Ransomware hackers dump 1.4 million stolen records from German government


A cybercriminal group known as Rhysida allegedly broke into the network of Berlin’s state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web.

According to multiple sources, the group first claimed responsibility for the attack on an underground forum, where it shared a small sample of the stolen files and demanded Berlin pay 30 bitcoin (around $2.3 million) in exchange for deleting the files.

Berlin recognized the attack in a press release, and said it would not be negotiating with the attackers, and instead launched a full-scale investigation into the incident, which it described as an “extremely serious crime and an attack on the state of Berlin.”

Read more…
Source:  TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Roaming Mantis reaches Europe

    February 7, 2022

    Roaming Mantis is a malicious campaign that targets Android devices and spreads mobile malware via smishing. Kaspersky researchers have been tracking Roaming Mantis since 2018, and they observed some new activities by Roaming Mantis in 2021, and some changes in the Android Trojan Wroba.g (or Wroba.o, a.k.a Moqhao, XLoader) that’s mainly used in this campaign. ...

  • Europol coordinates action against bomb manuals available online

    February 3, 2022

    On 1 February, a large-scale Referral Action Day targeting terrorist content online took place at Europol’s headquarters. The European Union Internet Referral Unit (EU IRU) at Europol’s European Counter Terrorism Centre (ECTC) coordinated the referral activity, which saw the involvement of specialised counter terrorism units from France, Germany, Hungary, Italy, the Netherlands, Portugal, Spain, Switzerland ...

  • Shell forced to reroute supplies after cyberattack on two German oil companies

    February 1, 2022

    A cyberattack on two German oil suppliers has forced energy giant Shell to reroute oil supplies to other depots, according to Reuters and the Handelsblatt newspaper. Handelsblatt was the first to report on Monday that oil companies Oiltanking and Mabanaft, both owned by German logistics conglomerate Marquard & Bahls Group, had suffered a cyberattack that crippled ...

  • German govt warns of APT27 hackers backdooring business networks

    January 26, 2022

    The BfV German domestic intelligence services (short for Bun­des­amt für Ver­fas­sungs­schutz) warn of ongoing attacks coordinated by the APT27 Chinese-backed hacking group. This active campaign is targeting German commercial organizations, with the attackers using the HyperBro remote access trojans (RAT) to backdoor their networks. HyperBro helps the threat actors maintain persistence on the victims’ networks by acting ...

  • New FluBot and TeaBot campaigns target Android devices worldwide

    January 26, 2022

    New FluBot and TeaBot malware distribution campaigns have been spotted, using typical smishing lures or laced apps against Android users in Australia, Germany, Poland, Spain, and Romania. The SMS topics used for spreading the FluBot malware include fake courier messages, “Is this you in this video?” coaxes, phony browser updates, and fake voicemail notifications. The most recent ...

  • After ransomware attack, global logistics firm Hellmann warns of scam calls and mail

    December 20, 2021

    German logistics giant Hellmann has warned its customers and partners to be on the lookout for fraudulent calls and mail after the company was hit with a ransomware attack two weeks ago. In an update about the cyberattack that initially forced them to remove all connections to their central data center, the company said business operations ...