Particle.news

Berlin Faces Ransomware Extortion Over Stolen Administrative Data

The Senat has refused the attackers’ demand while criminal and forensic probes work to verify what records were taken.

Overview

  • The intrusion on the state administration was first disclosed on 14 August and authorities now say data was exfiltrated from roughly 7 to 12 August, according to multiple official and reporting sources.
  • Security reporting attributes the extortion to the Rhysida ransomware group, which posted a Darknet leak, claims about 5–6 terabytes of data and is demanding 30 Bitcoin, roughly €2 million, with a one‑week countdown.
  • Berlin’s government held a special Senat session, publicly rejected payment and has opened criminal investigations by the LKA and the public prosecutor while federal agencies and external forensics teams, reportedly including CrowdStrike, examine the systems.
  • Affected services have been partially restored since 23–25 August and Wohngeld processing delays that hit about 50,000–55,000 recipients are being addressed so payments can resume, though some operational limits remain.
  • The attackers’ list of stolen material — cited as contracts, ~80,000 case files, emergency plans, passwords and login files — has not been independently verified and investigators warn stolen credentials or files could be resold or enable identity fraud and follow‑on crimes.