Ethical Hacking News
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote, Stolen Data Includes Personal Information, Sensitive Records, and Classified Information. The attack highlights the need for organizations to prioritize cybersecurity, particularly when it comes to protecting sensitive data and systems.
The Rhysida Ransomware Group targeted the Berlin government ahead of the upcoming elections.The group claimed responsibility for stealing 5.79 terabytes of data, including personal information, sensitive records, and classified information.The attackers accessed data from 12,076 individuals, including personal data and classified materials.The attackers' goal was to use the stolen data to violate GDPR, German classified-information rules, and other regulations.Officials refused to pay the ransom demand, citing US federal agency advice against paying ransoms.The Rhysida Ransomware Group has targeted government organizations globally, using tactics like phishing and exploiting vulnerabilities.The attack highlights the need for organizations to prioritize cybersecurity and protect sensitive data and systems.
The Rhysida Ransomware Group, a known threat actor, has targeted the Berlin government ahead of the upcoming elections. The attack, which occurred in late August, saw the group claiming responsibility for stealing 5.79 terabytes of data, including personal information, sensitive records, and classified information.
The attackers allegedly accessed data from 12,076 individuals, including personal data, such as email addresses, phone numbers, and identification documents. The group also claimed to have stolen sensitive records, including payroll data, leadership information, and credentials for systems used by the government. Additionally, the attackers accessed data related to classified materials, including documents allegedly containing state secrets.
The timing of the attack is particularly sensitive, as the Berlin government is set to elect its state parliament on September 20. The attackers have claimed that the stolen data could be used to violate GDPR, German classified-information rules, criminal law, and KRITIS/BSIG requirements.
Despite the group's claims, officials have refused to pay the ransom demand, citing long-standing advice from US federal agencies that paying a ransom does not guarantee data recovery and can encourage more attacks.
The Rhysida Ransomware Group has been identified as a threat actor that targets government organizations and has claimed victims in various countries, including the US, the UK, Canada, and Italy. The group typically gains access to its victims' networks by exploiting compromised VPN credentials, using zero-day vulnerabilities, or through old-fashioned phishing tactics.
In this case, the attackers accessed the Berlin government's network by exploiting the Zerologon vulnerability, which was patched by Microsoft in 2020. The attackers also isolated the Senate Department for Mobility, Transport, Climate Protection and Environment, and a second department from the network, which may have helped them avoid detection.
The incident highlights the need for organizations to prioritize cybersecurity, particularly when it comes to protecting sensitive data and systems. The attack also serves as a reminder that even the most secure networks can be vulnerable to exploitation, and that attackers may use various tactics to gain access to sensitive information.
Related Information:
https://www.ethicalhackingnews.com/articles/Rhysida-Ransomware-Group-Exploits-Vulnerabilities-in-Berlin-Government-Ahead-of-Elections-ehn.shtml
https://securityaffairs.com/198064/cyber-crime/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote.html
Published: Sat Aug 29 22:36:02 2026 by llama3.2 3B Q4_K_M