{"id":18346,"date":"2026-09-02T19:34:51","date_gmt":"2026-09-02T19:34:51","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=18346"},"modified":"2026-09-02T19:34:52","modified_gmt":"2026-09-02T19:34:52","slug":"berlin-rejects-rhysida-ransomware-blackmail","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=18346","title":{"rendered":"Berlin Rejects Rhysida Ransomware Blackmail"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"generic-article\">\n<p class=\"text-muted\">\n                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/fraud-management-cybercrime-c-409\" id=\"asset_topic_1_1\">Fraud Administration &amp; Cybercrime<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/geo-specific-c-518\" id=\"asset_topic_1_2\">Geo-Particular<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/ransomware-c-399\" id=\"asset_topic_1_3\">Ransomware<\/a>\n                                                    <\/p>\n<p>                    <span class=\"article-sub-title\">Extortion Group With Suspected Russian Provenance Imposes Friday Deadline<\/span><br \/>\n                <span class=\"article-byline\"><br \/>\n                                                <a rel=\"nofollow\" target=\"_blank\" class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/david-meyer-i-7589\">David Meyer<\/a>                                                     \u2022<br \/>\n                        <span class=\"text-nowrap\">September 2, 2026<\/span> \u00a0 \u00a0 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/berlin-rejects-rhysida-ransomware-blackmail-a-32731#disqus_thread\"\/><\/span><\/p>\n<figure>\n                <img decoding=\"async\" src=\"https:\/\/ismg-cdn.nyc3.cdn.digitaloceanspaces.com\/articles\/berlin-rejects-rhysida-ransomware-blackmail-image_large-8-a-32731.jpg\" alt=\"Berlin Rejects Rhysida Ransomware Blackmail\" class=\"img-responsive \"\/><figcaption>Picture: TTstudio\/Shutterstock\/ISMG<\/figcaption><\/figure>\n<p>Berlin officers quickly canceled distant work and are scouring all their techniques, after the infamous Rhysida ransomware gang attacked the German city-state in a double-extortion try that can come to some sort of conclusion this Friday.<\/p>\n<p><b>See Additionally:<\/b> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/demostracion-del-producto-backup-y-recuperacion-de-vm-a-20235?rf=RAM_SeeAlso\">Demostraci\u00f3n Del Producto: Backup Y Recuperaci\u00f3n De VM<\/a><\/p>\n<p>The assault was detected on Aug. 14, and all departments of the Berlin Senate had been instantly disconnected from their central community. These affected within the assault had been the departments for city improvement, development and housing &#8211; inflicting vital disruptions for these making an attempt to assert housing advantages &#8211; and for mobility, transport, setting and local weather safety. <\/p>\n<p>Berlin mayor Kai Wegner, who withdrew a re-election bid in July, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.berlin.de\/aktuelles\/10581479-958090-hackerangriff-auf-landesnetz-arbeit-mit-.html\" target=\"_blank\">mentioned<\/a> initially that no delicate information appeared to have been compromised. That assertion didn\u2019t final lengthy. By final Friday, following forensic investigations, Wegner admitted that public and personal information might have been taken between Aug. 7 and Aug. 12, and that the attackers had been making an attempt to blackmail the Berlin authorities. <\/p>\n<p>&#8220;The demand got here in early on Thursday night,&#8221; Wegner mentioned. &#8220;Berlin won&#8217;t give in to blackmail.&#8221;<\/p>\n<p>Based on a number of studies citing safety officers and knowledge on the darkweb, and with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.morgenpost.de\/berlin\/article413028932\/untersuchungen-zu-cyberangriff-laufen-weiter-steckt-russland-dahinter.html\" target=\"_blank\">affirmation<\/a> from the Berlin Senate on Tuesday, the wrongdoer was Rhysida, a prolific outfit that always targets organizations in the USA. A number of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/rhysida-hacking-group-strikes-more-healthcare-providers-a-27677\">American healthcare<\/a> suppliers have <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/delaware-health-system-plans-to-settle-rhysida-hack-lawsuit-a-29512\">fallen sufferer<\/a> though a Ransom-DB evaluation in February <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ransom-db.com\/blog\/rhysida-ransomware-group-analysis-2026\" target=\"_blank\">discovered<\/a> that nearly half of its identified assaults landed elsewhere on the earth, with Europe that includes strongly. <\/p>\n<p>Rhysida employs the now-standard tactic of double extortion, threatening leaks and the continued encryption of information on the sufferer\u2019s techniques. It focused the German metropolis of Stuttgart in Might of this yr, demanding 5 bitcoin in fee for information it claimed to have stolen, though neither the theft nor any ransom fee have been publicly confirmed.<\/p>\n<p>This time, the teams desires 30 bitcoins from Berlin, and says it can publish the information if it doesn\u2019t get the cryptocurrency by this coming Friday. Rhysida is operating an public sale till then, claiming that it&#8217;ll solely give the information to at least one purchaser.<\/p>\n<p>Based on Rhysida, the group claims to have 5.79 terabytes of Berlin Senate information, together with 16,389 emails, 11,963 cellphone numbers, 148 banking codes, tens of hundreds of contracts and judicial paperwork, and hundreds of personnel information containing extra private information. <\/p>\n<p>Rhysida additionally says it took credentials that had been saved in plaintext, together with labeled supplies and vulnerability analyses of Berlin\u2019s water provide.<\/p>\n<p>Berlin Senate spokeswoman Christine Richter <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/live\/i7qi13FWbac?si=L39Z4ZF9Ca1yj2A5&amp;t=2213\" target=\"_blank\">reiterated<\/a> at a Tuesday press convention that town wouldn&#8217;t cough up. She mentioned a &#8220;vital quantity of information&#8221; &#8211; a few of it personal &#8211; had been compromised on the two departments, however to this point there was no proof of every other departments being affected. Nonetheless, simply to verify, &#8220;all techniques throughout the state of Berlin should be scanned to rule out the chance that additional information has been exfiltrated.&#8221; <\/p>\n<p>She mentioned there are 12,000 such techniques that should be examined, although all of the techniques on the two affected departments have already been checked. Richter\u2019s workplace didn&#8217;t reply to a request for data concerning how lengthy all of this would possibly take.<\/p>\n<p>On Tuesday, Richter additionally appeared to verify Rhysida\u2019s declare scoring credentials, explaining that passwords for &#8220;sure specialised purposes&#8221; had been compromised, with the outcome that the 2 affected departments have &#8220;determined to implement extra safety measures&#8221; which have resulted in &#8220;some operational restrictions, although each departments stay reachable by e mail.&#8221;<\/p>\n<p>The Berlin newspaper Tagesspiegel <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.tagesspiegel.de\/berlin\/nach-hackerangriff-und-passwortklau-zwei-berliner-senatsverwaltungen-stoppen-homeoffice-zugriff-auf-ihre-netze-16001565.html\" target=\"_blank\">reported<\/a> sources within the departments as saying their house workplace entry had been shut off on Monday &#8211; they will ship and obtain emails, however they will\u2019t set up VPN entry to their inner networks, forcing them to work from their computer systems within the workplace. Richter confirmed this to the paper.<\/p>\n<p>Tagesspiegel <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.tagesspiegel.de\/berlin\/wasserversorgung-passworter-dienstvergehen-diesen-berliner-datenschatz-bieten-die-hacker-im-darknet-an-15998171.html \" target=\"_blank\">reported<\/a> earlier within the week that snippets of the stolen information exhibiting unencrypted login particulars had been helpfully saved in information with names like <code>Password.docx<\/code>, and that the passwords themselves included the likes of &#8220;Sunshine13&#8221; &#8211; not compliant with the suggestions of the Federal Workplace for Data Safety, it famous.<\/p>\n<p>As for what&#8217;s going to occur if Berlin sticks to its weapons and withholds fee, Rhysida has a historical past of constructing good on its threats. In 2023, after the British Library refused to pay the group 20 bitcoin, it printed round 600 gigabytes of the stolen information, together with employees particulars that <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.independent.co.uk\/news\/uk\/home-news\/british-library-strike-cyber-attack-b2855495.html\" target=\"_blank\">reportedly<\/a> pressured some to maneuver house. <\/p>\n<p>The Berlin Senate is adamant that the approaching state election on Sept. 20 won&#8217;t be affected by the hack. &#8220;The election setting is safe, in response to our safety officers,&#8221; mentioned Inside Senator Iris Spranger.<\/p>\n<p>It stays unclear the place Rhysida relies, though earlier analyses have hinted at a reference to Russia and its satellites. The cybersecurity agency Cynet <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cynet.com\/blog\/rhysida-the-ransomware-gang-strikes-again\/\" target=\"_blank\">famous<\/a> in 2023 that Rhysida\u2019s ransomware software program, ransom notes and leak web site typically included snippets of Russian, and the group conspicuously prevented concentrating on organizations in Russia and different post-Soviet states. And, in fact, Russia has been stepping up sabotage and drone assault efforts in Germany within the final yr or two, as a consequence of Germany\u2019s help for Ukraine &#8211; on Tuesday the federal government <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.dw.com\/en\/germany-interior-minister-warns-of-daily-hybrid-warfare\/a-78291550\" target=\"_blank\">accused<\/a> Russia of waging hybrid conflict.<\/p>\n<p>&#8220;There isn&#8217;t a proof of connections to Russia and even the Russian state&#8221; within the Berlin hack, Richter <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.morgenpost.de\/berlin\/article413028932\/untersuchungen-zu-cyberangriff-laufen-weiter-steckt-russland-dahinter.html\" target=\"_blank\">informed<\/a> the Berliner Morgenpost on Tuesday, &#8220;however such connections can&#8217;t be dominated out.&#8221;<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Fraud Administration &amp; Cybercrime , Geo-Particular , Ransomware Extortion Group With Suspected Russian Provenance Imposes Friday Deadline David Meyer \u2022 September 2, 2026 \u00a0 \u00a0 Picture: TTstudio\/Shutterstock\/ISMG Berlin officers quickly canceled distant work and are scouring all their techniques, after the infamous Rhysida ransomware gang attacked the German city-state in a double-extortion try that can [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":18348,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10358,4747,500,10420,10421],"class_list":["post-18346","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-berlin","tag-blackmail","tag-ransomware","tag-rejects","tag-rhysida"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18346","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18346"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18346\/revisions"}],"predecessor-version":[{"id":18347,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18346\/revisions\/18347"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/18348"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18346"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18346"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18346"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}