker attack on the Berlin administration, criminals published 1.44 million files with a size of 5.8 terabytes on the darknet. This affects, among other things, personal data of employees as well as security-relevant information on critical infrastructures such as thermal power plants, waterworks and defense companies. The authorities are currently carrying out an intensive data check and warn of possible misuse through identity theft or phishing attacks.

Die Zeit
3 min read
More on this topicrhysida