Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector

Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector

First seen 9 Sep 2026, 11:43 UTC Heise.DeFeeds.Feedburner 67.5

Article Content

Browse articles
ThreatCluster

In August 2026, the Berlin Senate Administration suffered a significant ransomware attack attributed to the group Rhysida, initiated by a phishing email that led to a fake CAPTCHA prompt. The attack exploited a method called TerminalFix, allowing attackers to execute malicious code and gain access to sensitive data. The BSI confirmed that data was exfiltrated from the Senate administrations for Urban Development and Transport, affecting critical information and leading to a ransom demand of 30 Bitcoin (approximately €2 million). The attack resulted in the isolation of the affected administrations from the state network, disrupting essential services including housing benefits for 50,000 households. Following the attack, Rhysida published the stolen data online after the city refused to pay the ransom. The incident highlights vulnerabilities in cybersecurity practices and the need for improved security measures against social engineering attacks.

Key Points: • The attack was initiated via a phishing email leading to a fake CAPTCHA prompt. • Rhysida demanded a ransom of 30 Bitcoin after exfiltrating sensitive data from the Berlin Senate. • The attack disrupted services for 50,000 households, highlighting significant operational impacts.

Ask AI about this cluster

Timeline

2026-08-07
Data exfiltration began
Cybercriminals accessed networks of the Berlin Senate administrations for Urban Development and Transport.
Heise.De
2026-08-14
Senate administrations isolated
The affected administrations were disconnected from the state network to contain the attack.
Heise.De
2026-08-21
Service disruptions reported
The isolation led to issues with transfer payments, affecting housing benefits for 50,000 households.
Heise.De
2026-08-28
Crisis meeting held
Security authorities met with Berlin representatives to address the data breach and ransom demand.
Heise.De
2026-09-01
Passwords confirmed exfiltrated
The Senate administration confirmed that passwords were among the data stolen in the attack.
Heise.De
2026-09-07
BSI report published
The BSI released a report detailing the TerminalFix attack vector and its implications.
Heise.De
2026-09-09
Data published online
Rhysida published the exfiltrated data online after the city refused to pay the ransom.
Feeds.Feedburner