Berlin Refuses Ransomware Payment After City Network Breach

Berlin Refuses Ransomware Payment After City Network Breach

Berlin's government says it will not pay extortionists after a state network breach exposed data; Manchester Airports Group also confirms customer data theft.

Berlin's state government has confirmed it is the target of an extortion attempt after the August compromise of the city's state administrative network, and it says it will not meet the attackers' demands. In the same statement, Berlin disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment, with data taken between August 7 and August 12, 2026. The scope and content are still being examined, and the Senate Chancellery said personal or other non-public data cannot be excluded from what was taken. The department first reported an outflow on August 7, seven days before it was cut off from the network on August 14. Berlin has not published a figure for how much data left the network. The only itemized account in circulation is the attackers' own, a leak site post indexed on August 28 that claims 5.79 terabytes of data and personal information on 12,076 individuals. As of August 29, Berlin's two releases carried no guidance for people whose records may be among the data.

Governing Mayor Kai Wegner said after a special Senate session at the Rotes Rathaus that the state is being blackmailed, according to the machine-translated English version on Berlin's official city portal. The Senate Chancellery's statement said the state criminal police, the public prosecutor and federal security authorities are investigating the suspected perpetrators and had identified no group behind the attack. Der Spiegel has named Rhysida as the group, citing an entry on the group's darknet leak site and security sources involved in the response. The Hacker News confirmed via a leak site monitoring service on August 29 that an entry titled Berlin, Germany was added to Rhysida's leak site on August 28. That post claims to have scanned 5.79 terabytes of data and around 1.44 million files, and it identifies the victim only as Berlin, Germany rather than the Senate or any department. No ransom figure appears in the entry, and its eleven file categories, the largest of which is 124,823 maps and geodata files, together account for about a quarter of the claimed total file count.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI) and the Multi-State Information Sharing and Analysis Center (MS-ISAC) set out Rhysida's tradecraft in a joint advisory from November 2023. The advisory documents three initial access routes: valid accounts on external-facing remote services, where attackers log in to internal VPN access points with stolen valid credentials, especially at organizations that do not enable multi-factor authentication (MFA) by default; Zerologon (CVE-2020-1472), an elevation of privileges vulnerability in Microsoft's Netlogon Remote Protocol that Microsoft patched on August 11, 2020; and phishing, which the agencies record as a successful route into victim networks. The agencies note that the FBI and CISA do not encourage paying ransom because payment does not guarantee recovery and may encourage further attacks. They recommend prioritizing fixes for known exploited vulnerabilities, enabling MFA across services, and segmenting networks to stop ransomware from spreading. The same document notes open-source reporting of similarities between Vice Society, which Microsoft tracks as Storm-0832, and the actors deploying Rhysida, an overlap that Check Point described in 2023. The monitoring service listed 280 Rhysida victims as of August 29, nine of them in Germany, including the Stuttgart city administration in May 2026 and the aid organization Welthungerhilfe in June 2025. Its listings also include the Port of Seattle, which runs Seattle-Tacoma International Airport, indexed in September 2024.

On Berlin's response, the Senate Chancellery said the state data protection commissioner and the Federal Office for Information Security (BSI) are being kept informed on a continuing basis. The Hacker News found no statement on the incident from the Berlin Commissioner for Data Protection and Freedom of Information as of August 29. Interior Senator Iris Spranger said that as things stand, no data left the areas relevant to the conduct of the September 20 Abgeordnetenhaus election, and that her security officers regard the election environment as secure. Berlin first disclosed the incident on August 17, saying forensic work had established a compromise of the state network and that both affected departments had been isolated since the previous Friday. At an August 19 press conference, Wegner said the incident was and remains serious, and emphasized that based on current knowledge no sensitive data had left the state network. Housing benefit applications and payments were unavailable while the two departments were off the network. All Senate departments were reconnected on August 23, and forensic work and scanning of the state network continue.

In a separate incident, Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, said on August 27 that an unauthorized third party obtained customer data relating to car park, lounge and Fast Track bookings and in-airport WiFi sign-ups at the three sites. A MAG spokesperson said in the company's published statement that passenger safety and aviation security were not compromised, adding that airport operations and customer parking services continue to operate normally. The data obtained includes email addresses, phone numbers, vehicle registrations and postcodes, and MAG said neither it nor the accessed system holds customers' bank or payment details. MAG describes the accessed system as distinct from MAG itself. Its customer information page states that the incident does not involve operational airport systems and advises passengers to continue traveling to the airport as usual. As of August 29, access to the online Manage My Booking service has been suspended as a precautionary measure, and changes to bookings due within the next 72 hours will be handled by customer services on 0208 163 8001, weekdays between 9:00 and 17:00. A figure of roughly 8.7 million affected customers has circulated widely, sourced to a company spokesperson speaking to the press, but MAG's own materials leave the count unstated. MAG said it has contacted affected customers directly and pointed them to the U.K. National Cyber Security Center's (NCSC) data breach guidance, advising them to stay alert for suspicious emails, text messages and phone calls.

Organizations that need to review their own exposure to the initial access routes described in the Rhysida advisory can use AEU-I, AEU Group's security-first IT and infrastructure consulting service, to plan and implement basic controls such as multi-factor authentication and network segmentation.

How to Protect Yourself

  1. Turn on multi-factor authentication (MFA) for your online accounts, especially any remote access or VPN login, so a stolen password alone cannot let someone in.
  2. Install security updates for your devices and software promptly, because attackers still use the Zerologon vulnerability from 2020 that Microsoft already patched.
  3. Be suspicious of unexpected emails, text messages or phone calls asking for personal information, especially if you may have been affected by a data breach.
  4. If you receive a data breach notice, change your passwords and watch for messages that mention details from the breach, which scammers can use to sound convincing.
  5. For businesses, keep a separate offline backup of important data so a ransomware attack does not leave you dependent on the attackers.

Vulnerabilities & Fixes

Terms Explained

  • multi-factor authentication (MFA) A security method that requires more than one proof of identity, such as a password plus a code from your phone, before letting you log in.
  • VPN Virtual private network, a secure encrypted tunnel used to connect to an internal network from outside.
  • phishing Emails or messages that try to trick you into revealing passwords or opening harmful links.
  • Zerologon A nickname for a serious vulnerability in Microsoft's Netlogon Remote Protocol that lets an attacker take over a domain controller without a password.
  • CVE-2020-1472 The official identifier for the Zerologon vulnerability in Microsoft Netlogon Remote Protocol.
  • ransomware Malicious software that blocks or steals data and demands payment to restore access or keep it private.

Related AEU services

  • AEU-I IT and security consulting