The Federal Office for Information Security (BSI) warns of a new attack campaign called “TerminalFix”. The authority refers to an analysis by Microsoft. Explosive: TerminalFix was apparently the entry ticket for cybercriminals into the networks of the Berlin Senate. The attack, which became known in mid-August, led to massive data exfiltration with partially critical information .
The BSI confirmed in a post on Mastodon that the TerminalFix method is the attack vector used by the cyber gang Rhysida. This information is not found in the authority’s BSI security notice (BITS) ( PDF ). However, on Mastodon, the BSI directly refers to this notice. Thus, it is certain: The Senate administrations for Building and Transport were attacked via TerminalFix.
August 7 to 12, 2026 : Data was exfiltrated by unknown parties from the two Senate administrations for Urban Development, Building and Housing, and for Mobility, Transport, Environment and Climate Protection . The attack began long before this date .
August 14, 2026: The two Senate administrations were isolated from the state network .
August 17, 2026: The Senate Chancellery informed via press release an "ICT incident in the Berlin state network . An emergency crisis team was established, the BKA and LKA are investigating, and the BSI is informed.
August 21, 2026 : The two authorities remain disconnected from the state network. This led to problems with transfer payments , including the inability to pay housing benefits to 50,000 eligible households in Berlin.
August 24, 2026 : All parts of the Senate administration are back online and, according to Governing Mayor Kai Wegner, “fundamentally operational”.
August 27, 2026: Florian Hauer, Berlin’s State Secretary for Digitization, stated : “We currently assume that the attack could be contained”. He could not rule out that “personal or other non-public data were also affected”.
August 28, 2026: Security authorities met with representatives of the State of Berlin for a crisis meeting . The attackers had stolen data and made a ransom demand. Governing Mayor Kai Wegner stated: “The State of Berlin will not be blackmailed.” No information was given the scope and content of the data. In the evening, Der Spiegel reported that the known ransomware gang “Rhysida” was allegedly behind it. Their darknet website demonstrably shows a demand for 30 Bitcoin (around 2 million Euros), along with alleged excerpts from the data. The criminals promised, among other things, lists of plaintext passwords, judicial documents, and over 46,500 state contracts.
August 30, 2026: CCC spokesperson Joachim Selzer warned of possible identity theft and other fraud attempts . Citizens whose personal information might be included in the alleged dataset would also easily fall victim to extortion attempts.
September 1, 2026: At a press conference, the Senate administration confirmed that passwords were also exfiltrated . Employees of the two administrations could therefore not currently work from . All 12,000 state systems in Berlin were being checked “around the clock”.
September 4, 2026: The criminals published around 1.44 million files on the darknet . These included personnel records, details of disciplinary proceedings, financial documents, and information on Berlin’s critical infrastructure.
September 5, 2026: The BSI warned of an “ increased threat level ” for society.
September 6, 2026: The State of Berlin established a "steering unit" . Those affected by the leak are to be contacted via email and letter . Politicians and IT experts expressed shock at the scope and content of the published data.
This is a variant of the malware campaign “ClickFix”, which Microsoft warned back in February 2026. As already described in detail , users are tricked by ClickFix into executing the Windows Terminal. PowerShell is available there, through which commands can be given to the operating system, for example, to copy files or execute programs.
TerminalFix differs from ClickFix primarily in that it uses Windows + X to access the Windows Terminal directly, rather than executing commands directly via Windows + R (as in “run”), followed by pressing the “I” key for direct access to PowerShell.
Via PowerShell, a malicious command is then executed, which the user must paste from the clipboard. It is there because it was copied there by a manipulated website before these actions via JavaScript. These websites, according to Microsoft , display a fake Cloudflare captcha. There is also a bit of social engineering involved here, because: The real Cloudflare captchas, to be effective, always have to look a little different and demand various things from the user. The fact that one sometimes has to press a few keys and not just click something might not be immediately apparent to unsuspecting users.
The command that lands in PowerShell downloads the attackers’ first malware from their systems in the background via a script. In the foreground, the manipulated website with the fake captcha prompts the user for further actions. The user is thus distracted while their PC is being infected. Among other things, the script calls the signed and benign Windows file “LockScreenContentServer.exe”, through which part of the malware is installed as “dui70.dll” via sideloading. The code within downloads PNG image files from the attackers, in which further programs and DLLs are hidden using steganography.
Subsequently, the package of malicious software installs itself persistently, i.e., permanently, via registry keys on the attacked system. Every 60 minutes, the malware checks if it is still running and listens for new commands from the attackers. They also set up a SOCKS proxy, thus having access to the attacked organization’s network through a tunnel. What the user does there can therefore be monitored and intercepted, provided not everything is properly encrypted. As is common with professional attacks, all these actions are concealed, for example, by hiding files and directories from plain view in Windows Explorer.
As a result, the attackers listen in and have at least access to the user’s local files and the directories they can access. From there, they can work their way further. Since the Berlin authorities – as has already been confirmed – also maintained plaintext password lists , Rhysida likely had a relatively easy game. How the criminals gained access to apparently all the data of the two Senate administrations is still unclear.
For all this to work, the first target person only needs to be lured into visiting a correspondingly manipulated website and then operating it as described. This can be done, for example, via a phishing email or a link via social media, in forums, or on websites. Such attacks are also called “Water-Holing”, as they are placed on websites where victims regularly gather -- similar to a watering hole that attracts herds of animals in the savanna.
Since the names and email addresses, as well as personnel structures of authorities, are usually at least partially public, social engineering is easy to accomplish. And even if it only succeeds on perhaps the twentieth attempt: The demanded around 2 million Euros in Bitcoin make the effort worthwhile.
Threats from gangs like Rhysida should be taken very seriously. As the BSI reports, citing an unnamed external service provider, in 92 percent of cases where criminals threaten publication, it actually occurs. Rhysida therefore primarily focuses on the healthcare and education sectors – government agencies are still among the five most frequently mentioned target types.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
