Redpacketsecurity
North Korea's Lazarus Group and Rhysida Ransomware Target Berlin Government
Article Content
On September 8, 2026, Redpacketsecurity reported that North Korea's Lazarus Group operates through six distinct cyber clusters, engaging in espionage and financial operations. Concurrently, the Rhysida ransomware group published sensitive data from the Berlin government after a €2 million extortion demand was rejected. The attack on Berlin involved the exfiltration of critical government data, with the Rhysida group threatening further exposure if their demands were not met. The Lazarus Group's operations are believed to be state-sponsored, focusing on financial gains and intelligence gathering. The Rhysida ransomware incident highlights the growing threat of ransomware targeting governmental entities. Both incidents underscore the need for robust cybersecurity measures in critical infrastructure. Current status indicates ongoing investigations and heightened security alerts in affected regions.
Key Points: • Lazarus Group operates through six cyber clusters for espionage and financial crimes. • Rhysida ransomware published Berlin government data after a €2 million ransom demand was refused. • Both incidents highlight significant threats to governmental cybersecurity.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.