Ransomware

Berlin and Rhysida: stolen data published after a cyberattack

Berlin is examining data published by an extortion group after an attack on two departments. The claimed volume is separate from confirmed impact.

Conceptual illustration: Berlin and Rhysida: stolen data published after a cyberattack
Conceptual illustration · SecurCheck

What is confirmed

On 5 September, Berlin's state government announced a crisis response after stolen data was published following an attack on two departments.

Rhysida claimed 5.79 TB and offered allegedly stolen material for sale; authorities had not validated that volume.

What it means

Publication increases the risk of further redistribution and targeted phishing against people whose details appear in the files.

Refusing a ransom does not guarantee attackers delete their copies.

What to do

Follow notices from the relevant departments and verify unusual requests through official channels.

For an organisation, preserve evidence, isolate affected systems and activate incident response.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Reuters — réponse de crise à Berlin
  2. Reuters — revendication Rhysida