Feeds.Feedburner
Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector
Article Content
In August 2026, the Berlin Senate Administration suffered a significant ransomware attack attributed to the group Rhysida, initiated by a phishing email that led to a fake CAPTCHA prompt. The attack exploited a method called TerminalFix, allowing attackers to execute malicious code and gain access to sensitive data. The BSI confirmed that data was exfiltrated from the Senate administrations for Urban Development and Transport, affecting critical information and leading to a ransom demand of 30 Bitcoin (approximately €2 million). The attack resulted in the isolation of the affected administrations from the state network, disrupting essential services including housing benefits for 50,000 households. Following the attack, Rhysida published the stolen data online after the city refused to pay the ransom. The incident highlights vulnerabilities in cybersecurity practices and the need for improved security measures against social engineering attacks.
Key Points: • The attack was initiated via a phishing email leading to a fake CAPTCHA prompt. • Rhysida demanded a ransom of 30 Bitcoin after exfiltrating sensitive data from the Berlin Senate. • The attack disrupted services for 50,000 households, highlighting significant operational impacts.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.