Faultline Faultline Kommando 161

Germany · Perspektive Online · · 3h

5.8 terabytes of leaked data from Berlin – consequences not foreseeable

Deutsch (original) · Auto-translated to English

On Friday and Saturday, a hacker group published 5.8 terabytes of data that they had stolen from the Berlin administration. They previously demanded Bitcoin worth two million euros as blackmail money. Since then, criticism of the security standards of the authorities in Berlin has increased.

On August 14thclickedan employee of the Berlin Senate Transport Administration came across a link from a phishing email. Phishing emails describe attacks by hackers who want to obtain private passwords and the like using fake email addresses or websites. After the successful attempt at deceptionweretwo Senate administrations can only be used to a limited extent for two weeks. Among other things, you could neither apply for nor receive housing benefit for five days.

The hacker group Rhysida is responsible for this attack. The groupdemanded30 Bitcoin, which is roughly worth two million euros. The Berlin Senate rejected it - among other things, because it was not known whether the data had already ended up somewhere else. So far, a political motive has not been ruled out, but it seems obvious that the hacker group was motivated purely by financial means.

Last Friday, around two weeks before the election of a new House of Representatives in the capital, the extortion deadline expired. The hacker group then called out “Have fun browsing, data hunters!” on Friday. around 755,000 files are public on the dark web. A further publication of around 550,000 to 560,000 files followed on the night from Saturday to Sunday. In total, there are around 1.44 million files with a size of 5.8 terabytes. This attack is the largest data leak in the history of the state of Berlin.

The leaked data from the Berlin administration includes appraisals and personnel files of employees, timesheets, telephone numbers, job references, company documents or documents relating to the application process.

The “Berlin flood of documents” – some sensitive data published

The mirrorreportedfrom a “mess of files of different formats and sizes”. The majority of the “Berlin flood of documents” shows normal administrative behavior. Der Spiegel reports on some “entertaining” surprises, such as the email correspondence from a department head in the Senate Administration. He is said to have sent “esoteric motivational pictures” to colleagues during the corona pandemic.

However, among the files, documents from an anti-discrimination agency also found their way onto the dark web. This includes at least one email exchange in which a case of sexual harassment is described and measures that could be taken to prevent it.

After sabotage attempts at substations: Brandenburg's Interior Minister is planning a "360-degree security center"

According to initial counts, Spiegel has 340,000 PDF files, more than 156,000 emails and over 123,000 images. Despite the publication, the damage to Berlin cannot yet be fully assessed. According to Florian Hauer (Berlin State Secretary for Digital and Chief Digital Officer), the state of Berlin has currently not even been able to download all the data from the Darknet; from a technical perspective alone, this process would probably take a week.

But according to Spiegel, using the search term “KRITIS” – i.e. critical infrastructure – you can find over 3,000 files, some of which are quite remarkable. For example, a Word document is called “Hazard analysis and special water plan”. But under the databealso information about the Bundeswehr and the expansion of the Chancellery; According to the Senate, however,no military dataPart of the data leak. Nevertheless, Hauer emphasized that we were talking about data that was subject to the lowest level of secrecy at most, i.e. “classified information – only for official use”.

The “TerminalFix” method: A wrong click was the 5.8 terabyte key

According to onereportBSI, the group used the “TerminalFix” attack method. Phishing emails lure those affected via a link to a manipulated website on which a supposed CAPTCHA test appears. This is usually used to check whether the person visiting the website is a real person. To complete this fake CAPTCHA test, you will be asked to enter a command in the Windows Command Prompt. The computer then silently downloads malware in the background while the test appears to be successful.

What is particularly noteworthy is that the hacker group was not only able to gain access to individual computers, as is the case, for example, with the well-known “ClickFix” scam. The Rhysida group, on the other hand, gained access to entire government networks. From that moment on, the hackers were able to intercept data and track everything that happened on the network.

IT expert: “The state of Berlin acted with gross negligence”

The fact that an entire state administration is so easy to hack is causing criticism. IT expert Manuel Atug is the founder of AG KRITIS, an independent working group that consists of 23 experts from various areas and primarily deals with options for better protection of critical infrastructure in Germany. Atug has already been invited as an expert by the Berlin Interior Committee in 2023 and 2025. Even back then he warned of “glaring security gaps”. He describes the data leak as a consequence of “desolate cybersecurity”

Surveillance, sabotage, data trading: Cabinet decides on reform of the secret services

Atug told the German Press Agency: “The state of Berlin acted with gross negligence and intentionally did not comply with the secrecy requirements.” Local administrations are particularly popular targets of such attacks. This is because they often maintain outdated systems and often do not have the necessary qualified personnel. The job offers in administration are in competition with comparable professions in the private sector, which are likely to appear significantly more attractive in terms of pay and career opportunities.

The post5.8 terabytes of leaked data from Berlin – consequences not foreseeableappeared firstperspective.

Read the full story at the source →

Source: Perspektive Online