
AI-generated summary
On August 14th, a cyber attack on the Berlin state network became known, which isolated the Senate Departments for Urban Development and Mobility for about a week. The attack was confirmed by the State Criminal Police Office and the BSI.
In the blackmail case following the massive data theft in the Berlin national network, the criminal hacker group Rhysida carried out its threat. Around an hour after the ultimatum expired, the 5.8 terabyte data package was published on the dark web late on Friday afternoon.
The blackmailers had set up a countdown on their leak site that expired on Friday at around 3:35 p.m. A ransom of 30 Bitcoin (the equivalent of around two million euros) was demanded. The Berlin Senate had previously confirmed that it would not respond to such blackmail and would not pay a ransom.
See F.A.Z. articles more often in your search results
F.A.Z. prefer on Google
After the deadline had passed, the “auction” was ended on the blackmailers’ website in the Darknet. “All files have been uploaded to the publicly accessible area – have fun browsing, data hunters!” it said. However, a link initially did not lead to the data, but rather an error message. An hour later you could start downloading the data.
Praise from experts for refusing to pay a ransom
The Senate's refusal to respond to blackmail attempts by criminal hackers was met with approval among experts. Bianca Kastl from the Chaos Computer Club said on RBB Inforadio that the Senate's decision was correct. “If you continued to support these groups with money or other things, then of course they would keep going,” she said. “You have to dry them out financially.”
The renowned IT security expert Christof Fischer pointed out that by law the state is not allowed to make payments in the event of extortion. However, the situation with incidents like those in Berlin is very difficult: "The data is in the hands of criminals, and publication in many cases has very damaging effects. So far, I have not come across any case in which payment was made and publication still took place." However, it can be assumed that the perpetrators, who mostly lived in Eastern European countries, made this data available to the authorities there in order to buy protection from investigations against themselves, Fischer told the German Press Agency.
Experience has shown that in comparable attacks it often takes several hours or days until stolen data sets are actually made available for download via archive files or so-called peer-to-peer networks. IT security experts and the Berlin investigative authorities continually monitor the relevant forums and leak sites.
Explosive details in the announcements
The listings and screenshots previously published by the attackers indicate a serious outflow of highly sensitive data. The group claims to have stolen around 1.44 million files. In addition to more than 5,000 personnel files, fines and pay slips, this also includes confidential documents from Federal Council committees and vulnerability analyzes of Berlin's drinking water supply. The blackmailers also boasted that they had obtained access data and passwords in plain text - including for administration databases and payment service providers.
The Berlin administration confirmed the cyber attack that became known on August 14th. Investigators from the State Criminal Police Office (LKA) and the Federal Office for Information Security (BSI) are involved in analyzing and dealing with the incident. If the data package becomes fully public, the authorities concerned and thousands of citizens and employees face significant data protection and security risks.
Because of the hacker attack, the Senate Department for Urban Development, Building and Housing and the Senate Department for Mobility, Transport, Environment and Climate Protection were isolated from the state network for around a week on August 14th. Because of the cyber attack in Berlin, housing benefit could not be applied for or paid out for days.
AI outlook — possibilities, not facts
The Berlin investigative authorities will continue to investigate the origin of the data and the perpetrator group Rhysida.
Very likely · Within weeks
Further data protection and security measures are being taken in the Berlin administration.
Likely · Within months

The hacker group Rhysida has published almost six terabytes of data after a cyber attack on the Berlin state administration after the Senate rejected the ransom demand of 30 Bitcoin. The BSI assumes that the perpetrators are financially motivated and warns of the attackers' actions.

Police stormed the vehicle of a 48-year-old man from Gevelsberg who is suspected of carrying out several sabotage actions against Germany's electricity supply, including attacks on substations in Jänschwalde, Bergheim and Dormagen. Letters of confession were sent to newspapers in which the perpetrator stated climate terrorist motives and threatened further attacks. Interior Ministers Reul and Dobrindt confirmed the attack in Niederzier and warned of left-wing extremist or foreign-controlled backgrounds. The investigation is ongoing and so far it is assumed that the perpetrator was an individual.

The hacker group Rhysida published around 5.8 terabytes of stolen data from the Berlin state network on the darknet after its ransom ultimatum expired. CCC spokesman Joachim Selzer confirmed the authenticity of the data, which includes, among other things, personnel documents. The Senate had previously declared that it would not pay a ransom.

The police stormed the vehicle of a 48-year-old man who is suspected of several acts of sabotage against the German electricity supply. The man himself was not in the vehicle, but was probably on foot. Explosive remains were found on him and authorities suspect climate terrorism.

The police are looking for a 48-year-old man from Gevelsberg who is suspected of having committed acts of sabotage against the German power grid. Explosives were found during a search of his apartment. A special operations team then stormed a truck in Niederzier that was presumably converted into a mobile home. The man was not in the vehicle and may have been on foot. Federal Interior Minister Dobrindt spoke of “climate terrorism,” while NRW Interior Minister Reul emphasized that the attack on critical infrastructure was a crime, regardless of ideology. This week there were several sabotage attempts at substations and power plants in North Rhine-Westphalia, Brandenburg and Saxony, in which launching devices and explosives were found. The police asked the public for information via an online portal.
The police stormed the vehicle of a 48-year-old man who is suspected of sabotage of German power systems. The man is currently believed to be on foot. Explosives were found in his apartment and letters of confession with detailed knowledge of the perpetrators were secured. Investigations are underway into possible climate extremism or externally controlled sabotage.