When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom. At the end of August, Berlin’s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom.
The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included. Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes: The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements.
These are Rhysida’s claims and have not been independently verified. The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.
The fallout goes far beyond routine data theft. Investigative journalist Lars Winkelsdorf pointed out the gravity of the situation on social media. Die absolute Vollkatastrophe ist eingetretenDieses Datenleck ist schlimmer als alle bisherigen Terroranschläge zusammen 1/xhttps://t.co/epU4mCYgew “In addition to LKA documents related to investigations, the files also include plans concerning national defense—ranging from the federal government’s secret communication channels in the event of an apocalypse to defense-related companies and emergency plans developed by government agencies,” Winkelsdorf wrote.
Exposing crisis response plans and secret communication channels turns a financial shakedown into a national security headache. Worse still, the leaked material includes files concerning chemical, biological, radiological, and nuclear threats. “Among the published files is a folder titled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological and nuclear threats,” notes the Euronews report Having that kind of operational data floating around public forums gives hostile actors a blueprint for disaster. Refusing to pay ransoms is the right policy, but it rarely stops the bleeding once the network is compromised.
Governments keep treating cybersecurity like an IT expense rather than an existential line of defense. Until boards start treating network segmentation with the same seriousness as physical security, we will keep watching expensive countdown timers tick down to zero. Berlin’s state government announced the launch of a crisis response after the threat actors published the stolen data. “A central crisis unit will oversee the review, verification and assessment of the leaked data and support efforts to inform affected citizens and businesses, said the city.” Reuters reports.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon