preloader

· · digital-security ransomware europe government public-sector incident-response rhysida

A Ransomware Gang Just Put Berlin’s Government Data Up for Auction, Weeks Before an Election

Source: Reuters

Public bodies keep telling themselves ransomware crews go after banks and hospitals first. Berlin’s state government just found out that a slow-moving public-sector network is exactly the kind of target this gang prefers.

What Rhysida says it took

The Rhysida ransomware group claims to have exfiltrated 5.79 terabytes of data from Berlin state agencies, including roughly 46,500 contracts along with emails, phone numbers, passwords and material the group describes as classified. After the city declined to pay, Rhysida put the data up for auction on its leak site, starting the bidding at 30 bitcoin, worth close to 78,000 dollars at the time, with a seven-day countdown attached. Berlin’s mayor and interior senator issued a joint statement rejecting the demand outright, saying the state would not submit to extortion. Officials have said election systems and related data were not affected.

The timing is not a coincidence worth ignoring

The attack landed less than a month before Berlin’s September 20 election. Whether or not the timing was deliberate, it illustrates a pattern that public-sector security teams need to plan around rather than hope doesn’t apply to them: adversaries increasingly time disclosure and extortion pressure to moments when an organisation is least able to absorb disruption or bad press. A local government dealing with a data auction days before a vote has far less room to negotiate calmly than one dealing with the same breach in a quiet month.

Rhysida has a long European track record

This is not a one-off for the group. Rhysida has been active since mid-2023 and has claimed close to 280 attacks, with a consistent pattern of targeting government institutions, healthcare providers, education and critical infrastructure across the US and Europe, including the British Library and multiple government bodies elsewhere on the continent. Public-sector organisations are attractive precisely because they often run older infrastructure, distribute IT responsibility across departments, and have compliance-driven security programmes that were not built with an active, well-resourced extortion group in mind.

What this means if you hold citizen or contract data

If your organisation, public or private, holds large volumes of contracts, correspondence or personal data and has not recently tested how it would detect, contain and communicate through an incident like this one, the gap between “we have a security policy” and “we have an incident response plan that works under pressure” is exactly what gets exposed in a week like Berlin just had.

If you want your organisation’s exposure to ransomware and data exfiltration assessed, or need help building an incident response plan that holds up under real deadline pressure, contact Excello Digital. We help European organisations get ahead of the kind of attack that does not wait for a convenient time to happen.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!