Berlin rejects extortion demand after Senate data exfiltration
Berlin’s state government publicly turned down the extortionists’ demands following a compromise that saw data siphoned from the Senate Department for Mobility, Transport, Climate Protection and Environment between 7 – 12 August 2026.
Timeline and response
The breach was discovered after forensic analysis confirmed exfiltration. The network was isolated on 14 August and fully restored on 23 August, after all Senate departments were re‑connected.
How the attackers got in
A joint advisory from CISA, the FBI and MS‑ISAC, dated November 2023, attributes the initial access to three techniques that are still relevant today:
- Compromised valid accounts – likely harvested from credential‑stuffing or prior phishing.
- Exploitation of the Zerologon vulnerability (CVE‑2020‑1472), a privilege‑escalation flaw in Microsoft Netlogon.
- Targeted phishing campaigns delivering malware or stealing credentials.
The advisory explicitly advises against paying any ransom.
Attribution – what we know and what’s still murky
Der Spiegel reported that a group calling itself Rhysida claimed responsibility on 28 August, citing a leak‑site entry. The claim has not been confirmed by any law‑enforcement agency; it remains an unconfirmed attribution.
A monitoring service listed 280 victims linked to Rhysida as of 29 August, including Stuttgart’s city administration (May 2026) and the charity Welthungerhilfe (June 2025). No official link to the Vice Society gang has been independently verified.
What was taken – verified vs. unverified claims
The Senate Chancellery confirmed that data was exfiltrated, but the exact volume and the personal nature of the records have not been publicly disclosed. A leak‑site post alleges 5.79 TB of data covering 12,076 individuals; this figure is unverified.
Other recent incidents in the region
On 27 August, Manchester Airports Group (MAG) disclosed a breach that exposed customer email addresses, phone numbers, vehicle registrations and postcodes. The breach forced MAG to suspend its “Manage My Booking” service on 29 August.
Who is affected
- Berlin’s state administrative network and the Senate Department for Mobility, Transport, Climate Protection and Environment.
- Potentially up to 12,000 Berlin residents (unconfirmed).
- Manchester Airports Group customers – thousands of travelers across the UK.
Defensive steps for organisations
- Patch all Windows servers for
CVE‑2020‑1472(Zerologon) without delay. - Enforce multi‑factor authentication on all privileged and remote access accounts.
- Implement strict network segmentation to isolate critical administrative systems.
- Deploy continuous monitoring for anomalous outbound traffic that may indicate data exfiltration.
- Conduct regular credential‑spray and phishing simulations to raise user awareness.
- Establish an incident‑response playbook that includes a clear “no‑pay” policy and coordination with law‑enforcement.
