Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Berlin Refuses to Pay Hackers Who Stole Data from the City's State Network: A Desperate Stand Against Cyber Extortion


Berlin's state government has refused to pay hackers who stole data from the city's state network, in a desperate stand against cyber extortion. The incident highlights the growing threat of cyber attacks and the importance of robust cybersecurity measures to protect against such threats.

  • Berlin's state government confirmed an extortion attempt following a compromise of its state administrative network.
  • Forensic work revealed further data outflows in the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7-12, 2026.
  • The stolen data includes personal and non-public information, and its scope and content are still being examined.
  • The attackers' ransom demand was reported to be 5.79 terabytes of data and personal information on 12,076 individuals.
  • Experts warn against paying ransom, as it does not guarantee recovery and may embolden adversaries.
  • The incident highlights the growing threat of cyber extortion and the need for robust cybersecurity measures.
  • Ancillary incidents, such as the Manchester Airports Group data breach, demonstrate the importance of incident response and coordination.



  • Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and has stated that it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with the exfiltration dated between August 7 and August 12, 2026.

    The scope and content of the data that was stolen are still being examined, and the Senate Chancellery said that personal or other non-public data cannot be excluded from what was taken. The department first reported an outflow on August 7, the Senate Chancellery said in response to questions, seven days before it was cut off from the network on August 14.

    Berlin has published no figure for how much data left the network. The only itemized account in circulation is the attackers' own, a leak-site post indexed on August 28 that claims 5.79 terabytes of data and personal information on 12,076 individuals. The Senate's two releases on the incident carried no guidance for people whose records may be among the data as of August 29.

    "The state of Berlin is being blackmailed," Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus, quoted in the machine-translated English version on Berlin's official city portal. "We will not give in to these extortionists' demands. We will not pay the ransom."

    The Senate Chancellery's statement said that the state criminal police, the public prosecutor, and federal security authorities are investigating the suspected perpetrators and identified no group behind the attack. Der Spiegel has named Rhysida as the group that first reported the attribution on August 28, citing an entry on the group's darknet leak site and security sources involved in the response. The Hacker News confirmed via a leak-site monitoring service on August 29 that an entry titled "Berlin, Germany" was added to Rhysida's leak site on August 28.

    The post claims to have scanned 5.79 terabytes of data and around 1.44 million files, and it identifies the victim only as Berlin, Germany, rather than as the Senate or any department. No ransom figure appeared in the entry, and its eleven file categories, the largest of which is 124,823 maps and geodata files, together account for about a quarter of the claimed total file count.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) set out the group's tradecraft in a joint advisory on Rhysida, which documents the following routes for initial access - valid accounts on external-facing remote services, where the actors authenticate to internal virtual private network (VPN) access points with compromised valid credentials, notably at organizations lacking multi-factor authentication (MFA) enabled by default.

    Zerologon (CVE-2020-1472), an elevation of privileges vulnerability in Microsoft's Netlogon Remote Protocol that Microsoft patched on August 11, 2020, was also mentioned as a potential entry point. Phishing, which the agencies record as a successful route into victim networks, was another method used by the group.

    The advisory dates to November 2023, when the agencies first warned of Rhysida's double extortion attacks. It records that the "FBI and CISA do not encourage paying ransom" because payment does not guarantee recovery and may embolden adversaries to target further organizations.

    The agencies recommend prioritizing remediation of known exploited vulnerabilities, enabling multi-factor authentication across services, and segmenting networks to prevent ransomware spreading.

    The monitoring service listed 280 Rhysida victims as of August 29, nine of them in Germany, including the Stuttgart city administration in May 2026 and the aid organization Welthungerhilfe in June 2025. Its listings also include the Port of Seattle, which runs Seattle-Tacoma International Airport, indexed in September 2024.

    The Senate Chancellery said Berlin's state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed on a continuing basis. The Hacker News found no statement on the incident from the Berlin Commissioner for Data Protection and Freedom of Information as of August 29.

    Interior Senator Iris Spranger said that as things stand, no data left the areas relevant to the conduct of the September 20 Abgeordnetenhaus election, and that her security officers regard the election environment as secure.

    The incident highlights the growing threat of cyber extortion and the importance of robust cybersecurity measures to protect against such attacks. It also underscores the need for effective incident response and coordination between government agencies and private sector organizations.

    In a related development, Manchester Airports Group (MAG) has confirmed that an unauthorized third party obtained customer data relating to car park, lounge and Fast Track bookings and in-airport WiFi sign-ups at the three sites. The company has stated that passenger safety and aviation security were not compromised, and that airport operations and customer parking services continue to operate normally.

    The data obtained includes email addresses, phone numbers, vehicle registrations and postcodes, and MAG said neither it nor the accessed system holds customers' bank or payment details. The incident is being investigated by the U.K. National Cyber Security Center (NCSC).

    The incident is a reminder that no organization is immune to cyber attacks, and that robust cybersecurity measures are essential to protect against such threats. It also highlights the need for effective incident response and coordination between government agencies and private sector organizations.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Berlin-Refuses-to-Pay-Hackers-Who-Stole-Data-from-the-Citys-State-Network-A-Desperate-Stand-Against-Cyber-Extortion-ehn.shtml

  • https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html


  • Published: Sat Aug 29 17:02:13 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us