Berlin Government Confirms Second Data Dump from Rhysida Ransomware Attack
Berlin's government is dealing with a second wave of fallout from a cyberattack that compromised two of its ministries in mid-August, according to The Record.
Hackers hit the ministries responsible for urban development and housing, and for transport and climate protection. After disconnecting the affected systems from the wider government network on 14 August, officials now face a fresh problem: the attackers have published a second batch of stolen credentials online.
The Rhysida ransomware group claimed responsibility in late August, saying it had taken 5.79 terabytes of data including contracts, emails, passwords and classified files. Berlin's data protection authority confirmed that the leak contains personal information about public employees and may include data belonging to ordinary Berlin residents — names, addresses, dates of birth, bank details, email addresses, phone numbers, and copies of documents submitted to the administration.
Berlin has not paid the ransom. "The State of Berlin will not be blackmailed," Chief Digital Officer Florian Hauer said.
Germany's Federal Office for Information Security (BSI) separately warned about a related campaign it connected to the same criminal group. Attackers are setting up fake CAPTCHA verification pages that trick visitors into manually running malicious commands on their own computers — a technique sometimes called TerminalFix.
What you should do: If you submitted documents or personal information to Berlin city services, monitor your bank accounts and email for unusual activity. If you receive unexpected messages claiming to be from Berlin authorities asking you to click a link or verify details, treat them as suspicious until confirmed through an official channel.
Sources

