Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Meta Tests Robots to Handle Data Center Work

    August 29, 2026

    7 Indigenous Guarani killed after loose grain trailer hits car in central Brazil

    August 29, 2026

    Wisconsin prisons hit record population as crowding strains staffing and programs

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meta Tests Robots to Handle Data Center Work
    • 7 Indigenous Guarani killed after loose grain trailer hits car in central Brazil
    • Wisconsin prisons hit record population as crowding strains staffing and programs
    • Exiled Publishers Are Helping Russians Get Around the Kremlin’s Censorship
    • USDA recalled 30K pounds of beef from Argentina. Trump’s import plan wasn’t to blame
    • Somali piracy surges as the impact of the US-Iran war ripples outwards
    • Judge Rules Trump Unlawfully Targeted Stanford Students Who Criticized Israel
    • Chinese automakers are following Tesla’s bet that robots are the next big profit machine
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Berlin’s state government has confirmed that it is the target of an extortion attempt following the August compromise of the city’s state administrative network, and said it will not meet the extortionists’ demands.

    The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with the exfiltration dated between August 7 and August 12, 2026.

    Scope and content are still being examined, and the Senate Chancellery said personal or other non-public data cannot be excluded from what was taken.

    The department first reported an outflow on August 7, the Senate Chancellery said in response to questions, seven days before it was cut off from the network on August 14.

    Berlin has published no figure for how much left the network. The only itemized account in circulation is the attackers’ own, a leak-site post indexed on August 28 that claims 5.79 terabytes of data and personal information on 12,076 individuals.

    The Senate’s two releases on the incident carried no guidance for people whose records may be among the data as of August 29.

    “The state of Berlin is being blackmailed,” Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus, quoted in the machine-translated English version on Berlin’s official city portal.

    The Senate Chancellery’s statement said that the state criminal police, the public prosecutor, and federal security authorities are investigating the suspected perpetrators and identified no group behind the attack.

    Der Spiegel has named Rhysida as the group that first reported the attribution on August 28, citing an entry on the group’s darknet leak site and security sources involved in the response. The Hacker News confirmed via a leak-site monitoring service on August 29 that an entry titled “Berlin, Germany” was added to Rhysida’s leak site on August 28.

    Cybersecurity

    The post claims to have scanned 5.79 terabytes of data and around 1.44 million files, and it identifies the victim only as Berlin, Germany, rather than as the Senate or any department. No ransom figure appeared in the entry, and its eleven file categories, the largest of which is 124,823 maps and geodata files, together account for about a quarter of the claimed total file count.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) set out the group’s tradecraft in a joint advisory on Rhysida, which documents the following routes for initial access –

    • Valid accounts on external-facing remote services, where the actors authenticate to internal virtual private network (VPN) access points with compromised valid credentials, notably at organizations lacking multi-factor authentication (MFA) enabled by default.
    • Zerologon (CVE-2020-1472), an elevation of privileges vulnerability in Microsoft’s Netlogon Remote Protocol that Microsoft patched on August 11, 2020.
    • Phishing, which the agencies record as a successful route into victim networks.

    The advisory dates to November 2023, when the agencies first warned of Rhysida’s double extortion attacks. It records that the “FBI and CISA do not encourage paying ransom” because payment does not guarantee recovery and may embolden adversaries to target further organizations.

    The agencies recommend prioritizing remediation of known exploited vulnerabilities, enabling multi-factor authentication across services, and segmenting networks to prevent ransomware spreading.

    The same document notes open-source reporting of similarities between Vice Society, which Microsoft tracks as Storm-0832, and the actors deploying Rhysida, an overlap with Vice Society that Check Point set out in 2023.

    The monitoring service listed 280 Rhysida victims as of August 29, nine of them in Germany, including the Stuttgart city administration in May 2026 and the aid organization Welthungerhilfe in June 2025. Its listings also include the Port of Seattle, which runs Seattle-Tacoma International Airport, indexed in September 2024.

    The Senate Chancellery said Berlin’s state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed on a continuing basis. The Hacker News found no statement on the incident from the Berlin Commissioner for Data Protection and Freedom of Information as of August 29.

    Interior Senator Iris Spranger said that as things stand, no data left the areas relevant to the conduct of the September 20 Abgeordnetenhaus election, and that her security officers regard the election environment as secure.

    Berlin first disclosed the incident on August 17, saying forensic work had established a compromise of the state network and that both affected departments had been isolated since the previous Friday.

    At an August 19 press conference, Wegner said the incident was and remains serious, and emphasized that, based on current knowledge, no sensitive data had left the state network.

    Housing benefit applications and payments were unavailable while the two departments were off the network. All Senate departments were reconnected on August 23, and forensic work and scanning of the state network continue.

    Manchester Airports Group Confirms Customer Data Theft

    Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, said on August 27 that an unauthorized third party obtained customer data relating to car park, lounge and Fast Track bookings and in-airport WiFi sign-ups at the three sites.

    Cybersecurity

    “At no point has passenger safety or aviation security been compromised,” a MAG spokesperson said in the company’s published statement, adding that airport operations and customer parking services continue to operate normally.

    The data obtained includes email addresses, phone numbers, vehicle registrations and postcodes, and MAG said neither it nor the accessed system holds customers’ bank or payment details. MAG’s statement describes it only as a system distinct from MAG itself.

    MAG’s customer information page states that the incident “does not involve operational airport systems” and advises passengers to continue traveling to the airport as usual.

    As of August 29, access to the online Manage My Booking service has been suspended as a precautionary measure. Changes to bookings due within the next 72 hours will be handled by customer services on 0208 163 8001, weekdays between 9:00 and 17:00.

    A figure of roughly 8.7 million affected customers has circulated widely, sourced to a company spokesperson speaking to the press, and MAG’s own materials leave the count unstated.

    MAG said it has contacted affected customers directly and pointed them to the U.K. National Cyber Security Center’s (NCSC) data breach guidance, advising them to stay alert for suspicious emails, text messages and phone calls.

    Berlin Citys data hackers Network Pay refuses state stole
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Meta Tests Robots to Handle Data Center Work

    PaperCut releases second emergency patch for exploited flaws

    Fair pay, service charges and the pressure to tip | Social etiquette

    McKesson discloses breach after ShinyHunters claims patient data theft

    Berlin is being blackmailed by hackers, mayor says

    Offensive Security Investments Surge as AI Threats Increase

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Meta Tests Robots to Handle Data Center Work

    August 29, 2026

    7 Indigenous Guarani killed after loose grain trailer hits car in central Brazil

    August 29, 2026

    Wisconsin prisons hit record population as crowding strains staffing and programs

    August 29, 2026

    Exiled Publishers Are Helping Russians Get Around the Kremlin’s Censorship

    August 29, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Meta Tests Robots to Handle Data Center Work

    August 29, 2026

    7 Indigenous Guarani killed after loose grain trailer hits car in central Brazil

    August 29, 2026

    Wisconsin prisons hit record population as crowding strains staffing and programs

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.