Hacker attack on Berlin administration: No military data stolen
After the cyber attack on Berlin Senate administrations by the Rhysida group, the Senate gives the all-clear on military secrets, but warns of possible citizen data on the dark web.
Quick Look
- After a hacker attack on the Berlin Senate administration, IT State Secretary Florian Hauer confirmed that no military data was stolen.
- However, citizen data could have ended up on the dark web.
- The Senate is planning a contact point for those affected.
AI-generated summary
Why It Matters
The hacker group Rhysida attacked Berlin Senate administrations in mid-August and demanded a ransom of 30 Bitcoin. After the payment was refused, data was published on the dark web.
According to the Senate, no data relating to the country's military defense was stolen in the serious hacker attack on parts of the Berlin administration. As Berlin's IT State Secretary Florian Hauer announced, the Senate administrations concerned did not have any relevant data.
Hauer had already announced on Monday that only data that had the lowest of four levels of secrecy had been stolen. However, he now admitted that he could not rule out that data related to critical infrastructure, such as emergency plans, would be affected.
According to the State Secretary, the package, which ended up on the Darknet after an extortion attempt, could also contain data from citizens. These would be identified and informed as quickly as possible, although this could still take weeks. Companies that were in contact with the Senate administrations - for example to apply for a building permit - could also be affected. Attempts are currently being made to download the more than five and a half terabytes of data from the Darknet in order to then systematically analyze it in a protected area, said Hauer.
Hackers demanded 30 Bitcoin as a ransom
As Berlin's Governing Mayor Kai Wegner (CDU) announced, the so-called election environment was not affected by the attack. The elections to the House of Representatives and the district council assemblies in less than two weeks are therefore “certain as of today,” said Wegner.
The cyber attack on the Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Environment and Climate Protection became known in mid-August. According to previous findings, data flowed on a large scale from August 7th to 12th. The hacker group Rhysida wanted to extort around two million euros in ransom in the cryptocurrency Bitcoin, but the Senate did not respond to the demand. The hackers then published the data on the dark web.
According to media reports, sensitive data such as private cell phone numbers, birth certificates, personnel files or criminal records can be viewed in the data package. This should also include data on hazard protection, as well as information on the expansion of the Federal Chancellery.
Because of the hacker attack, the Senate administrations were isolated from the state network for around a week. For days, among other things, no housing benefit could be applied for or paid out. According to Wegner, there is now no longer any evidence of infiltration. We are currently investigating what happened and how the perpetrators acted - the investigation is in full swing.
»Very professional and with a very high criminal energy«
As a consequence of the attack, the governing mayor announced that he would quickly ensure better protection of the Berlin administration's data network. "We will not wait until a new coalition is formed, but will make all human and financial resources available," said Wegner after the most recent Senate meeting.
“New insights were gained” from the cyber attack. The crisis team that was set up after the hacker attack became known to look after the security of the state network is continuing to work. So far it has been possible to fend off the daily attacks, said Wegner. "Now someone has gotten through - very, very professional and with a very, very high level of criminal energy."
The Senate is planning a kind of contact point for affected citizens. As Wegner and Hauer announced, it's about helping people who believe that their data could have leaked. Details of the contact point are still open; a central email contact is initially planned. A telephone hotline is also conceivable. The aim is to offer this as quickly as possible.
What to Watch
AI outlook — possibilities, not facts
Establishment of a central email contact point for affected citizens.
Very likely · Within weeks
Open Questions
- When exactly will the contact point be available for those affected?
- How many citizens exactly are affected by the data leak?
