Posted in

Berlin Refuses to Pay Hackers After State Network Data Breach

Berlin’s state government has confirmed that it is the target of an extortion attempt following the compromise of the city’s state administrative network earlier this month. Authorities said they will not comply with the attackers’ demands.

The Senate Chancellery also disclosed that forensic investigations have uncovered additional data outflows involving the Senate Department for Mobility, Transport, Climate Protection and Environment. According to the authorities, the newly identified data exfiltration took place between August 7 and August 12, 2026.

The full scope and contents of the data remain under investigation. Berlin authorities said they cannot rule out the possibility that personal or other non-public information was among the material removed from the network.

Additional Data Exfiltration Discovered

The department initially reported a data outflow on August 7, according to the Senate Chancellery. Seven days later, on August 14, the department was disconnected from the state network as authorities responded to the incident.

Berlin has not disclosed how much data was ultimately removed from its systems.

However, an account published on an alleged ransomware leak site on August 28 claimed that the attackers had obtained 5.79 terabytes of data, including information relating to approximately 12,076 individuals.

That figure has not been independently confirmed by Berlin authorities.

The attackers’ post reportedly claimed to have scanned approximately 1.44 million files. It listed 11 categories of files, with maps and geodata representing the largest category at 124,823 files. Together, the categories account for only around a quarter of the total file count claimed by the attackers.

As of August 29, Berlin’s two public statements on the incident had not provided specific guidance for individuals whose personal information may have been affected.

Berlin Says It Is Being Blackmailed

Following a special Senate session at Berlin’s Rotes Rathaus, Governing Mayor Kai Wegner confirmed the extortion attempt.

“The state of Berlin is being blackmailed.”

The Senate Chancellery said Berlin’s state criminal police, the public prosecutor’s office and federal security authorities are investigating the suspected perpetrators. Authorities have not officially attributed the attack to a particular ransomware group.

German media outlet Der Spiegel reported that Rhysida was the group behind the leak-site claim, citing the group’s darknet site and security sources involved in the response.

A leak-site monitoring service also recorded an entry titled “Berlin, Germany” on the Rhysida site on August 28.

The listing identifies the victim simply as Berlin, Germany, rather than naming the Senate or a specific government department.

No ransom amount was included in the listing.

Rhysida Attack Methods

A joint advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Multi-State Information Sharing and Analysis Center (MS-ISAC) describes several techniques associated with Rhysida attacks.

These include:

  • Compromised valid accounts: Attackers can use stolen credentials to access external-facing remote services, including VPN infrastructure. Organizations without multi-factor authentication enabled by default are particularly exposed.
  • Zerologon (CVE-2020-1472): A privilege-escalation vulnerability affecting Microsoft’s Netlogon Remote Protocol. Microsoft issued a patch for the vulnerability in August 2020.
  • Phishing: The agencies have identified phishing as another successful method used to gain initial access to victim networks.

The joint advisory, published in November 2023, warned that Rhysida was conducting double-extortion ransomware attacks.

CISA and the FBI have advised organizations not to pay ransom, noting that payment does not guarantee data recovery and could encourage attackers to target additional organizations.

The agencies recommend prioritizing the remediation of known exploited vulnerabilities, implementing multi-factor authentication across services and segmenting networks to limit the spread of ransomware.

The advisory also noted similarities reported between Rhysida operators and Vice Society, tracked by Microsoft as Storm-0832. Security firm Check Point previously documented similarities between the two operations.

Rhysida Has Targeted Organizations Worldwide

The monitoring service tracking Rhysida’s leak site listed 280 victims worldwide as of August 29, including nine organizations in Germany.

Among the German victims listed were the Stuttgart city administration, reportedly added in May 2026, and aid organization Welthungerhilfe, listed in June 2025.

The list also includes the Port of Seattle, operator of Seattle-Tacoma International Airport, which was added in September 2024.

The presence of an organization on a ransomware leak site does not, by itself, independently verify the attackers’ claims about the amount or nature of data stolen.

Berlin Continues Forensic Investigation

Berlin authorities said the state’s data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed of developments.

As of August 29, no public statement about the incident had been identified from the Berlin Commissioner for Data Protection and Freedom of Information.

Interior Senator Iris Spranger said that, based on the information currently available, no data had left areas relevant to the September 20 Abgeordnetenhaus election. Security officials consider the election environment secure, she said.

Berlin first publicly disclosed the cyber incident on August 17. Authorities said forensic analysis had confirmed a compromise of the state network and that two affected departments had already been isolated.

At a press conference on August 19, Wegner described the incident as serious and said that, based on knowledge available at the time, there was no evidence that sensitive data had left the state network.

Some government services, including housing benefit applications and payments, became unavailable while the affected departments were disconnected.

All Senate departments were reconnected to the network on August 23. Forensic investigations and security scans of the state network are continuing.

Manchester Airports Group Confirms Customer Data Theft

Separately, Manchester Airports Group (MAG) confirmed on August 27 that an unauthorized third party had obtained customer information connected to services at Manchester, London Stansted and East Midlands airports.

The affected services include airport car park bookings, lounge reservations, Fast Track bookings and in-airport Wi-Fi registrations.

MAG said the incident did not compromise passenger safety or aviation security.

“At no point has passenger safety or aviation security been compromised.”

The company said airport operations and customer parking services continue to operate normally.

What Customer Data Was Exposed?

According to MAG, the compromised information may include:

  • Email addresses
  • Phone numbers
  • Vehicle registration numbers
  • Postcodes

MAG said the affected system does not contain customers’ bank or payment information.

The company has described the affected platform as a system separate from its core airport operations. Its customer information guidance states that the incident does not involve operational airport systems and advises passengers to continue travelling as normal.

As of August 29, access to the online Manage My Booking service remained suspended as a precaution.

Customers with bookings within the following 72 hours can contact customer services for changes. The company has also said it is contacting affected customers directly.

Around 8.7 Million Customers Reportedly Affected

A figure of approximately 8.7 million affected customers has circulated in media reports, attributed to a company spokesperson.

MAG’s own published materials, however, do not state a total number of affected customers.

The company has advised customers to remain alert for suspicious emails, text messages and phone calls that could exploit the stolen information in follow-up phishing or social-engineering attempts.

MAG has also directed affected customers to guidance from the UK’s National Cyber Security Centre (NCSC) on responding to data breaches.

What These Incidents Show

The Berlin network compromise and the Manchester Airports Group data theft involve different organizations and circumstances, but both highlight the risks posed by unauthorized access to systems containing sensitive information.

For Berlin, the investigation is still determining the full scope of the data that may have been exfiltrated, while authorities have confirmed that the incident has escalated into an extortion attempt.

For MAG customers, the immediate concern is the potential misuse of contact and booking information. Customers should remain cautious about unsolicited messages that reference airport bookings, travel plans or other personal details.

Both incidents also underscore the importance of strong access controls, multi-factor authentication, network segmentation, vulnerability management and rapid forensic investigation following a suspected breach.

This article will be updated as Berlin authorities, Manchester Airports Group and relevant cybersecurity agencies release additional information.

Leave a Reply

Your email address will not be published. Required fields are marked *