Ransomware group says it stole Berlin data, offers it for auction

Sign up now: Get ST's newsletters delivered to your inbox

Berlin’s Governing Mayor Kai Wegner and Berlin’s Senator for Interior, Digitalisation and Sport Iris Spranger attending a press conference on Aug 28 about a cyberattack which hit the Berlin’s Senate network.

Berlin's Governing Mayor Kai Wegner and Berlin's Senator for Interior, Digitalisation and Sport Iris Spranger attending a press conference on Aug 28 about a cyberattack which hit the Berlin's Senate network.

PHOTO: REUTERS

BERLIN – A ransomware group said on Aug 28 it was putting up for auction a trove of data it stole from Berlin state agencies, and city officials refused to pay.

The Rhysida group, which researchers say operates from Russia or Eastern Europe, said on its website it took 5.79 terabytes of data including 46,500 contracts as well as e-mails, phone numbers, passwords and classified information.

The group said it was auctioning the data at a starting price of 30 bitcoin in just under seven days, showing a countdown timer on its website.

The cyberattack on Berlin's network comes less than a month before the city-state holds elections on Sept 20.

‘Berlin will not submit to extortion’

Broadcaster RBB reported on the evening of Aug 27 that Berlin had received ransom demands for an unspecified amount following the attack.

“The state of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, Iris Spranger, said in a joint statement on Aug 28, before the ransomware group claimed the attack on their website.

Officials could not provide details on the content or scope of the affected data because the extent of the breach was still being examined, Wegner said at a press conference.

Spranger said the city’s election infrastructure had not been affected and that, according to security officials, no data related to the election had been compromised.

Ransomware group targets government

Rhysida has claimed nearly 280 attacks since it emerged in June 2023, according to cybercrime research platform eCrime.ch.

Roughly half of its victims have been in the US, followed by the UK, Canada and Italy, as well as other nations, according to Ransom-DB, a ransomware analysis and tracking service. The group has repeatedly targeted government institutions, such as the October 2023 hack of the British Library. The group has also claimed attacks on the Chilean army, schools, healthcare facilities and businesses of all sizes. REUTERS

See more on