Full Report
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
Analysis Summary
# Incident Report: Berlin State Network Extortion Attempt
## Executive Summary
In August 2026, the Berlin state administrative network suffered a significant data breach and subsequent extortion attempt by the Rhysida ransomware group. The attackers exfiltrated approximately 5.79 terabytes of data, including maps, geodata, and personal information of over 12,000 individuals. The Berlin government has officially refused to meet the attackers' ransom demands and is working with federal authorities to remediate the impact.
## Incident Details
- **Discovery Date:** August 7, 2026
- **Incident Date:** August 7 – August 14, 2026
- **Affected Organization:** Berlin State Government (specifically the Senate Department for Mobility, Transport, Climate Protection and Environment)
- **Sector:** Government / Public Sector
- **Geography:** Berlin, Germany
## Timeline of Events
### Initial Access
- **Date/Time:** Approximately August 7, 2026.
- **Vector:** Suspected use of compromised VPN credentials (lacking MFA), exploitation of Zerologon (CVE-2020-1472), or phishing.
- **Details:** The first data outflow was detected on August 7, marking the beginning of the exfiltration phase.
### Lateral Movement
- **Details:** The attackers moved through the state administrative network to reach the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment.
### Data Exfiltration/Impact
- **Date:** August 7 – August 12, 2026.
- **Details:** Attackers stole 5.79 TB of data (1.44 million files). This included 124,823 maps/geodata files and personal information belonging to at least 12,076 individuals.
### Detection & Response
- **Discovery:** Forensic work identified the outflow after the initial August 7 detection.
- **Response actions:** The affected department was physically cut off from the network on August 14, 2026. Governing Mayor Kai Wegner publicly announced the refusal to pay the ransom on August 28, 2026.
## Attack Methodology
*Based on CISA/FBI/MS-ISAC advisory for the Rhysida group:*
- **Initial Access:** Likely compromised valid credentials for external-facing remote services (VPNs) or Phishing.
- **Persistence:** Not explicitly detailed, but typically involves maintaining remote access via VPN.
- **Privilege Escalation:** Potential exploitation of Zerologon (CVE-2020-1472).
- **Lateral Movement:** Standard domain reconnaissance and movement techniques utilized by ransomware-as-a-service (RaaS) groups.
- **Exfiltration:** Large-scale data transfer to attacker-controlled infrastructure.
- **Impact:** Data theft and extortion (blackmail); the group typically threatens to leak data on their darknet site.
## Impact Assessment
- **Financial:** No ransom paid; however, significant costs are expected for forensic investigation and network remediation.
- **Data Breach:** High. 5.79 TB of data, including non-public administrative data and PII of 12,000+ people.
- **Operational:** A major state department was disconnected from the network for at least two weeks.
- **Reputational:** High public profile incident involving the blackmail of a capital city’s government.
## Indicators of Compromise
- **Network indicators:** Activity associated with Rhysida leak site: `https[:]//www[.]ransomware[.]live/id/QmVybGluLCBHZXJtYW55QHJoeXNpZGE`
- **Behavioral indicators:** Large outbound data transfers; authentication attempts on VPNs without MFA.
## Response Actions
- **Containment:** Disconnection of the Senate Department for Mobility, Transport, Climate Protection and Environment from the state network on August 14.
- **Investigation:** Involvement of the State Criminal Police, Public Prosecutor, and Federal Office for Information Security (BSI).
- **Policy:** Official refusal to pay the ransom to avoid emboldening future attacks.
## Lessons Learned
- **MFA Criticality:** The suspected use of valid credentials highlights the vulnerability of remote access points that do not require multi-factor authentication.
- **Detection Lag:** Data exfiltration occurred for several days before the affected systems were fully isolated from the network.
- **Transparency:** While the government was quick to refuse payment, there was a noted lack of immediate guidance for citizens whose data was compromised.
## Recommendations
- **Enforce MFA:** Ensure Multi-Factor Authentication is mandatory for all VPN and remote access points.
- **Patch Management:** Prioritize remediation of known exploited vulnerabilities, specifically older high-impact flaws like Zerologon.
- **Network Segmentation:** Implement strict segmentation between different government departments to prevent a compromise in one sector from reaching the entire administrative network.
- **Egress Monitoring:** Implement improved alerting for large-scale data transfers to unauthorized external destinations.