North Korea's Lazarus Group and Rhysida Ransomware Target Berlin Government

North Korea's Lazarus Group and Rhysida Ransomware Target Berlin Government

First seen 8 Sep 2026, 02:32 UTC Redpacketsecurity 60.0

Article Content

Browse articles
ThreatCluster

On September 8, 2026, Redpacketsecurity reported that North Korea's Lazarus Group operates through six distinct cyber clusters, engaging in espionage and financial operations. Concurrently, the Rhysida ransomware group published sensitive data from the Berlin government after a €2 million extortion demand was rejected. The attack on Berlin involved the exfiltration of critical government data, with the Rhysida group threatening further exposure if their demands were not met. The Lazarus Group's operations are believed to be state-sponsored, focusing on financial gains and intelligence gathering. The Rhysida ransomware incident highlights the growing threat of ransomware targeting governmental entities. Both incidents underscore the need for robust cybersecurity measures in critical infrastructure. Current status indicates ongoing investigations and heightened security alerts in affected regions.

Key Points: • Lazarus Group operates through six cyber clusters for espionage and financial crimes. • Rhysida ransomware published Berlin government data after a €2 million ransom demand was refused. • Both incidents highlight significant threats to governmental cybersecurity.

Ask AI about this cluster

Timeline

2026-09-08
Lazarus Group cyber clusters detailed
Redpacketsecurity reveals six distinct cyber clusters used by North Korea's Lazarus Group for espionage and financial operations.
Redpacketsecurity
2026-09-08
Rhysida ransomware attacks Berlin government
Rhysida ransomware group publishes sensitive data after Berlin government refuses to pay €2 million ransom.
Redpacketsecurity
2026-09-08
Ongoing investigations launched
Authorities initiate investigations into the Rhysida ransomware attack and the activities of the Lazarus Group.
Redpacketsecurity